Triveni Jadhav

Create your portfolio with ProoVCreate your portfolio with ProoV
ProoV
DE Verified work portfolio

ProoV Portfolio

Triveni Jadhav

Computer Science · SPPU

View the ProoV leaderboard

Projects

Certified

Self-directed project

Fundamentals of Cybersecurity

Cybersecurity · July 2026

84/ 100

Built an end-to-end incident response analysis for a phishing-led intrusion: triaged the email as malicious, reconstructed the attacker path from auth logs, mapped the activity to kill-chain stages, and chose a containment sequence that cut access before remediation. Also drafted a GDPR-style breach notification and a structured executive incident report with timeline, impact, and control recommendations.

Graded against

  • Threat Triage & Detection20%
  • Log Analysis & Investigation30%
  • Incident Response & Containment20%
  • Compliance & Breach Notification15%
  • Executive Communication & Lessons15%

Passed · pass mark 60/100

What stood out6
  • Caught the phishing indicators with no false positives on the triage task and identified the email as malicious.
  • Flagged the anomalous authentication rows and explicitly caught impossible travel in the log investigation.
  • Selected a containment order that isolates the host before disabling the account and blocking indicators.
  • Produced a structured incident report with timeline, root cause, impact, and recommendations.
  • Leakage-Free Incident Triage
  • Log-Based Attack Path Reconstruction
The work I submitted9 tasks

Phishing Triage

My solution
{"prompt":"Flag the red flags in the phishing email","flagged":["urgency","attachment","greeting","link"],"caughtCritical":3,"totalCritical":4,"falsePositives":0,"passed":false,"attempt":2}

Killchain Map

My solution
{"prompt":"Map each observed event to its kill-chain stage","mappings":{"phish":"Delivery","run":"Exploitation","creds":"Installation","login":"Command & Control","exfil":"Actions on Objectives"},"correct":5,"total":5,"passed":true,"attempt":1}

Log Triage

My solution
{"prompt":"Flag the anomalous sign-in rows in the auth log","flaggedRows":["r3","r4","r5","r7","r8"],"caughtImpossibleTravel":true,"badCaught":5,"falsePositives":0,"passed":true,"attempt":1}

Ioc Extraction

My solution
{"prompt":"Select the real Indicators of Compromise to block","selected":["ru-host","attachment","c2","attacker-ip"],"iocsCaught":4,"benignBlocked":0,"passed":true,"attempt":1}

Containment Plan

My solution
{"prompt":"Choose and order the sound containment actions; cut access first; avoid the destructive ones.","selected":["isolate-host","disable-account","block-iocs","force-reset"],"order":["isolate-host","disable-account","block-iocs","force-reset"],"avoidedBad":["re-image","alert-all"],"soundCaught":4,"destructiveChosen":0,"accessCutFirst":true,"passed":true,"attempt":1}

Breach Notification

My solution
{"prompt":"Draft the GDPR Art. 33 72-hour breach notification to the supervisory authority.","text":"On 02:14 (INC-4471), Falkenstein Automotive became aware of a phishing attack that compromised an employee account and exposed personal data. \nAffected: Markus Weber and likely the data present on his laptop\nConsequences: unauthorized access, credential misuse, leaking of data\nMeasures taken: The compromised account was isolated and the attacker was blocked, the credentials were reset\n","charCount":387,"elementsCovered":["nature","data","consequences","measures"],"passed":true,"attempt":1}

Incident Report

My solution
{"prompt":"Write the incident report (Summary / Timeline / Root cause / Impact / Recommendations)","sections":{"summary":"At 02:14 (INC-4471), Falkenstein Automotive identified a phishing attack that compromised an employee account. The attacker used stolen credentials to access company resources before the incident was detected and contained.","timeline":"23:07: Phishing email delivered to Markus. Shortly after: Markus opened the email and executed the malicious attachment. Malware harvested credentials and established persistence. ~02:00: Stolen credentials were used to log in from Rotterdam and access the finance file share. 02:14: SIEM detected the suspicious activity. The compromised host was isolated, the account disabled, IoCs blocked, and credentials reset.","rootCause":"The user had no MFA so just one click compromised his account. and since he had more access than required for his role, the company's security was also compromised.","impact":"One employee account was compromised through phishing, allowing unauthorized access to company resources and the finance file share. Credentials were stolen, creating a risk of unauthorized access and potential exposure of personal and business data. The incident was contained before wider lateral movement or ransomware deployment was observed.","recommendations":"Enforce MFA to all the accounts, train the employees for identifying phishing attacks, Enable role-based access in the company, monitor logs."},"charCount":1290,"sectionsAddressed":["summary","timeline","rootCause","impact","recommendations"],"passed":true,"attempt":1}

Recommendations

My solution
{"prompt":"Rate each control on impact and effort; order by priority (quick wins first)","ratings":{"mfa":{"impact":3,"effort":1},"awareness":{"impact":3,"effort":2},"least-privilege":{"impact":2,"effort":2},"endpoint":{"impact":2,"effort":3},"segmentation":{"impact":2,"effort":3}},"ranking":[{"rank":1,"control":"mfa","impact":3,"effort":1,"score":5},{"rank":2,"control":"awareness","impact":3,"effort":2,"score":4},{"rank":3,"control":"least-privilege","impact":2,"effort":2,"score":2},{"rank":4,"control":"endpoint","impact":2,"effort":3,"score":1},{"rank":5,"control":"segmentation","impact":2,"effort":3,"score":1}],"passed":true,"attempt":1}

Real Case Analysis

My solution
{"prompt":"Real case: which ONE control would have most reduced the damage, and why?","text":"The single control i'd prioritise is log monitoring. In this case, there was a time of over 4 weeks in which the attack could've been detected and hence contained. It'd have stopped the attacker before getting all the data and also we could've then spotted the weakness of our system and then improve it so as to be better prepared if any attackes occur in the future.","charCount":368,"controlsNamed":["monitoring / detection"],"passed":true,"attempt":1}
Verified certificateTamper-proof · issued by ProoV
1Project completed
1Verified certificate
84Average score
Create your portfolio with ProoV