Self-directed project
Fundamentals of Cybersecurity
Cybersecurity · July 2026
A ProoV case study · educational project, not employment
Built a complete beginner SOC incident response workflow from phishing triage through containment and executive reporting. The work identified a malicious email, isolated the anomalous Rotterdam login as the compromise point, mapped events to kill-chain stages, and drafted a GDPR-style breach notification and incident summary grounded in the observed facts. The capstone also translated the real Continental case into a concrete control recommendation focused on exfiltration monitoring.
Graded against
- Threat Triage & Detection20%
- Log Analysis & Investigation30%
- Incident Response & Containment20%
- Compliance & Breach Notification15%
- Executive Communication & Lessons15%
Passed · pass mark 60/100
What stood out6
- Correctly identified the phishing email as malicious and caught 3 of 4 critical red flags without false positives.
- Flagged the impossible-travel login row and tied it to the compromise path instead of treating the alert as generic noise.
- Sequenced containment in a sensible order that cut access first and avoided destructive actions.
- Used the Continental case to justify egress/exfiltration monitoring with the concrete 40TB / 4-week dwell-time fact.
- Leakage-Free Threat Triage
- Anomaly-Driven Log Investigation
The work I submitted18 tasks
10 tasks · 6.5k characters · 8 written answers · 387 words
- Phishing Triage188 characters
- Killchain Map244 characters
- Log Triage170 characters
- Ioc Extraction176 characters
- Containment Plan373 characters
- Breach Notification1.5k characters
- Incident Report2.1k characters
- Recommendations649 characters
- Real Case Analysis432 characters
- Teach Back649 characters
- Phishing Triage8 words
- Killchain Map12 words
- Log Triage9 words
- Ioc Extraction8 words
- Containment Plan14 words
- Breach Notification165 words
- Incident Report158 words
- Recommendations13 words
Summarised on purpose — the submitted code and writing stay private so this page cannot be reused as an answer key. The full submission sits behind the verified certificate.