Skip to content
View archana6malviya's full-sized avatar

Block or report archana6malviya

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
archana6malviya/README.md

🛡️ Cybersecurity Project Portfolio – Archana Malviya

👩‍💻 About Me

I am an aspiring SOC Analyst (Entry-Level) with hands-on experience in log analysis, SIEM monitoring, cybersecurity, SOC, incident-response, SIEM, Linux, network incident response, and network traffic analysis. I created these projects to gain real-world SOC skills by simulating attacks, investigating security incidents, and documenting findings using industry-standard tools and frameworks.

My focus areas include:

  • Incident Detection & Response

  • Log Analysis (Linux, Windows, SIEM)

  • Network Traffic Investigation

  • SOC Playbooks & Incident Reporting

  • MITRE ATT&CK Mapping

📂 Projects

🔹 SIEM Log Monitoring & Incident Response (Splunk)

Summary: Monitored Linux and Windows logs using Splunk SIEM to detect suspicious activities such as failed login attempts and brute-force attacks. Created alerts, dashboards, and incident reports.

Skills Demonstrated:

  • SIEM monitoring & alerting

  • Log correlation & investigation

  • Incident response documentation

MITRE ATT&CK mapping

Tools Used: Splunk, Linux, Windows Logs, MITRE ATT&CK

🔗 Project Link: https://github.com/archana6malviya/SIEM-Log-Monitoring-with-Splunk

🔹 Linux Security Log Investigation & Incident Response

Summary: Analyzed Linux authentication and system logs to identify SSH brute-force attempts. Investigated attacker IPs, timestamps, and actions, followed by incident reporting and SOC playbook creation.

Skills Demonstrated:

  • Linux log analysis

  • SSH brute-force detection

  • Incident reporting

  • SOC playbook creation

Tools Used: Linux, auth.log, journalctl, grep, awk

🔗 Project Link: https://github.com/archana6malviya/Linux-Security-Log-Investigation

🔹 Network Traffic Analysis & Incident Investigation

Summary: Captured and analyzed network traffic to detect suspicious activity such as ICMP abuse, SSH traffic, and DNS anomalies. Identified potential attack patterns and documented findings.

Skills Demonstrated:

  • Network traffic analysis

  • Packet inspection

  • Threat identification

  • Incident documentation

Tools Used: Wireshark, tcpdump, Linux

🔗 Project Link: https://github.com/archana6malviya/Network-Traffic-Analysis

🔹 Failed Login Analysis Lab

Summary: Simulated multiple failed authentication attempts to identify brute-force behavior. Investigated logs and correlated events to confirm malicious activity.

Skills Demonstrated:

  • Authentication log analysis

  • Brute-force detection

  • Security event investigation

Tools Used: Linux logs, grep, cut, awk

🔗 Project Link: https://github.com/archana6malviya/failed-login-analysis-lab

🔹 DNS Port Unreachable Investigation

Summary: Analyzed ICMP “Port Unreachable” messages and DNS-related network behavior to understand misconfigurations or potential scanning activity.

Skills Demonstrated:

  • Network troubleshooting

  • ICMP & DNS analysis

  • Security investigation mindset

Tools Used: tcpdump, Wireshark, Linux

🔗 Project Link: https://github.com/archana6malviya/dns-port-unreachable-lab

🧠 Skills Practiced

  • SOC Operations & Incident Response

  • SIEM Monitoring (Splunk)

  • Linux & Windows Log Analysis

  • Network Traffic Analysis

  • SSH Brute-Force Detection

  • Alert Investigation & Triage

  • Incident Reporting & Playbooks

MITRE ATT&CK Framework

Documentation & GitHub Portfolio Management

📫 Contact & Profiles

GitHub: https://github.com/archana6malviya

LinkedIn: (add your LinkedIn URL here)

Pinned Loading

  1. dns-port-unreachable-lab dns-port-unreachable-lab Public

    A practical cybersecurity lab showing how DNS UDP requests to a closed port generate ICMP (Destination Port Unreachable). Includes tcpdump captures, scripts, walkthrough, and SOC-style analysis.

    Shell

  2. failed-login-analysis-lab failed-login-analysis-lab Public

    “Identifying Failed Login Attempts & Basic Security Events”

  3. Network-Traffic-Analysis Network-Traffic-Analysis Public

    Capturing, analyzing, and interpreting network traffic using Wireshark and tcpdump on both Windows and Linux virtual machines.

  4. Linux-Security-Log-Investigation Linux-Security-Log-Investigation Public

    Investigate Linux authentication logs

  5. SIEM-Log-Monitoring-with-Splunk SIEM-Log-Monitoring-with-Splunk Public

    “SIEM project using Splunk to detect Linux SSH brute-force attacks with dashboards and alerts.”

    1

  6. incident-response-project- incident-response-project- Public