This repository demonstrates practical cybersecurity projects focused on threat detection, SIEM monitoring, and incident analysis.
- Detected brute-force attacks using KQL queries
- Analyzed Windows Security Event logs (Event ID 4625)
- Performed incident investigation and response
- Investigated phishing email headers (SPF/DKIM)
- Extracted Indicators of Compromise (IOCs)
- Used VirusTotal and URLScan for threat validation
- Detected suspicious login activity using SPL queries
- Identified brute-force and credential stuffing patterns
- Performed log-based threat analysis
- SIEM Tools: Microsoft Sentinel, Splunk
- Log Analysis & Threat Detection
- KQL & SPL Query Writing
- Incident Response & Investigation
- Phishing Analysis & IOC Extraction
Naba Maqsood
https://github.com/NabaMqsood/Cybersecurity-Portfolio
Each project includes real analysis screenshots demonstrating:
- SIEM dashboards
- Detection queries
- Threat investigation results