Lead Threat Hunter, Aramis Group PhD, Web Security Paris, France

Onur Catakoglu

I build the detection and response layer, and I like to watch attackers work before I decide what to catch them with.

12 yrsin security
PhDweb security
4 teamsled or founded
3 paperspeer reviewed
The short versionTwelve years, one recurring obsession.

I started in a research lab, not a SOC. My PhD at EURECOM was spent standing up honeypots on the open web and reading what came back: thousands of attackers poking at deliberately weak applications, then doing whatever they actually do once they are inside. That habit of studying behaviour first and writing rules second has followed me into every job since.

From there I went industrial. At Amadeus I built the automation layer for three SOC teams, including an in-house SOAR and the pipelines feeding three different SIEMs. At Glovo I hired and led a cyber defense team of four, and learned what incident command feels like when the company is still trading through the incident. At Dataiku I was the first dedicated security engineer, which meant writing the procedures, choosing the tooling and answering the auditors, all in the same quarter.

Today I am at Aramis Group, building a group-wide threat monitoring and response platform on open source foundations for subsidiaries across several countries. Detection as code, automation wherever a human is doing something twice, and standards that the engineering teams can actually live with.

The obsession

Honeypots

A honeypot is the only place you get to watch an attacker instead of reading about one.

Threat reports tell you what somebody concluded. A honeypot tells you what happened: which payload landed, what got pulled down next, how the shell was used, what the operator typed when the automation stopped and a person took over. The post-exploitation phase is where the interesting behaviour lives, and it is the part almost nobody instruments.

I have been building and running them since 2014, first for a doctorate and later against scraping bots in production. Most of my detection logic starts as something I saw an attacker do rather than something I read in a matrix.

LeadershipWhere I carried the responsibility, not the ticket.
  • Incident commander on high-severity incidents Ran response on major incidents at Glovo and Aramis Group, out of more than twenty handled by the team, and wrote the crisis management runbooks still in use.
  • Founded a security function as the first dedicated hire At Dataiku, stood up procedures, tooling benchmarks and audit workstreams for SOC 2 Type 2 and ISO 27001 with nobody to inherit them from.
  • Built and led a cyber defense team Hired and ran four engineers at Glovo across threat detection and incident response, with on-call guidelines and playbooks written from scratch.
  • Set group-wide security standards across subsidiaries Defined corporate and infrastructure security practice for Aramis Group's operating companies in multiple countries, backed by the monitoring platform that evidences it.
  • Architected SIEM and custom SOAR for enterprise SOCs Designed ingestion across three SIEM platforms and built an in-house SOAR with a Python playbook library serving three SOC teams at Amadeus.
Track recordAn event stream. Newest first.
2023 · 11present

Aramis Group

Lead Threat Hunter

Paris, France

Building the group's threat monitoring and response capability from the ground up, for subsidiaries in several countries.

  • Built the platform on open source foundations: Elasticsearch, Kibana, ElastAlert, then ELK SIEM rules as the detection catalogue grew.
  • Integrated telemetry from Microsoft Entra ID, Defender, SentinelOne, Google Workspace, GCP, AWS CloudWatch and Keycloak into one surface.
  • Introduced Detection as Code for rule management, and maintain Shuffle SOAR so routine triage stops reaching a human.
  • Write incident response playbooks, run tabletop exercises, and take incident command when something real lands.
  • Set security standards for corporate and infrastructure IT, and move DevSecOps practice into the engineering workflow.
2023 · 012023 · 08

Dataiku

Lead Security Engineer

Paris, France

First dedicated security engineer, building the function and its operating model.

  • Wrote the security procedures, guidelines and internal policy set, and acted as the point of contact for engineering and business teams.
  • Contributed to SOC 2 Type 2 and ISO 27001 audit workstreams.
  • Benchmarked the toolkit across EDR, SIEM, email gateway and password management, and assessed DLP capability on a dedicated test bed.
  • Reviewed and hardened joiner and leaver processes with IT and People teams.
2021 · 082022 · 12

Glovo

Cyber Defense Lead

Barcelona, Spain

Built and led the cyber defense team covering threat detection and incident response.

  • Hired and ran a team of four across two streams, detection and response.
  • Acted as incident commander on several high-severity incidents, out of more than twenty handled overall.
  • Wrote on-call guidelines, crisis management runbooks and response playbooks, and contributed to incident response policy and risk assessment.
  • Started the in-house SOAR platform project and deepened the team's AWS and cloud risk coverage.
2018 · 062021 · 08

Amadeus IT Group

Information Security Architect

Sophia-Antipolis, France

Application SOC and later the global SOC, owning the integration and automation layer behind security and fraud investigations.

  • Built an in-house SOAR in Python with integration libraries and a large playbook catalogue, plus ingestion and export pipelines across Splunk, QRadar and Logz.io and two ticketing systems.
  • Administered TheHive for three SOC teams and wrote the response tooling analysts used daily.
  • Led a honeypot-style project to identify unwanted scraping bots and cut their cost impact on backend systems.
  • Led synthetic monitoring of customer-facing frontends to surface security gaps and compromised third parties.
  • Handled very high severity incidents involving customer applications and data exposure, and ran vendor PoCs across threat intelligence, WAF, RASP, SIEM, SOAR and bot mitigation.
2014 · 022017 · 12

EURECOM

Security Researcher, PhD

Sophia-Antipolis, France

Studied attacker behaviour on the web, with honeypots as the instrument.

  • Designed, deployed and operated web honeypots to collect attack data at scale.
  • Developed methods to extract indicators of compromise automatically from web application attacks, published at WWW, RAID and SAC.
  • Analysed post-exploitation activity and the abuse of server-side request functionality.
2013 · 092014 · 01

LOGO Siber Güvenlik ve Ağ Teknolojileri

Software Developer

Istanbul, Turkey

  • Developed modules for a next-generation firewall, covering licensing, DHCP and Java RMI components.
2011 · 032013 · 07

Sabancı University

Research and Teaching Assistant

Istanbul, Turkey

  • Researched wireless sensor network security and designed a cryptographic key pre-distribution scheme for multi-phase deployments.
  • Taught alongside faculty on software engineering, computer networks, and computer and network security.
ToolkitFilled means daily depth. Outlined means solid working knowledge.

Detection and response

Threat hunting Detection engineering Incident response Incident command Detection as Code Sigma SOC operations Tabletop exercises Post-exploitation analysis

Platforms

Elastic Stack ELK SIEM Shuffle SOAR Elastic Fleet ElastAlert TheHive Splunk QRadar SentinelOne Defender Burp Suite

Cloud and infrastructure

AWS security GCP security Linux hardening Microsoft Entra ID Google Workspace Okta Keycloak Terraform Containers Azure

Automation and code

Python Bash Playbook design Log pipelines API integration SQL Java C and C++ PHP JavaScript

Filled chips are what I use every week.

PublishedPeer reviewed, and still relevant to the day job.
Automatic Extraction of Indicators of Compromise for Web Applications International World Wide Web Conference, WWW 2016
Attacks Landscape in the Dark Side of the Web ACM Symposium on Applied Computing, SAC 2017Best paper, security track
Uses and Abuses of Server-Side Requests Research in Attacks, Intrusions and Defenses, RAID 2016
Uneven Key Pre-Distribution Scheme for Multi-Phase Wireless Sensor Networks Wireless sensor network security
Education
PhD, Computer and Information Systems Security
EURECOM · 2014 - 2017
Web security and attacker behaviour: honeypot design, large-scale attack data collection, automated IOC extraction.
MSc, Computer Science and Engineering
Sabancı University · 2011 - 2013
Wireless sensor network security. TÜBİTAK research project scholarship.
BSc, Computer Science and Engineering
Sabancı University · 2006 - 2011
Achievement scholarship, top 0.17% in the national entrance examination.
Say hello

No plain-text address on this page. If you work in security you already know why, and if you write scrapers for a living, consider this a small toll.

$ python3 -c "print('mronur' + '89' + chr(64) + 'gmail' + chr(46) + 'com')"

Away from the keyboard it is mostly cooking, books and a guitar. I played CTFs for years, and these days I would rather pull apart a real payload out of a honeypot than grind a contrived one.