Introducing This Project
This project simulates a real-world security investigation. Working from a compromised host (NPT-WS01), I used Microsoft Defender Advanced Hunting to trace attacker activity across the endpoint, writing KQL queries to uncover 11 distinct indicators of compromise. The investigation was documented as a formal incident report aligned to NIST SP 800-61, mapping each finding to the MITRE ATT&CK framework and closing with a containment plan.
Tools and Concepts
Microsoft Defender Advanced Hunting, KQL (Kusto Query Language), MITRE ATT&CK framework, NIST SP 800-61 incident response lifecycle.
Project Reflection
This project deepened my ability to write investigative KQL queries under a realistic time-pressured scenario, and to translate raw endpoint telemetry into a structured, audience-ready incident report, a skill directly relevant to SOC and incident response roles.