No more typing reviews! Try our Samantha, our new voice AI agent.

Real-Time Threat Detection & Traffic Analysis System

Koyena Paul - PeerSpot reviewer
Managed Security Services Associate at Accenture
5 people affected
3 people managed
2 month project

Project Description

Developed a SIEM-based threat detection and traffic analysis system using Splunk to monitor and analyze security events in real time. Created detection use cases aligned with the MITRE ATT&CK framework for phishing, brute-force attacks, and anomalous network behavior. Performed log correlation, IOC-based threat hunting, and HTTP/network traffic analysis to identify suspicious activities and improve incident detection. The project strengthened skills in SIEM operations, threat analysis, incident response, and security monitoring.

Lessons Learned

If I were to do this project again, I would focus on making it more production-ready by integrating additional log sources such as firewall, DNS, and cloud security logs to improve visibility. I would also enhance the detection use cases with behavioral analytics, automate incident response using SOAR playbooks, and incorporate threat intelligence feeds for better IOC correlation. Additionally, I would perform more extensive performance testing and optimize alert tuning to further reduce false positives while maintaining high detection accuracy.

Highlights

Under budget
Received recognition / award
Support from colleagues

Difficulties

Steep learning curve

Products Used

Technical Skills Used

  • Splunk SIEM, Log Analysis & Correlation, Threat Detection, Threat Hunting, Incident Response, IOC Investigation
  • Kolkata (IN)22.562688.363