Network Traffic Analysis with Wireshark and Snort
- Captured and analyzed live network traffic to detect malicious activity. Configured Snort IDS rules to detect ICMP and SSH traffic patterns, evaluated alerts, and reported incidents.
SIEM Dashboard Implementation (Splunk or ELK)
- Deployed and configured a Security Information and Event Management (SIEM) tool to aggregate and visualize logs. Created dashboards for malware detection, user activity, and threat intelligence monitoring.
Windows Security Hardening Project
- Hardened a Windows 10/11 system by modifying registry settings, configuring Group Policy Objects (GPOs), and implementing security baselines. Documented improvements in system resilience.
Incident Response Tabletop Exercise
- Collaborated in a simulated cyber incident scenario. Responded to a ransomware attack by analyzing logs, coordinating containment strategies, and presenting an incident response plan.