In a Computer Science project, I investigated how Windows logging choices affected the evidence available to a threat-hunting platform. I worked with HELK and documented its deployment, logging options and detection effectiveness against a range of simulated attacks.
The output was a technical report connecting the lab setup with the results of the simulations. This gave me practical academic experience of relating logged activity to the attacks a defender was trying to detect.
Methods, evidence & technical decisions
Deployment and Windows logging
I documented HELK deployment details and Windows logging options as part of the academic evaluation. The work connected configuration of the lab with the telemetry available for threat hunting.
Open this detail ↗Simulated attacks and observed detection
I evaluated detection effectiveness against a range of simulated attacks and recorded the results in a technical report. This was an academic lab exercise, separate from the production investigations and detection work in my professional cases.
Open this detail ↗Skills used in this work