Ana SayfaHome Tehdit VeritabanıThreat Database
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us Başarı HikayeleriSuccess Stories İletişimContact
Sayı 1Issue 1

SiberKapan Türkiye Siber Tehdit Raporu — Sayı 1 SiberKapan Turkey Cyber Threat Report — Issue 1

Gözlem Dönemi: 9 Haziran 2026 — 28 Haziran 2026 Observation Period: June 9, 2026 — June 28, 2026 MISP Resmi Feed Official MISP Feed
Bu raporu PDF olarak indirip paylaşabilirsiniz. You can download and share this report as a PDF. PDF İndir Download PDF
Yönetici ÖzetiExecutive Summary

9 Haziran – 28 Haziran 2026 döneminde 28.896 benzersiz tehdit IP'si tespit edildi. During June 9 – June 28, 2026, 28,896 unique threat IPs were detected.

Yakalanan tehditlerin %45,3'ü, küresel veritabanlarında (AbuseIPDB) henüz hiç kaydı bulunmayan IP'lerden geldi (Novel Detection). Of the captured threats, 45.3% came from IPs with no prior record in global databases (AbuseIPDB) — a Novel Detection.

Büyük ölçekli bir finansal altyapıda, devreye alınmasından sonraki ilk 48 saat içinde 609.000'den fazla saldırı policy seviyesinde gerçek zamanlı olarak engellendi. On a large-scale financial infrastructure, over 609,000 attacks were blocked in real time at the policy level within the first 48 hours of deployment.

SiberKapan, 2023'te Türkiye-içi honeypot tabanlı bir feed olarak başladı; 2026'da sıfırdan yeniden inşa edilen v2 ile uluslararası MISP tehdit istihbaratı ağına resmi feed olarak kabul edildi. Artık dünyadaki güvenlik ekiplerinin tek tıkla entegre edebileceği, küresel ölçekte tanınmış bir kaynak. SiberKapan began in 2023 as a Turkey-local honeypot-based feed; with the v2 rebuild in 2026, it was officially accepted into the international MISP threat intelligence network. It is now a globally recognized source that security teams worldwide can integrate with a single click.

Bu rapor, SiberKapan'ın honeypot, FortiGate Security Fabric entegrasyonu, fail2ban ve nginx imza motorundan topladığı verilere dayanarak Türkiye merkezli tehdit görünümünü ortaya koymayı amaçlamaktadır. This report aims to present a Turkey-centric threat landscape based on data collected from SiberKapan's honeypot, FortiGate Security Fabric integration, fail2ban, and nginx signature engine.

Genel GörünümOverview

Raporlama döneminde SiberKapan, 28.896 benzersiz tehdit IP adresi tespit etti. Coğrafi dağılımda Çin (%43,0) ve Türkiye (%23,4) ilk iki sırada yer aldı, bunları ABD (%5,3), Hindistan (%4,0) ve Hollanda (%2,9) takip etti. During the reporting period, SiberKapan detected 28,896 unique threat IP addresses. Geographically, China (43.0%) and Turkey (23.4%) ranked first and second, followed by the US (5.3%), India (4.0%), and the Netherlands (2.9%).

28.896
Benzersiz Tehdit IPUnique Threat IPs
9–28 Haz
Gözlem DönemiObservation Period
%43,0
En Yüksek Kaynak Ülke (Çin)Top Source Country (China)
ÜlkeCountry Kod IP SayısıIP Count %
ÇinChinaCN12.430%43,0
TürkiyeTurkeyTR6.759%23,4
Amerika Birleşik DevletleriUnited StatesUS1.537%5,3
HindistanIndiaIN1.143%4,0
HollandaNetherlandsNL842%2,9
PakistanPakistanPK785%2,7
AlmanyaGermanyDE491%1,7
UkraynaUkraineUA342%1,2
Hong KongHong KongHK334%1,2
RusyaRussiaRU321%1,1
Not — Türkiye Kaynaklı Trafiğin Doğası Note — The Nature of Turkey-Originated Traffic

Türkiye kategorisindeki IP'lerin ASN/altyapı analizi, bu trafiğin üç farklı kaynaktan birinden veya birkaçının kombinasyonundan gelebileceğini gösteriyor: (1) ele geçirilmiş ev/IoT cihazları üzerinden çalışan botnet'ler, (2) Türkiye'de barındırılan ancak yabancı aktörler tarafından kiralanan VPS/VDS sunucuları, (3) yerli aktörler tarafından doğrudan kullanılan altyapı. Mevcut veri, ağırlıklı olarak Türk hosting/VPS sağlayıcılarında (tüketici ISP'lerine kıyasla) bir yoğunlaşma göstermekte olup, bu da ikinci ihtimali güçlendiriyor. Literatürde "Bulletproof Hosting" ve "Egress Node" olarak tanımlanan modellerle örtüşen bir yoğunlaşma deseni olabileceği değerlendirilmektedir — saldırganların coğrafi konum filtrelerini (Geo-IP blocking) aşmak amacıyla yerel VPS kiraladığı senaryolar bilinen bir taktiktir. Ancak bu IP'lerin büyük kısmı doğrulama süreci devam eden bir tespit kategorisinden geldiği için kesin bir sonuca varılmamıştır; bu konu ayrıca araştırılmaktadır. ASN/infrastructure analysis of IPs in the Turkey category shows this traffic may originate from one or a combination of three sources: (1) botnets running on compromised home/IoT devices, (2) VPS/VDS servers hosted in Turkey but rented by foreign actors, (3) infrastructure used directly by domestic actors. Current data shows a concentration weighted toward Turkish hosting/VPS providers (compared to consumer ISPs), reinforcing the second possibility. This may overlap with patterns described in the literature as "Bulletproof Hosting" and "Egress Node" models — attackers renting local VPS to bypass geo-IP blocking is a known tactic. However, since most of these IPs come from a detection category still under verification, no definitive conclusion has been reached; this is under further investigation.

Sensörlerimizin Yakaladığı: Organik TespitCaught by Our Sensors: Organic Detection

Üçüncü taraf feed'lerden ödünç alınmış bir liste değil — bu bölümdeki her satır, SiberKapan'ın kendi honeypot'larına, fail2ban entegrasyonuna ve nginx imza motoruna gerçek zamanlı çarpan trafikten geliyor. Not a list borrowed from third-party feeds — every line in this section comes from traffic hitting SiberKapan's own honeypots, fail2ban integration, and nginx signature engine in real time.

Haziran ayı içindeki bu ~20 günlük pencerede, organik sensörler toplam 11.757 kayıt ve 1.563 benzersiz IP yakaladı. Listenin başını, hiç şaşırtmayan bir klasik çekiyor: SSH brute-force (7.606 kayıt / 303 IP), internetin en eski, en sabırlı ziyaretçisi, hâlâ kapıyı çalıyor. Onu Telnet (2.152 kayıt / 471 IP) takip ediyor. Devamında Fail2ban (1.470 kayıt / 515 IP), HTTP kabakuvvet (254 kayıt / 152 IP), RDP saldırıları (168 kayıt / 96 IP) ve en yeni tehdit istihbarat aktörümüz olan Nginx access log paternlerinden çıkardığımız olaylar (52 kayıt / 38 IP) takip ediyor. In this ~20-day window in June, organic sensors captured a total of 11,757 records and 1,563 unique IPs. Topping the list is an unsurprising classic: SSH brute-force (7,606 records / 303 IPs) — the internet's oldest, most patient visitor, still knocking on the door. Telnet follows (2,152 records / 471 IPs). Then Fail2ban blocks (1,470 records / 515 IPs), HTTP brute-force (254 records / 152 IPs), RDP attacks (168 records / 96 IPs), and events derived from our newest detection vector, Nginx access log patterns (52 records / 38 IPs).

Saldırı TipiAttack Type KayıtRecords Benzersiz IPUnique IPs
SSH Brute-Force7.606303
Telnet2.152471
Fail2ban EngellemeleriFail2ban Blocks1.470515
HTTP Honeypot254152
RDP16896
Nginx İmza Tespitleri (UA + Path)Nginx Signature Detections (UA + Path)5238
Vaka Çalışması Case Study

Kritik Hacimli Bir Altyapıda Gerçek Dünya Etkisi Real-World Impact on a Critical-Volume Infrastructure

Teoriler güzeldir, ancak SiberKapan'ın bunu sahada da kanıtlaması gerekiyordu. Haziran ayında, Türkiye'de günlük işlem hacmi on milyonlara ulaşan bir finansal/e-fatura altyapısında SiberKapan, FortiGate üzerinde External Connector olarak devreye alındı. Theories are nice, but SiberKapan needed to prove this in the field too. In June, SiberKapan was deployed as an External Connector on FortiGate within a financial/e-invoicing infrastructure that processes tens of millions of transactions daily in Turkey.

609.118
policy seviyesinde engelleme — devreye alınmasından sonraki ilk 48 saat içinde policy-level blocks — within the first 48 hours of deployment

SiberKapan'ın beslediği tehdit verisi, devreye girdiği ilk günlerde saldırgan trafiği gerçek zamanlı olarak durdurdu. Bu, bir laboratuvar deneyi değil; üretimde, gerçek veriyle gerçek parayla işlemlere açık çalışan bir sistemde alınan ilk somut etki ölçümü. The threat data fed by SiberKapan stopped attacker traffic in real time within its first days in production. This is not a lab experiment — it is the first concrete impact measurement taken on a live production system handling real money and real transactions.

Önden Görmek: Novel DetectionSeeing It First: Novel Detection

Bir tehdit istihbaratı platformunun asıl sınavı, bilineni tekrar etmek değil, henüz kimsenin bilmediğini ilk gören olmaktır. The real test of a threat intelligence platform is not repeating the known — it's being the first to see what no one else has yet.

10.867
Karşılaştırılan IPIPs Compared
%45,3
Novel Detection OranıNovel Detection Rate

Bu dönemde AbuseIPDB ile karşılaştırılan 10.867 IP'nin %45,3'ü (4.926 IP), SiberKapan tarafından tespit edildiği anda AbuseIPDB'de hiçbir rapor kaydına sahip değildi. Sıfır rapor, sıfır confidence skoru. Başka bir deyişle, bu IP'ler dünyanın en büyük topluluk tabanlı tehdit veritabanında henüz tanınmamışken, SiberKapan onları zaten yakalamıştı. Of the 10,867 IPs compared with AbuseIPDB during this period, 45.3% (4,926 IPs) had zero report record on AbuseIPDB at the moment SiberKapan detected them. Zero reports, zero confidence score. In other words, while these IPs were not yet recognized in the world's largest community-based threat database, SiberKapan had already caught them.

Bu, şans eseri bir rakam değil; SiberKapan'ın honeypot öncelikli mimarisinin doğal bir sonucu — saldırgan, büyük feed'lere rapor edilmeden önce küçük, sabırlı bir tuzağa düşüyor. This is not a coincidental figure — it's a natural result of SiberKapan's honeypot-first architecture: the attacker falls into a small, patient trap before ever being reported to the large feeds.

Metodoloji Notu Methodology Note

"Novel detection", tarih bazlı bir kıyaslama değil, AbuseIPDB'nin ilgili IP için toplam rapor sayısının ve confidence skorunun sıfır olduğu durumlar baz alınarak hesaplanmıştır. Bu yöntem, zaman damgası temelli karşılaştırmaların taşıdığı yorum belirsizliğini ortadan kaldırmak için tercih edilmiştir. "Novel detection" is not a date-based comparison; it is calculated based on cases where AbuseIPDB's total report count and confidence score for the given IP are zero. This method was chosen to remove the interpretive ambiguity that timestamp-based comparisons carry.

Önerilen AksiyonlarRecommended Actions

Bu raporda gözlenen saldırı kalıplarına karşı önerilen, kısa ve uygulanabilir savunma adımları: Short, actionable defense steps recommended against the attack patterns observed in this report:

Bu Rapor HakkındaAbout This Report

Bu, SiberKapan Türkiye Tehdit Raporu'nun ilk sayısıdır ve 9 Haziran 2026 – 28 Haziran 2026 veri penceresini kapsamaktadır. Bu nedenle rapor, bir trend analizi değil, bir başlangıç noktasıdır. Gelecek sayılarda dönemsel karşılaştırmalar yapılabilmesi için referans işlevi görecektir. Şeffaflık ilkesi doğrultusunda, aşağıdaki veri kategorileri bu rapora kasıtlı olarak dahil edilmemiştir: This is the first issue of the SiberKapan Turkey Threat Report and covers the data window of June 9 – June 28, 2026. As such, this report is a starting point rather than a trend analysis — it will serve as a reference for periodic comparisons in future issues. In line with the principle of transparency, the following data categories were intentionally excluded from this report:

  • UDP Flood tespitleri: Doğrulama süreci devam eden bir tespit kategorisi olduğu için (yanlış pozitif riski nedeniyle inceleme altında), bu rapordaki hiçbir istatistiğe dahil edilmemiştir.UDP Flood detections: Excluded from every statistic in this report, as this category is still under verification (under review due to false-positive risk).
  • Harici feed kaynaklı toplu veri (örn. malware_distribution): Bu kayıtlar SiberKapan'ın kendi tespiti değil, üçüncü taraf feed'lerden alınan veridir; "organik tespit" istatistiklerinde ayrı tutulmuştur.Bulk data from external feeds (e.g. malware_distribution): These records are not SiberKapan's own detections but data sourced from third-party feeds; kept separate from "organic detection" statistics.