Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Incident Response Lab

Hands-on case studies from real-world-style cybersecurity incidents. Includes end-to-end investigations of phishing and malware alerts using tools like Microsoft Sentinel, Wireshark, and Hybrid Analysis. Built to demonstrate practical skills in SOC analysis, threat hunting, and incident reporting.


Included Case Studies

Case ID Title Description File
001 Malware Analysis – invoice_reader.exe Trojan investigation from SIEM alert and sandbox analysis malware-analysis-case001.md
002 Phishing Investigation (coming soon) Investigation of a spear-phishing email using email headers and IOC enrichment In progress

Tools & Techniques Used

  • Tools: Wireshark, Microsoft Defender, Hybrid Analysis, Any.Run, Procmon, Sysinternals, VirusTotal
  • Techniques: IOC extraction, sandboxing, packet analysis, MITRE ATT&CK mapping, threat containment
  • Frameworks: NIST CSF, ISO 27001

Author

Butool Fatima
Cybersecurity Analyst | MSc Computer Science (UK)
LinkedIn Profile »


How to Use

This repo is meant to demonstrate:

  • Realistic incident response case write-ups
  • Markdown formatting for security documentation
  • Hands-on use of SOC tools and investigative thinking

About

A hands-on cybersecurity project simulating phishing and malware incident response using Splunk, Wireshark, and MITRE ATT&CK

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors