This project aims to redesign Windows audit policy configurations to reduce log noise and enhance detection clarity within Splunk. The objective is to produce a streamlined, purposeful audit policy that supports effective threat detection, baselining, and investigative workflows in a lab or SOC simulation environment.
windows-security-auditing audit-policy-optimization splunk-detection-engineering soc-lab-automation event-log-analysis
-
Updated
Jun 30, 2025 - Jupyter Notebook