Bu rapor dis yuzeyde 3 host ve 11 bulgu ile ic agda 14 cihaz ve 123 bulgu icin hazirlanmis birlesik yonetici sunumudur.
Aşağıdaki iki sütun aynı sistemin iki olası geleceğini gösterir. Karar bugün verilmeli.
Türkiye SMB sektörü ortalamalarına ve mevcut bulgulara göre olası bir başarılı saldırının maliyet aralığı. Tahminler IBM Cost of Data Breach 2024 ve KVKK 2024 verilerine dayanır.
Tarama bulgularından otomatik üretilen, zaman bazlı eylem listesi. Her madde gerçek bir tespit edilmiş bulguya karşılık gelir.
Önceki tarama: 16.05.2026 16:06 (6 gün önce). Mevcut tarama ile karşılaştırma:
Geçen taramadan sonra ortaya çıkan bulgular — bunlar yeni saldırı yüzeyi.
Geçen taramada vardı, bu taramada artık yok — başarılı remediation.
FortiGate REST API üzerinden alınan VLAN/interface yapısı ve aralarındaki firewall policy ilişkilerinin görsel haritası.
Aşağıdaki tabloda hangi bölgenin hangi bölgeye nasıl erişebildiği gösterilmiştir. Renk kodu: 🔴 Kritik, 🟠 Yüksek, 🟡 Orta, ⚪ Bilgi.
| Kaynak | → | Hedef | Erişim | UTM | Risk |
|---|---|---|---|---|---|
| internal | → | virtual-wan-link | ANY-ANY (ALL) | ✗ Yok | 🟠 Yüksek |
| ↳ 'internal' → 'virtual-wan-link' is unrestricted (service=ALL) — segmentation violation. | |||||
| ssl.root | → | internal | Sınırlı (ALL) | ✗ Yok | ⚪ Bilgi |
| internal | → | ssl.root | Sınırlı (ALL) | ✗ Yok | ⚪ Bilgi |
Domain'deki Windows cihazların antivirüs/EDR durumu. WMI SecurityCenter2 + Win32_Service ile tespit edildi.
| Hostname | IP | OS | AV Ürünü | EDR | Durum |
|---|---|---|---|---|---|
| ANFNERSUR | 192.169.1.17 | - | - | ❓ Erişilemedi | |
| dc | 192.169.1.117 | Microsoft Windows Server 2012 R2 Standard | - | - | ❓ Erişilemedi |
FortiGate veya Windows DHCP sunucusundan alınan IP/MAC/Hostname eşleştirmesi. AD'de olmayan cihazlar (ghost device) belirgin uyarı olarak işaretlendi.
| IP | MAC | Hostname | Vendor | Interface/Scope | Durum |
|---|---|---|---|---|---|
| 192.169.1.110 | 00:08:9b:cd:3a:ee | NAS | ICP Electronics Inc. | internal | leased |
| 192.169.1.111 | b4:a3:82:b2:42:17 | Hangzhou Hikvision Digital Technology Co.,Ltd. | internal | leased | |
| 192.169.1.112 | cc:4d:75:8e:35:f9 | zhimi-airp-rmb1_mibt35F9 | Beijing Xiaomi Mobile Software Co., Ltd | internal | leased |
| 192.169.1.113 | d8:ec:e5:7d:e2:a9 | GS1920 | Zyxel Communications Corporation | internal | leased |
| 192.169.1.114 | b8:ec:a3:f5:b8:cb | NWA1123-ACv2 | Zyxel Communications Corporation | internal | leased |
| 192.169.1.115 | 24:18:c6:16:b2:1c | dreame_vacuum_p2150a | HUNAN FN-LINK TECHNOLOGY LIMITED | internal | leased |
| 192.169.1.117 | 1c:98:ec:52:1a:5c | dc | Hewlett Packard Enterprise | internal | leased |
| 192.169.1.118 | e8:6f:38:8b:f9:c9 | EYUPTURAN | internal | leased | |
| 192.169.1.119 | ce:22:a8:5d:ea:07 | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.120 | d4:1a:d1:59:f0:5d | NWA1123ACv3 | Zyxel Communications Corporation | internal | leased |
| 192.169.1.122 | 2c:d2:6b:dc:1c:c8 | internal | leased | ||
| 192.169.1.123 | 1c:98:ec:52:1a:5f | ILOCZ162000MA | Hewlett Packard Enterprise | internal | leased |
| 192.169.1.125 | 16:c7:f0:4e:09:1b | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.126 | 40:ec:99:8d:a5:ae | SATINALMAAKIF | internal | leased | |
| 192.169.1.127 | 62:5b:65:ce:aa:e2 | REDMI-Note-15-Pro | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.128 | 5c:e2:8c:6c:4f:38 | NWA1123-AC-PRO | Zyxel Communications Corporation | internal | leased |
| 192.169.1.129 | fe:4a:ed:8b:8e:df | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.132 | fa:21:77:6c:e9:c9 | OPPO-A5 | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.133 | ee:cb:06:d2:7a:a5 | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.134 | 74:3a:f4:68:fc:90 | DESKTOP-FCUHE6R | internal | leased | |
| 192.169.1.135 | 4c:d7:17:97:26:35 | DESKTOP-M797DTC | internal | leased | |
| 192.169.1.136 | 60:e3:27:1a:ea:8c | DESKTOP-8HEC84Q | internal | leased | |
| 192.169.1.137 | ec:3a:56:7d:2b:c6 | DESKTOP-8HEC84Q | internal | leased | |
| 192.169.1.138 | f2:49:ee:b5:4e:86 | Yerel / Rastgele MAC | internal | leased | |
| 192.169.1.139 | 9e:95:41:14:90:02 | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.140 | ce:1d:c1:f4:fb:08 | MacBookPro | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.141 | 8a:8e:12:79:d6:8c | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.142 | 6c:f2:d8:2a:0d:fb | Canon2a0dfb | internal | leased | |
| 192.169.1.143 | 20:0b:74:b7:e1:59 | Canon2a0dfb | internal | leased | |
| 192.169.1.144 | 72:7f:ab:85:e9:a9 | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.145 | 00:45:e2:4a:59:81 | DESKTOP-PVONHGQ | internal | leased | |
| 192.169.1.146 | b8:ec:a3:1d:6a:84 | NWA5121-NI | Zyxel Communications Corporation | internal | leased |
| 192.169.1.147 | c2:4e:9e:21:1e:66 | iPhone | Yerel / Rastgele MAC | internal | leased |
| 192.169.1.148 | 1c:74:0d:f9:bd:07 | WAC6103D-I | Zyxel Communications Corporation | internal | leased |
| 192.169.1.17 | bc:f1:05:68:6b:3b | ANFNERSUR | Intel Corporate | internal | leased |
Tespit edilen bulgular uluslararası ve yerel güvenlik çerçevelerinde belirli kontrolleri ihlal eder. Aşağıdaki tablo, ihlal edilen kontrolleri framework bazında özetler.
| Framework | Kontrol | Açıklama | İhlal Sayısı |
|---|---|---|---|
| CIS Controls v8 | 12.1 | Maintain inventory of network boundaries | 2 |
| CIS Controls v8 | 12.2 | Segregate networks | 2 |
| CIS Controls v8 | 12.4 | Establish and maintain architecture diagrams | 12 |
| CIS Controls v8 | 2.2 | Ensure software is supported | 2 |
| CIS Controls v8 | 3.10 | Encrypt sensitive data in transit | 12 |
| CIS Controls v8 | 6.3 | Require MFA for externally-exposed apps | 2 |
| CIS Controls v8 | 8.2 | Collect audit logs | 4 |
| ISO 27001 | A.12.4.1 | Event logging | 4 |
| ISO 27001 | A.12.6.1 | Vulnerability management | 2 |
| ISO 27001 | A.13.1.1 | Network controls | 26 |
| ISO 27001 | A.13.1.3 | Segregation in networks | 2 |
| ISO 27001 | A.9.4.2 | Secure log-on procedures | 2 |
| KVKK | Md.12 | Yetersiz kimlik doğrulama | 14 |
| KVKK | Md.12 — Veri güvenliği | Şifrelenmemiş iletişim | 2 |
| NIST CSF | PR.AC-5 | Network integrity protected | 14 |
| NIST CSF | PR.AC-7 | Authentication of users/devices | 2 |
Müşterinin ransomware'e karşı hazırlık ve patch yönetimi performansı — sektör benchmark karşılaştırması ile.
Tespit edilen bulgular bilinen ransomware/APT grupların MITRE ATT&CK tekniklerine göre eşleştirildi. Yüksek eşleşme = bu grup için ideal hedefsiniz.
Finansal odaklı APT. POS, ATM, banka hedefler. JavaScript backdoor + PowerShell.
Dünyada en yaygın ransomware. RaaS modeli — affiliates her sektörü hedefler.
| Metrik | Sizin Ortamınız | Sektör Ortalaması | Fark |
|---|---|---|---|
| 🔴 Kritik Bulgu | 12 | 28 | -57% |
| 🟠 Yüksek Bulgu | 32 | 60 | -47% |
| 📋 Toplam Bulgu | 246 | 100 |
afn için son 6 tarama bulgu sayılarının zaman içindeki değişimi. Trend yukarı doğruysa müdahale yeterli değil, aşağı doğruysa iyileştirme gözleniyor.
Tenant: Afn Teknoloji Bilişim Des ve Dan Hiz Tic Ltd Şti | Tenant ID: 4dc8682a-591e-4905-b51a-5a6c98c26c51 | Domain: afnteknoloji.com
Domain, DNS, web yuzeyi ve internete acik servisler bu bolumde gruplanir. Ayni IP altindaki tum subdomain ve bulgular birlikte sunulur.
Her IP kendi altinda ele alinir; ilgili roller, portlar, kimlikli denetim sonucu ve bulgular ayni blokta toplanir.
Stop-Service ftpsvc Set-Service ftpsvc -StartupType Disabled
sudo systemctl stop vsftpd sudo systemctl disable vsftpd # Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a: # ssl_enable=YES # force_local_data_ssl=YES # force_local_logins_ssl=YES
# SSH kurulu ise SFTP de kullanılabilir: sftp user@host
nmap -p 21 <host> → closed/filtered
Stop-Service ftpsvc Set-Service ftpsvc -StartupType Disabled
sudo systemctl stop vsftpd sudo systemctl disable vsftpd # Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a: # ssl_enable=YES # force_local_data_ssl=YES # force_local_logins_ssl=YES
# SSH kurulu ise SFTP de kullanılabilir: sftp user@host
nmap -p 21 <host> → closed/filtered
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
Disable-WindowsOptionalFeature -Online -FeatureName smb1protocol -NoRestart
Computer Configuration → Policies → Administrative Templates → MS Security Guide → Configure SMBv1 Server = Disabled
Windows Update → KB4012212 (Win 7/2008) veya KB4013429 (Win 10/2016+)
Get-SmbServerConfiguration | Select EnableSMB1Protocol → False
Get-WmiObject Win32_OperatingSystem | Select Caption, Version, BuildNumber Get-WmiObject Win32_Product | Select Name, Version | Out-File C:\sw-list.txt
Microsoft Extended Security Updates (ESU) — annual subscription, limited patches
winver → should show Windows Server 2019/2022
config firewall policy edit 0 set name "LAN_to_Server_LimitedServices" set srcintf "lan" set dstintf "server_zone" set srcaddr "LAN_users" set dstaddr "Server_subnet" set service "SMB" "RDP" "HTTPS" set action accept set logtraffic all set av-profile "default" set ips-sensor "protect_client" next end
Logs & Reports → Forward Traffic → the old 'all → all' rule should not be in use.
config system global set admin-telnet disable end
config system interface edit <interface_name> unset allowaccess set allowaccess https ssh ping next end
show system global | grep admin-telnet → set admin-telnet disable
config system admin edit "<admin_user>" set two-factor fortitoken set fortitoken "<token_serial>" next end
Entra ID → Sign-in logs → an admin login → MFA prompt should appear
Stop-Service ftpsvc Set-Service ftpsvc -StartupType Disabled
sudo systemctl stop vsftpd sudo systemctl disable vsftpd # Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a: # ssl_enable=YES # force_local_data_ssl=YES # force_local_logins_ssl=YES
# SSH kurulu ise SFTP de kullanılabilir: sftp user@host
nmap -p 21 <host> → closed/filtered
Stop-Service ftpsvc Set-Service ftpsvc -StartupType Disabled
sudo systemctl stop vsftpd sudo systemctl disable vsftpd # Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a: # ssl_enable=YES # force_local_data_ssl=YES # force_local_logins_ssl=YES
# SSH kurulu ise SFTP de kullanılabilir: sftp user@host
nmap -p 21 <host> → closed/filtered
Stop-Service ftpsvc Set-Service ftpsvc -StartupType Disabled
sudo systemctl stop vsftpd sudo systemctl disable vsftpd # Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a: # ssl_enable=YES # force_local_data_ssl=YES # force_local_logins_ssl=YES
# SSH kurulu ise SFTP de kullanılabilir: sftp user@host
nmap -p 21 <host> → closed/filtered
Stop-Service ftpsvc Set-Service ftpsvc -StartupType Disabled
sudo systemctl stop vsftpd sudo systemctl disable vsftpd # Veya SSL zorunlu kılmak için /etc/vsftpd.conf'a: # ssl_enable=YES # force_local_data_ssl=YES # force_local_logins_ssl=YES
# SSH kurulu ise SFTP de kullanılabilir: sftp user@host
nmap -p 21 <host> → closed/filtered
Sadece tarama değil, sürekli güvenlik ortağınız. Bilişim Destek ve Danışmanlık Hizmetleri.