Ahmet Goker
Threat Intelligence & OSINT Analyst
Dutch citizen, full EU work authorisation
linkedin.com/in/ahmet-gökergithub.com/0xCD4csintresearch.org
- 4 yearshands-on security experience
- 207checked OSINT sources
- 22investigation workflows
Profile
Threat intelligence and OSINT analyst with four years of hands-on experience in open source investigations, threat research, security operations and mobile application security. Founder of CSINT Research, where I build source-checked intelligence workflows, analyst tools and research automation. Experienced in collection, validation, enrichment, IOC and CVE analysis, and clear intelligence reporting.
Core Skills
OSINT & Threat Intelligence collection planning, query design, source validation, metadata analysis, infrastructure pivoting, network and domain analysis, CVE verification, OPSEC, sock puppet management, automated collection with n8n, intelligence reporting.
Security Operations Elastic Stack, Kibana, log analysis, SIEM monitoring, vulnerability scanning, incident context and triage.
Engineering & Tooling Python, Bash, Linux, Nmap, Burp Suite, Wireshark, MobSF, Frida, DynamoRIO.
Frameworks MITRE ATT&CK, OWASP MASVS, NIS2, NIST CSF, ISO 27001.
Experience
Founder, Threat Intelligence & OSINT Researcher
- Built and run a public OSINT and threat intelligence site with 207 checked sources, 34 research categories and 22 step-by-step investigation workflows.
- Track CVEs and threat changes with CISA KEV, FIRST EPSS, NVD, vendor advisories and public IOC reports. Each record keeps its source link and review date.
- Built tools for IOC extraction, CVE review, email header analysis, web evidence capture, redirect checks, file comparison and static file analysis.
- Turn verified CVE and IOC data into analyst notes and draft Sigma, YARA, Suricata, KQL and Splunk detection content, with clear review warnings.
- Built Event Desk workflows for collecting evidence, linking entities, tracking source changes and preparing reports while keeping analyst approval in the process.
- Use Next.js, TypeScript and Python for the site, with Cloudflare Workers, D1, KV, R2 and Browser Rendering for APIs, storage, scheduled jobs and screenshots.
- Run a bilingual Telegram research desk with separate daily OSINT and Threat Intelligence, Blue Team and Red Team rotations, GitHub screenshots, source links, review notes and per-stream duplicate controls.
- Write practical OSINT notes, handbooks and lab cases about source checks, OPSEC, fact versus inference, confidence and legal limits.
Cyber Security Specialist
- Collected and analysed open source information to translate online threat activity into actionable security guidance for internal and client facing use.
- Automated collection, enrichment and validation pipelines using n8n and OSINTDog, significantly reducing manual research time per investigation.
- Produced threat context to support detection and response, working with Elastic Stack for SIEM monitoring and log analysis.
- Designed and built CTF labs, malware analysis environments and blue and red team exercise scenarios.
- Supported penetration tests and vulnerability assessments across web and network targets.
Cybersecurity Instructor
- Develop and deliver technical course material on network security, penetration testing and defensive fundamentals.
- Translate complex security topics into structured, practical material for mixed experience audiences.
Mobile Security Researcher
- Performed security research and penetration testing on Android and iOS applications against the OWASP MASVS standard.
- Conducted static and dynamic analysis of application behaviour, API traffic and permission models using MobSF and Frida.
Threat Cases Operator
- Monitored and analysed logs in Kibana for threat detection across critical environments.
Malware Analyst Intern
- Carried out binary analysis, fuzzing and vulnerability research on malware samples.
Education
BSc Computer Engineering
- Nuffic credential evaluation, 2026. Equivalent to a Dutch WO bachelor's degree in computer science.
- Thesis on DynamoRIO based dynamic binary instrumentation for Linux malware analysis.
Certifications
GIAC Open Source Intelligence, GOSI exam scheduled 1 October 2026.
eMAPT eLearnSecurity Mobile Application Penetration Tester.
Additional CNPEN Certified Network Pentester, CBTEAMER Certified Blue Teamer, CBFRPRO Binary Fuzzing & Reversing.
Languages
DutchEnglishTurkish
Additional
Active CTF player on Hack The Box and TryHackMe. Maintainer of csintresearch.org and open source tooling on github.com/0xCD4.

