Triveni Jadhav

Erstelle dein Portfolio mit ProoVErstelle dein Portfolio mit ProoV
ProoV
EN Verifiziertes Arbeitsportfolio

ProoV Portfolio

Triveni Jadhav

Computer Science · SPPU

Zum ProoV-Leaderboard

Projekte

Zertifiziert

Selbstgesteuertes Projekt

Fundamentals of Cybersecurity

Cybersicherheit · Juli 2026

84/ 100

Built an end-to-end incident response analysis for a phishing-led intrusion: triaged the email as malicious, reconstructed the attacker path from auth logs, mapped the activity to kill-chain stages, and chose a containment sequence that cut access before remediation. Also drafted a GDPR-style breach notification and a structured executive incident report with timeline, impact, and control recommendations.

Bewertet nach

  • Threat Triage & Detection20%
  • Log Analysis & Investigation30%
  • Incident Response & Containment20%
  • Compliance & Breach Notification15%
  • Executive Communication & Lessons15%

Bestanden · Bestehensgrenze 60/100

Was herausstach6
  • Caught the phishing indicators with no false positives on the triage task and identified the email as malicious.
  • Flagged the anomalous authentication rows and explicitly caught impossible travel in the log investigation.
  • Selected a containment order that isolates the host before disabling the account and blocking indicators.
  • Produced a structured incident report with timeline, root cause, impact, and recommendations.
  • Leakage-Free Incident Triage
  • Log-Based Attack Path Reconstruction
Meine eingereichte Arbeit9 Aufgaben

Phishing Triage

Meine Lösung
{"prompt":"Flag the red flags in the phishing email","flagged":["urgency","attachment","greeting","link"],"caughtCritical":3,"totalCritical":4,"falsePositives":0,"passed":false,"attempt":2}

Killchain Map

Meine Lösung
{"prompt":"Map each observed event to its kill-chain stage","mappings":{"phish":"Delivery","run":"Exploitation","creds":"Installation","login":"Command & Control","exfil":"Actions on Objectives"},"correct":5,"total":5,"passed":true,"attempt":1}

Log Triage

Meine Lösung
{"prompt":"Flag the anomalous sign-in rows in the auth log","flaggedRows":["r3","r4","r5","r7","r8"],"caughtImpossibleTravel":true,"badCaught":5,"falsePositives":0,"passed":true,"attempt":1}

Ioc Extraction

Meine Lösung
{"prompt":"Select the real Indicators of Compromise to block","selected":["ru-host","attachment","c2","attacker-ip"],"iocsCaught":4,"benignBlocked":0,"passed":true,"attempt":1}

Containment Plan

Meine Lösung
{"prompt":"Choose and order the sound containment actions; cut access first; avoid the destructive ones.","selected":["isolate-host","disable-account","block-iocs","force-reset"],"order":["isolate-host","disable-account","block-iocs","force-reset"],"avoidedBad":["re-image","alert-all"],"soundCaught":4,"destructiveChosen":0,"accessCutFirst":true,"passed":true,"attempt":1}

Breach Notification

Meine Lösung
{"prompt":"Draft the GDPR Art. 33 72-hour breach notification to the supervisory authority.","text":"On 02:14 (INC-4471), Falkenstein Automotive became aware of a phishing attack that compromised an employee account and exposed personal data. \nAffected: Markus Weber and likely the data present on his laptop\nConsequences: unauthorized access, credential misuse, leaking of data\nMeasures taken: The compromised account was isolated and the attacker was blocked, the credentials were reset\n","charCount":387,"elementsCovered":["nature","data","consequences","measures"],"passed":true,"attempt":1}

Incident Report

Meine Lösung
{"prompt":"Write the incident report (Summary / Timeline / Root cause / Impact / Recommendations)","sections":{"summary":"At 02:14 (INC-4471), Falkenstein Automotive identified a phishing attack that compromised an employee account. The attacker used stolen credentials to access company resources before the incident was detected and contained.","timeline":"23:07: Phishing email delivered to Markus. Shortly after: Markus opened the email and executed the malicious attachment. Malware harvested credentials and established persistence. ~02:00: Stolen credentials were used to log in from Rotterdam and access the finance file share. 02:14: SIEM detected the suspicious activity. The compromised host was isolated, the account disabled, IoCs blocked, and credentials reset.","rootCause":"The user had no MFA so just one click compromised his account. and since he had more access than required for his role, the company's security was also compromised.","impact":"One employee account was compromised through phishing, allowing unauthorized access to company resources and the finance file share. Credentials were stolen, creating a risk of unauthorized access and potential exposure of personal and business data. The incident was contained before wider lateral movement or ransomware deployment was observed.","recommendations":"Enforce MFA to all the accounts, train the employees for identifying phishing attacks, Enable role-based access in the company, monitor logs."},"charCount":1290,"sectionsAddressed":["summary","timeline","rootCause","impact","recommendations"],"passed":true,"attempt":1}

Recommendations

Meine Lösung
{"prompt":"Rate each control on impact and effort; order by priority (quick wins first)","ratings":{"mfa":{"impact":3,"effort":1},"awareness":{"impact":3,"effort":2},"least-privilege":{"impact":2,"effort":2},"endpoint":{"impact":2,"effort":3},"segmentation":{"impact":2,"effort":3}},"ranking":[{"rank":1,"control":"mfa","impact":3,"effort":1,"score":5},{"rank":2,"control":"awareness","impact":3,"effort":2,"score":4},{"rank":3,"control":"least-privilege","impact":2,"effort":2,"score":2},{"rank":4,"control":"endpoint","impact":2,"effort":3,"score":1},{"rank":5,"control":"segmentation","impact":2,"effort":3,"score":1}],"passed":true,"attempt":1}

Real Case Analysis

Meine Lösung
{"prompt":"Real case: which ONE control would have most reduced the damage, and why?","text":"The single control i'd prioritise is log monitoring. In this case, there was a time of over 4 weeks in which the attack could've been detected and hence contained. It'd have stopped the attacker before getting all the data and also we could've then spotted the weakness of our system and then improve it so as to be better prepared if any attackes occur in the future.","charCount":368,"controlsNamed":["monitoring / detection"],"passed":true,"attempt":1}
Verifiziertes ZertifikatFälschungssicher · ausgestellt von ProoV
1Abgeschlossenes Projekt
1Verifiziertes Zertifikat
84Durchschnittsnote
Erstelle dein Portfolio mit ProoV