24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Public Administration · 2024
Public Administration · Case 2024

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

An APT group that had stayed active for 14 months in the systems of a metropolitan municipality was detected by the DSET threat hunting team. Finance · archive · waste management data had been exfiltrated. A comprehensive cleanup in coordination with USOM.

Duration
3 months (hunting + cleanup)
Scope
2,400 endpoints · 14-month intrusion
Customer Satisfaction
★★★★★

01 The Challenge

The municipality's SIEM system was issuing anomalous C2 traffic alerts but they had been dismissed as "probably internal IT." When DSET threat hunting stepped in, it became clear the APT group had been inside for 14 months. The start: the waste collection management system (a user with a weak password). Then: finance · personnel records · the archive. A total of ~340 GB of data had been exfiltrated.

02 DSET's Approach

01

MITRE ATT&CK mapping

The C2 traffic patterns aligned with APT28 (Fancy Bear) TTPs. The custom backdoor used was identified as an 'X-Agent' derivative.

02

Threat hunting

Through memory forensics + endpoint trace analysis, a persistent presence was detected on 47 different hosts. Processes disguised as system services.

03

Choke point

To avoid losing the connection to the C2 server, the attacker was exfiltrating data slowly. A DNS tunnel + an exfiltration channel hidden inside images were detected.

04

USOM coordination

IoC sharing with USOM · blocking of the C2 IPs across Turkey · a proactive warning to the relevant public institutions.

05

Eradication

A controlled and simultaneous cleanup · all persistence mechanisms were removed before the attacker realized they were being cornered.

06

Hardening

A tier-2 admin model · LAPS · network segmentation · just-in-time access · closing off the attacker's return paths.

03 Results in Numbers

14 months → 3 weeks
Detection Time
47 hosts cleaned
Affected Endpoints
~340 GB (detected)
Data Leakage
61 indicators shared
USOM IoC
0 (18 months)
Re-intrusion
Re-tested 6 months later
Exercise

04 Customer Testimonial

"

There were SIEM alerts but we had accepted them as 'normal traffic.' 3 weeks after DSET arrived we learned there had been a 14-month intrusion. It was a major wake-up call.

Information Systems Manager
Metropolitan Municipality
★★★★★

05 Key Takeaways

A SIEM alert is not dismissed as 'internal IT' · root cause analysis is essential
APT groups stay silent for months · proactive threat hunting is needed
Even a waste management system can be a door into finance · network segmentation
Coordination with USOM · prevents the spread of attacker TTPs

06 Services Used in This Case

Digital Forensics

Trust in evidence is trust in justice.

KAOS Local Artificial Intelligence

Turkey's cyber guardian · local · independent · on the path to world leadership.

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
Healthcare

Ransomware at a 250-bed private hospital · full recovery within 48 hours

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms