Self-directed project
Fundamentals of Cybersecurity
Cybersecurity · August 2026
A ProoV case study · educational project, not employment
Built a complete beginner SOC incident workflow end to end: triaged a phishing email, mapped observed activity to the cyber kill chain, identified an impossible-travel login, extracted the relevant IOCs, and ordered containment actions to cut access quickly. Also produced a structured incident report and correctly argued that MFA would have broken the attack chain in the Continental LockBit case, reducing the risk of large-scale exfiltration.
Graded against
- Threat Triage & Detection20%
- Log Analysis & Investigation30%
- Incident Response & Containment20%
- Compliance & Breach Notification15%
- Executive Communication & Lessons15%
Passed · pass mark 60/100
What stood out6
- Correctly flagged all four phishing red flags with zero false positives
- Identified the impossible-travel sign-in and isolated the compromised row without over-flagging
- Sequenced containment to cut access first by disabling the account before broader actions
- Chose MFA as the single most effective control for the real Continental case and tied it to the ~40 TB exfiltration risk
- Leakage-Free Threat Triage
- Log-Based Anomaly Detection
The work I submitted18 tasks
10 tasks · 4.3k characters · 8 written answers · 220 words
- Phishing Triage186 characters
- Killchain Map244 characters
- Log Triage170 characters
- Ioc Extraction176 characters
- Containment Plan373 characters
- Breach Notification400 characters
- Incident Report1.0k characters
- Recommendations648 characters
- Real Case Analysis411 characters
- Teach Back688 characters
- Phishing Triage8 words
- Killchain Map12 words
- Log Triage9 words
- Ioc Extraction8 words
- Containment Plan14 words
- Breach Notification36 words
- Incident Report120 words
- Recommendations13 words
Summarised on purpose — the submitted code and writing stay private so this page cannot be reused as an answer key. The full submission sits behind the verified certificate.