Cybersecurity Lab Simulation & Alert Triage (TryHackMe & independent research)
You performed playbook-driven verification and false-positive analysis on alerts generated from internal security logs to ensure queue accuracy and correct routing decisions. You also audited external infrastructure indicators to support triage workflows by identifying exposed services, open ports, and outdated systems. Finally, you followed standardized escalation procedures to pass verified threats onward to remediation teams using predefined templates. • SIEM/Splunk log monitoring and structured analysis for unauthorized access, malware activity, and suspicious network behavior • False-positive filtering and alert validation using systematic, playbook-based methods • External asset verification using Shodan and CIDR-based search techniques • Incident escalation routing to identify high-risk assets and communicate findings via templates