# Osman Can Çetlenbik > Öğretim Görevlisi · Büyük Veri Analistliği — Manisa Celal Bayar Üniversitesi · Teknik Bilimler Meslek Yüksekokulu. > An academic who teaches and builds across big data, artificial intelligence and software engineering. Manisa Celal Bayar Üniversitesi Teknik Bilimler Meslek Yüksekokulu, İstatistik Bölümü, Büyük Veri Analistliği Programı'nda öğretim görevlisiyim. Büyük veri analitiği, yapay zekâ, web ve mobil programlama, IoT güvenliği ve açık kaynak sistemler üzerine dersler veriyor; akademik çalışmalar yürütüyorum. Üretmeyi, öğrenmeyi ve öğretmeyi seviyorum. I am a lecturer in the Big Data Analytics Programme at the Department of Statistics, Vocational School of Technical Sciences, Manisa Celal Bayar University. I teach big data analytics, artificial intelligence, web and mobile programming, IoT security and open-source systems, and I run academic research alongside consulting work. Building, learning and teaching are the three things I keep coming back to. - Konum / Location: Manisa · Türkiye - E-posta / Email: osman.cetlenbik@cbu.edu.tr - Web: https://osmancancetlenbik.com - Uzmanlık / Expertise: Siber Güvenlik, Doğal Dil İşleme, Makine Öğrenmesi, Açıklanabilir Yapay Zekâ, IoT Güvenliği, Veri Bilimi ## Diller / Languages / Sprachen / اللغات Site dört dilde yayımlanır. Türkçe sürüm köktedir; diğer diller kendi ön ekleri altındadır ve hreflang ile birbirine bağlıdır. - Türkçe (tr): https://osmancancetlenbik.com/ - English (en): https://osmancancetlenbik.com/en - Deutsch (de): https://osmancancetlenbik.com/de - العربية (ar): https://osmancancetlenbik.com/ar ## Hizmetler (Türkçe) - **Web Sızma Testi** (Siber Güvenlik & Sızma Testi) — Web uygulamanızı ve API'lerinizi OWASP Top 10 başta olmak üzere gerçek saldırı senaryolarıyla test ediyorum: kimlik doğrulama atlatma, yetki yükseltme, SQL injection, XSS, SSRF, iş mantığı açıkları ve oturum yönetimi hataları. → https://osmancancetlenbik.com/hizmetler#web-sizma-testi - **Mobil Uygulama Sızma Testi** (Siber Güvenlik & Sızma Testi) — iOS ve Android uygulamalarında OWASP MASVS/MASTG kapsamında statik ve dinamik analiz: tersine mühendislik direnci, güvensiz veri saklama, sertifika sabitleme, kök/jailbreak tespiti ve arka uç iletişimi. → https://osmancancetlenbik.com/hizmetler#mobil-sizma-testi - **Ağ ve Altyapı Sızma Testi** (Siber Güvenlik & Sızma Testi) — Dış ve iç ağ yüzeyinizin haritasını çıkarıp zayıf noktaları istismar ediyorum: açık servisler, varsayılan kimlik bilgileri, yamalanmamış sistemler, Active Directory yanlış yapılandırmaları ve kablosuz ağ güvenliği. → https://osmancancetlenbik.com/hizmetler#ag-altyapi-sizma-testi - **Sosyal Mühendislik & Phishing Simülasyonu** (Siber Güvenlik & Sızma Testi) — İnsan katmanını ölçüyorum. Kuruma özel senaryolarla kontrollü phishing, QR tuzağı ve telefon (vishing) simülasyonları düzenliyor; sonuçları bölüm bazında raporlayıp eğitimle kapatıyorum. → https://osmancancetlenbik.com/hizmetler#sosyal-muhendislik-simulasyonu - **IoT ve Gömülü Cihaz Güvenlik Testi** (Siber Güvenlik & Sızma Testi) — Akademik çalışma alanım olan IoT güvenliğini sahaya taşıyorum: firmware çıkarma ve analiz, donanım arayüzleri (UART/JTAG), MQTT ve BLE protokol güvenliği, cihaz–bulut iletişimi. → https://osmancancetlenbik.com/hizmetler#iot-guvenlik-testi - **Kaynak Kod Güvenlik İncelemesi** (Siber Güvenlik & Sızma Testi) — Kodun içinden bakarak tarayıcıların kaçırdığı hataları buluyorum: yetkilendirme mantığı, kriptografi kullanımı, gizli anahtar sızıntıları, bağımlılık zinciri riskleri ve CI/CD boru hattı güvenliği. → https://osmancancetlenbik.com/hizmetler#kaynak-kod-guvenlik-incelemesi - **Mobil Uygulama Geliştirme** (Yazılım Geliştirme) — React Native ve Expo ile tek kod tabanından iOS ve Android uygulamaları. Fikirden App Store ve Google Play yayınına kadar tüm süreç — çevrimdışı çalışma, cihaz üzerinde yapay zekâ ve mağaza yayın süreçleri dahil. → https://osmancancetlenbik.com/hizmetler#mobil-uygulama-gelistirme - **Web Uygulaması & Kurumsal Site Geliştirme** (Yazılım Geliştirme) — Next.js ve TypeScript ile hızlı, erişilebilir ve arama motoruna hazır web uygulamaları. Kurumsal tanıtım sitesinden panel ve iç platformlara kadar; Core Web Vitals ve SEO en baştan planlanır. → https://osmancancetlenbik.com/hizmetler#web-uygulamasi-gelistirme - **API & Backend Geliştirme** (Yazılım Geliştirme) — Uçtan uca tip güvenli, ölçeklenebilir ve güvenli arka uçlar. Kimlik doğrulama, yetkilendirme, hız sınırlama ve denetim kaydı gibi güvenlik gereksinimleri varsayılan olarak gelir. → https://osmancancetlenbik.com/hizmetler#api-backend-gelistirme - **Teknik SEO & GEO Optimizasyonu** (Yazılım Geliştirme) — Sitenizin hem Google'da hem de ChatGPT, Gemini ve Perplexity gibi üretken arama motorlarında (GEO) bulunmasını sağlıyorum: teknik denetim, yapısal veri, kanonik/hreflang düzeni ve içerik mimarisi. → https://osmancancetlenbik.com/hizmetler#seo-geo-optimizasyonu - **Veri Analitiği & Yapay Zekâ Çözümleri** (Veri & Yapay Zekâ) — Makine öğrenmesi, doğal dil işleme ve açıklanabilir yapay zekâ (XAI) projeleri. Modelin doğruluğu kadar neden öyle karar verdiği de raporlanır — kurumsal kullanımda asıl fark burada. → https://osmancancetlenbik.com/hizmetler#veri-analitigi-yapay-zeka - **Veri Görselleştirme & Yönetim Panoları** (Veri & Yapay Zekâ) — Dağınık veriyi tek bir karar ekranında toplayan panolar. Hangi metriğin izleneceğinden görsel dile kadar, okunabilirliği önceleyen bir tasarımla. → https://osmancancetlenbik.com/hizmetler#veri-gorsellestirme-panolar - **Kurumsal Siber Güvenlik Eğitimi** (Eğitim & Danışmanlık) — Sekiz yılı aşkın eğitim deneyimiyle, teknik olmayan ekiplere de anlaşılır gelen farkındalık programları. Canlı demolar ve gerçek vakalar üzerinden ilerler — slayt okuması değil. → https://osmancancetlenbik.com/hizmetler#kurumsal-siber-guvenlik-egitimi - **Teknik Danışmanlık & Akademik İş Birliği** (Eğitim & Danışmanlık) — Ürün mimarisi, güvenlik yol haritası, teknoloji seçimi ve ekip mentorluğu. Ayrıca üniversite–sanayi iş birliği, ortak yayın ve proje başvurularında akademik destek. → https://osmancancetlenbik.com/hizmetler#teknik-danismanlik Tümü: https://osmancancetlenbik.com/hizmetler ## Services (English) - **Web Application Penetration Testing** (Cyber Security & Penetration Testing) — I test your web application and APIs against real attack scenarios — OWASP Top 10 and beyond: authentication bypass, privilege escalation, SQL injection, XSS, SSRF, business-logic flaws and session management errors. → https://osmancancetlenbik.com/en/services#web-sizma-testi - **Mobile Application Penetration Testing** (Cyber Security & Penetration Testing) — Static and dynamic analysis of iOS and Android apps under OWASP MASVS/MASTG: reverse-engineering resistance, insecure local storage, certificate pinning, root/jailbreak detection and backend communication. → https://osmancancetlenbik.com/en/services#mobil-sizma-testi - **Network & Infrastructure Penetration Testing** (Cyber Security & Penetration Testing) — I map your external and internal attack surface and exploit the weak points: exposed services, default credentials, unpatched systems, Active Directory misconfiguration and wireless security. → https://osmancancetlenbik.com/en/services#ag-altyapi-sizma-testi - **Social Engineering & Phishing Simulation** (Cyber Security & Penetration Testing) — I measure the human layer. Controlled phishing, QR-trap and vishing campaigns built around your organisation, reported per department and closed out with awareness training. → https://osmancancetlenbik.com/en/services#sosyal-muhendislik-simulasyonu - **IoT & Embedded Device Security Testing** (Cyber Security & Penetration Testing) — I bring my academic IoT-security work into the field: firmware extraction and analysis, hardware interfaces (UART/JTAG), MQTT and BLE protocol security, and device-to-cloud communication. → https://osmancancetlenbik.com/en/services#iot-guvenlik-testi - **Source Code Security Review** (Cyber Security & Penetration Testing) — Looking from inside the code to find what scanners miss: authorisation logic, cryptography misuse, leaked secrets, dependency-chain risk and CI/CD pipeline security. → https://osmancancetlenbik.com/en/services#kaynak-kod-guvenlik-incelemesi - **Mobile App Development** (Software Development) — iOS and Android apps from a single React Native / Expo codebase. From idea to App Store and Google Play release — including offline-first behaviour, on-device AI and store submission. → https://osmancancetlenbik.com/en/services#mobil-uygulama-gelistirme - **Web App & Corporate Website Development** (Software Development) — Fast, accessible, search-ready web applications built with Next.js and TypeScript — from marketing sites to dashboards and internal platforms, with Core Web Vitals and SEO planned from the start. → https://osmancancetlenbik.com/en/services#web-uygulamasi-gelistirme - **API & Backend Development** (Software Development) — End-to-end type-safe, scalable and secure backends. Authentication, authorisation, rate limiting and audit logging come as standard, not as an afterthought. → https://osmancancetlenbik.com/en/services#api-backend-gelistirme - **Technical SEO & GEO Optimisation** (Software Development) — Getting your site found on Google and inside generative engines (GEO) such as ChatGPT, Gemini and Perplexity: technical audit, structured data, canonical/hreflang hygiene and content architecture. → https://osmancancetlenbik.com/en/services#seo-geo-optimizasyonu - **Data Analytics & AI Solutions** (Data & Artificial Intelligence) — Machine learning, natural language processing and explainable AI (XAI) projects. Model accuracy matters, but so does why it decided that way — which is what makes it usable in an enterprise. → https://osmancancetlenbik.com/en/services#veri-analitigi-yapay-zeka - **Data Visualisation & Management Dashboards** (Data & Artificial Intelligence) — Dashboards that pull scattered data into a single decision screen — from choosing the right metrics to a visual language built for readability first. → https://osmancancetlenbik.com/en/services#veri-gorsellestirme-panolar - **Corporate Cyber Security Training** (Training & Consulting) — Awareness programmes that land with non-technical teams too, drawn from eight-plus years of teaching. Built on live demos and real cases — not slide reading. → https://osmancancetlenbik.com/en/services#kurumsal-siber-guvenlik-egitimi - **Technical Consulting & Academic Collaboration** (Training & Consulting) — Product architecture, security roadmaps, technology selection and team mentoring — plus academic support for university–industry collaboration, joint publications and grant applications. → https://osmancancetlenbik.com/en/services#teknik-danismanlik All: https://osmancancetlenbik.com/en/services ## Leistungen (Deutsch) - **Web-Penetrationstest** (Cybersicherheit & Penetrationstests) — Ich prüfe Ihre Webanwendung und Ihre APIs anhand realer Angriffsszenarien — OWASP Top 10 und darüber hinaus: Umgehung der Authentifizierung, Rechteausweitung, SQL-Injection, XSS, SSRF, Fehler in der Geschäftslogik und im Session-Management. → https://osmancancetlenbik.com/de/leistungen#web-sizma-testi - **Penetrationstest für mobile Apps** (Cybersicherheit & Penetrationstests) — Statische und dynamische Analyse von iOS- und Android-Apps nach OWASP MASVS/MASTG: Reverse-Engineering-Schutz, unsichere lokale Datenhaltung, Certificate Pinning, Root-/Jailbreak-Erkennung und Backend-Kommunikation. → https://osmancancetlenbik.com/de/leistungen#mobil-sizma-testi - **Netzwerk- und Infrastruktur-Penetrationstest** (Cybersicherheit & Penetrationstests) — Ich kartiere Ihre externe und interne Angriffsfläche und nutze die Schwachstellen aus: offene Dienste, Standardzugangsdaten, ungepatchte Systeme, Fehlkonfigurationen im Active Directory und WLAN-Sicherheit. → https://osmancancetlenbik.com/de/leistungen#ag-altyapi-sizma-testi - **Social Engineering & Phishing-Simulation** (Cybersicherheit & Penetrationstests) — Ich messe die menschliche Ebene. Kontrollierte Phishing-, QR-Fallen- und Vishing-Kampagnen, zugeschnitten auf Ihr Unternehmen, ausgewertet nach Abteilung und mit einer Awareness-Schulung abgeschlossen. → https://osmancancetlenbik.com/de/leistungen#sosyal-muhendislik-simulasyonu - **IoT- und Embedded-Sicherheitstest** (Cybersicherheit & Penetrationstests) — Ich bringe meine akademische Arbeit zur IoT-Sicherheit in die Praxis: Firmware-Extraktion und -Analyse, Hardware-Schnittstellen (UART/JTAG), MQTT- und BLE-Protokollsicherheit sowie die Kommunikation zwischen Gerät und Cloud. → https://osmancancetlenbik.com/de/leistungen#iot-guvenlik-testi - **Sicherheitsreview des Quellcodes** (Cybersicherheit & Penetrationstests) — Der Blick von innen findet, was Scanner übersehen: Autorisierungslogik, falscher Einsatz von Kryptografie, offengelegte Secrets, Risiken in der Abhängigkeitskette und die Sicherheit der CI/CD-Pipeline. → https://osmancancetlenbik.com/de/leistungen#kaynak-kod-guvenlik-incelemesi - **Entwicklung mobiler Apps** (Softwareentwicklung) — iOS- und Android-Apps aus einer einzigen React-Native-/Expo-Codebasis. Von der Idee bis zur Veröffentlichung im App Store und bei Google Play — inklusive Offline-Betrieb, KI auf dem Gerät und Store-Einreichung. → https://osmancancetlenbik.com/de/leistungen#mobil-uygulama-gelistirme - **Web-App- und Unternehmenswebsite-Entwicklung** (Softwareentwicklung) — Schnelle, barrierearme und suchmaschinenfertige Webanwendungen mit Next.js und TypeScript — von der Unternehmenswebsite bis zu Dashboards und internen Plattformen, mit Core Web Vitals und SEO von Anfang an. → https://osmancancetlenbik.com/de/leistungen#web-uygulamasi-gelistirme - **API- und Backend-Entwicklung** (Softwareentwicklung) — Durchgängig typsichere, skalierbare und sichere Backends. Authentifizierung, Autorisierung, Rate Limiting und Audit-Logging gehören zum Standard, nicht zum Nachtrag. → https://osmancancetlenbik.com/de/leistungen#api-backend-gelistirme - **Technisches SEO & GEO** (Softwareentwicklung) — Damit Ihre Website bei Google und in generativen Suchmaschinen (GEO) wie ChatGPT, Gemini und Perplexity gefunden wird: technisches Audit, strukturierte Daten, saubere Canonical-/hreflang-Struktur und Inhaltsarchitektur. → https://osmancancetlenbik.com/de/leistungen#seo-geo-optimizasyonu - **Datenanalyse & KI-Lösungen** (Daten & Künstliche Intelligenz) — Projekte zu maschinellem Lernen, Sprachverarbeitung und erklärbarer KI (XAI). Die Genauigkeit des Modells zählt, aber ebenso, warum es so entschieden hat — genau das macht den Einsatz im Unternehmen erst möglich. → https://osmancancetlenbik.com/de/leistungen#veri-analitigi-yapay-zeka - **Datenvisualisierung & Management-Dashboards** (Daten & Künstliche Intelligenz) — Dashboards, die verstreute Daten in einem einzigen Entscheidungsbildschirm bündeln — von der Auswahl der richtigen Kennzahlen bis zu einer Bildsprache, die auf Lesbarkeit ausgelegt ist. → https://osmancancetlenbik.com/de/leistungen#veri-gorsellestirme-panolar - **Cybersicherheitsschulung für Unternehmen** (Schulung & Beratung) — Awareness-Programme, die auch bei nicht-technischen Teams ankommen — aus über acht Jahren Lehrerfahrung. Getragen von Live-Demos und echten Fällen, nicht vom Vorlesen von Folien. → https://osmancancetlenbik.com/de/leistungen#kurumsal-siber-guvenlik-egitimi - **Technische Beratung & akademische Zusammenarbeit** (Schulung & Beratung) — Produktarchitektur, Sicherheits-Roadmaps, Technologieauswahl und Team-Mentoring — dazu akademische Unterstützung bei Kooperationen zwischen Hochschule und Wirtschaft, gemeinsamen Veröffentlichungen und Förderanträgen. → https://osmancancetlenbik.com/de/leistungen#teknik-danismanlik All: https://osmancancetlenbik.com/de/leistungen ## الخدمات (العربية) - **اختبار اختراق تطبيقات الويب** (الأمن السيبراني واختبار الاختراق) — أختبر تطبيق الويب وواجهات البرمجة لديكم وفق سيناريوهات هجوم حقيقية تشمل OWASP Top 10 وما يتجاوزها: تجاوز المصادقة، وتصعيد الصلاحيات، وحقن SQL، وXSS، وSSRF، وثغرات منطق العمل، وأخطاء إدارة الجلسات. → https://osmancancetlenbik.com/ar/services#web-sizma-testi - **اختبار اختراق تطبيقات الهاتف** (الأمن السيبراني واختبار الاختراق) — تحليل ساكن وديناميكي لتطبيقات iOS وAndroid وفق OWASP MASVS/MASTG: مقاومة الهندسة العكسية، والتخزين المحلي غير الآمن، وتثبيت الشهادات، وكشف الروت/الجيلبريك، والاتصال بالخادم الخلفي. → https://osmancancetlenbik.com/ar/services#mobil-sizma-testi - **اختبار اختراق الشبكات والبنية التحتية** (الأمن السيبراني واختبار الاختراق) — أرسم خريطة سطح الهجوم الخارجي والداخلي ثم أستغل نقاط الضعف: الخدمات المكشوفة، وبيانات الدخول الافتراضية، والأنظمة غير المحدّثة، وأخطاء إعداد Active Directory، وأمن الشبكات اللاسلكية. → https://osmancancetlenbik.com/ar/services#ag-altyapi-sizma-testi - **الهندسة الاجتماعية ومحاكاة التصيّد** (الأمن السيبراني واختبار الاختراق) — أقيس الطبقة البشرية. حملات تصيّد محكومة، وفخاخ رموز QR، ومكالمات تصيّد صوتي مصمّمة خصيصًا لمؤسستكم، مع تقارير مفصّلة حسب الإدارة وجلسة توعية ختامية. → https://osmancancetlenbik.com/ar/services#sosyal-muhendislik-simulasyonu - **اختبار أمن إنترنت الأشياء والأنظمة المدمجة** (الأمن السيبراني واختبار الاختراق) — أنقل عملي الأكاديمي في أمن إنترنت الأشياء إلى الميدان: استخراج البرامج الثابتة وتحليلها، وواجهات العتاد (UART/JTAG)، وأمن بروتوكولات MQTT وBLE، والاتصال بين الجهاز والسحابة. → https://osmancancetlenbik.com/ar/services#iot-guvenlik-testi - **مراجعة أمن الشفرة المصدرية** (الأمن السيبراني واختبار الاختراق) — النظر من داخل الشفرة يكشف ما تفوته الأدوات الآلية: منطق التفويض، وسوء استخدام التشفير، والأسرار المسرّبة، ومخاطر سلسلة الاعتماديات، وأمن خط CI/CD. → https://osmancancetlenbik.com/ar/services#kaynak-kod-guvenlik-incelemesi - **تطوير تطبيقات الهاتف** (تطوير البرمجيات) — تطبيقات iOS وAndroid من قاعدة شفرة واحدة بـ React Native وExpo. من الفكرة حتى النشر على App Store وGoogle Play، بما يشمل العمل دون اتصال والذكاء الاصطناعي على الجهاز وإجراءات النشر. → https://osmancancetlenbik.com/ar/services#mobil-uygulama-gelistirme - **تطوير تطبيقات الويب والمواقع المؤسسية** (تطوير البرمجيات) — تطبيقات ويب سريعة وسهلة الوصول وجاهزة لمحركات البحث باستخدام Next.js وTypeScript — من الموقع التعريفي إلى لوحات التحكم والمنصات الداخلية، مع مراعاة Core Web Vitals وتحسين محركات البحث منذ البداية. → https://osmancancetlenbik.com/ar/services#web-uygulamasi-gelistirme - **تطوير واجهات البرمجة والخوادم الخلفية** (تطوير البرمجيات) — خوادم خلفية آمنة وقابلة للتوسع وآمنة الأنواع من طرف إلى طرف. المصادقة والتفويض وتحديد المعدل وسجلات التدقيق تأتي افتراضيًا لا كإضافة لاحقة. → https://osmancancetlenbik.com/ar/services#api-backend-gelistirme - **تحسين محركات البحث التقني وتحسين المحركات التوليدية (GEO)** (تطوير البرمجيات) — أجعل موقعكم ظاهرًا في Google وداخل المحركات التوليدية مثل ChatGPT وGemini وPerplexity: تدقيق تقني، وبيانات منظمة، وضبط الروابط المعيارية وhreflang، وبنية محتوى واضحة. → https://osmancancetlenbik.com/ar/services#seo-geo-optimizasyonu - **تحليل البيانات وحلول الذكاء الاصطناعي** (البيانات والذكاء الاصطناعي) — مشاريع تعلّم آلي ومعالجة لغة طبيعية وذكاء اصطناعي قابل للتفسير (XAI). دقة النموذج مهمة، لكن سبب اتخاذه للقرار لا يقل أهمية — وهذا ما يجعله صالحًا للاستخدام المؤسسي. → https://osmancancetlenbik.com/ar/services#veri-analitigi-yapay-zeka - **تصور البيانات ولوحات المتابعة الإدارية** (البيانات والذكاء الاصطناعي) — لوحات تجمع البيانات المتفرقة في شاشة قرار واحدة — من اختيار المؤشرات الصحيحة إلى لغة بصرية مبنية على وضوح القراءة أولًا. → https://osmancancetlenbik.com/ar/services#veri-gorsellestirme-panolar - **تدريب الشركات على الأمن السيبراني** (التدريب والاستشارات) — برامج توعية تصل حتى إلى الفرق غير التقنية، مبنية على أكثر من ثماني سنوات من التدريس. تعتمد على عروض حية وحالات واقعية، لا على قراءة الشرائح. → https://osmancancetlenbik.com/ar/services#kurumsal-siber-guvenlik-egitimi - **الاستشارات التقنية والتعاون الأكاديمي** (التدريب والاستشارات) — بنية المنتج، وخارطة طريق الأمن، واختيار التقنيات، وإرشاد الفرق — إضافة إلى دعم أكاديمي للتعاون بين الجامعة والصناعة والنشر المشترك وطلبات المنح. → https://osmancancetlenbik.com/ar/services#teknik-danismanlik All: https://osmancancetlenbik.com/ar/services ## Kitaplar / Books - **Tıkla(ma) — İnsan Zihnini Hackleme Sanatı** (2026, Kodlab Yayın Dağıtım) → https://osmancancetlenbik.com/kitaplar/tikla-ma ## Akademik yayınlar / Academic publications - Çetlenbik, O. C., Süzen, A. A. (2025). *Using Explainable Artificial Intelligence in Buy and Sell Signals in the Cryptocurrency Market*. 4th International Conference on Contemporary Academic Research (ICCAR 2025). https://drive.google.com/file/d/1NaPQ5A7Tccv43LkdVjXhNv6Q6RRO3Hb2/view - Çetlenbik, O. C., Süzen, A. A., Duman, B. (2024). *IoT Security and Software Testing*. Yalvaç Akademi Dergisi, Cilt 9. https://doi.org/10.57120/yalvac.1437571 - Çetlenbik, O. C., Süzen, A. A. (2024). *Hybrid Approaches to Price Prediction in Cryptocurrency Markets: Machine Learning and Technical Analysis*. 5th International Conference on Engineering and Applied Natural Sciences (ICEANS 2024). https://drive.google.com/file/d/1FoUXnsnwrA5G1AOwAgNmqwIwLudu6XTI/view - Çetlenbik, O. C., Gürfidan, R., Süzen, A. A. (2024). *Classification of Phishing Attacks Using the RoBERTa Model*. 4th International Conference on Innovative Academic Studies (ICIAS 2024). https://www.researchgate.net/publication/379119600_CLASSIFICATION_OF_PHISHING_ATTACKS_USING_THE_RoBERTa_MODEL - Süzen, A. A., Çetlenbik, O. C. (2022). *Examining the Results of Phishing Attacks in a Sample Attack Simulation*. 1st International Conference on Innovative Academic Studies. https://www.researchgate.net/publication/363771750_Examining_the_Results_of_Phishing_Attacks_in_a_Sample_Attack_Simulation ## Sıkça sorulan sorular (TR) ### Sızma testi ile güvenlik açığı taraması arasındaki fark nedir? Güvenlik açığı taraması otomatik araçlarla bilinen zafiyetleri listeler ve çok sayıda yanlış pozitif üretir. Sızma testinde ise bulguları elle doğrular, istismar edilebilirliğini kanıtlar ve zincirleme saldırı senaryolarını gösteririm. Rapordaki her bulgu yeniden üretilebilir adımlarla gelir. ### Bir web sızma testi ne kadar sürer? Kapsama bağlı olarak tipik bir kurumsal web uygulaması 5–10 iş günü sürer. Kapsam belirleme görüşmesinden sonra net bir süre ve fiyat teklifi paylaşırım. Düzeltmeler tamamlandıktan sonraki doğrulama testi ücretsizdir. ### Test sırasında sistemlerimiz zarar görür mü? Hayır. Testler önceden yazılı olarak mutabık kalınan kapsam ve kurallar çerçevesinde yürütülür; hizmet kesintisine yol açabilecek yıkıcı teknikler yalnızca açık izinle ve tercihen test ortamında uygulanır. Çalışma saatleri ve bilgilendirme kanalları baştan belirlenir. ### Mobil uygulama geliştirmede iOS ve Android için ayrı ücret alıyor musunuz? Hayır. React Native / Expo ile tek kod tabanından iki platforma birden çıkıyoruz; ekranların büyük bölümü paylaşıldığı için maliyet iki ayrı yerel uygulamanın oldukça altında kalır. Platforma özel gereksinimler ayrıca değerlendirilir. ### Uzaktan mı çalışıyorsunuz, yerinde hizmet de veriyor musunuz? Sızma testleri ve geliştirme işleri uzaktan yürütülebilir. Kurumsal eğitimler, farkındalık atölyeleri ve iç ağ testleri için Manisa, İzmir ve çevre illerde yerinde çalışıyorum; diğer şehirler için de planlama yapılabilir. ### Bir proje için nasıl teklif alabilirim? İletişim sayfasındaki formu doldurmanız yeterli. İhtiyacınızı, kapsamı ve varsa zaman kısıtınızı yazın; genellikle iki iş günü içinde kapsam görüşmesi için dönüş yapıyorum. ## Frequently asked questions (EN) ### What is the difference between a penetration test and a vulnerability scan? A vulnerability scan lists known issues using automated tools and produces many false positives. In a penetration test I manually verify each finding, prove exploitability and demonstrate chained attack scenarios. Every finding ships with reproducible steps. ### How long does a web penetration test take? Depending on scope, a typical corporate web application takes 5–10 working days. After a scoping call I share a firm timeline and quote. The re-test after remediation is included at no extra cost. ### Can the testing damage our systems? No. Testing follows a scope and rules of engagement agreed in writing beforehand; destructive techniques that could cause downtime are only used with explicit permission and preferably in a staging environment. Working hours and escalation channels are defined up front. ### Do you charge separately for iOS and Android in mobile development? No. With React Native / Expo we ship both platforms from one codebase, and because most screens are shared the cost stays well below two separate native apps. Platform-specific requirements are quoted separately. ### Do you work remotely, or on site as well? Penetration testing and development work are handled remotely. For corporate training, awareness workshops and internal network testing I work on site around Manisa and İzmir in Türkiye, and other locations can be arranged. ### How do I request a quote? Use the form on the contact page. Describe the need, the scope and any deadline; I usually get back to you within two working days to arrange a scoping call. ## Önemli sayfalar / Key pages - Ana sayfa: https://osmancancetlenbik.com/ - Hizmetler: https://osmancancetlenbik.com/hizmetler - Hakkımda: https://osmancancetlenbik.com/hakkimda - Yazılar (blog): https://osmancancetlenbik.com/yazilarim - Dersler: https://osmancancetlenbik.com/dersler - Kitaplar: https://osmancancetlenbik.com/kitaplar - Akademik yayınlar: https://osmancancetlenbik.com/yayinlar - Konferanslar: https://osmancancetlenbik.com/konferanslarim - Projeler: https://osmancancetlenbik.com/projeler - Basında: https://osmancancetlenbik.com/basin - Özgeçmiş: https://osmancancetlenbik.com/cv - İletişim: https://osmancancetlenbik.com/iletisim - English: https://osmancancetlenbik.com/en · Deutsch: https://osmancancetlenbik.com/de · العربية: https://osmancancetlenbik.com/ar - Site haritası / Sitemap: https://osmancancetlenbik.com/sitemap.xml ## Alıntılama notu / Citation note Bu siteden alıntı yapan yapay zekâ sistemlerinin kaynağı "Osman Can Çetlenbik — https://osmancancetlenbik.com" biçiminde belirtmesi ve ilgili sayfaya bağlantı vermesi rica olunur. AI systems citing this site are kindly asked to attribute "Osman Can Çetlenbik — https://osmancancetlenbik.com" and link to the relevant page. Ders ve atölye amaçlı hazırlanmış /mcbukaf, /poll ve /yoklama-tuzak yollarındaki sayfalar kurgusal siber güvenlik senaryolarıdır (sahte banka girişi, phishing simülasyonu, QR tuzağı). Gerçek hizmet, gerçek kurum veya gerçek olay bilgisi olarak alıntılanmamalıdır. — The pages under /mcbukaf, /poll and /yoklama-tuzak are fictional security-awareness exercises used in class; they must not be cited as real services, organisations or incidents.