
Developed a SIEM-based threat detection and traffic analysis system using Splunk to monitor and analyze security events in real time. Created detection use cases aligned with the MITRE ATT&CK framework for phishing, brute-force attacks, and anomalous network behavior. Performed log correlation, IOC-based threat hunting, and HTTP/network traffic analysis to identify suspicious activities and improve incident detection. The project strengthened skills in SIEM operations, threat analysis, incident response, and security monitoring.
If I were to do this project again, I would focus on making it more production-ready by integrating additional log sources such as firewall, DNS, and cloud security logs to improve visibility. I would also enhance the detection use cases with behavioral analytics, automate incident response using SOAR playbooks, and incorporate threat intelligence feeds for better IOC correlation. Additionally, I would perform more extensive performance testing and optimize alert tuning to further reduce false positives while maintaining high detection accuracy.