Lab 02: Splunk Log Analysis & Security Event Investigation
In this lab, I used Splunk to investigate SSH authentication activity and identify potential security threats. Analyzed failed and successful login events, manually extracted fields, and correlated source IP addresses to distinguish between malicious behavior and normal background scanning.
Lab 03: Authentication Failure Analysis and Correlation in Wazuh
This lab focused on investigating repeated authentication failures in Wazuh and determining when the activity transitioned from a false positive to a true positive. I analyzed alert escalation behavior, evaluated frequency and time-based patterns, and correlated failed login attempts with a subsequent successful authentication.
Lab 04:Microsoft Entra ID Authentication Investigation
This lab focused on investigating authentication activity in Microsoft Entra ID to analyze failed and successful sign-in events through a SOC lens.
Lab 05: Email Analysis
Here I go through a simple process of evaluating a potential malicious email.




