Threat Intelligence - OpenCTI
Installing and configuration of a threat intelligence platform called OpenCTI for up to date vulnerability / threat information.

Installing and configuration of a threat intelligence platform called OpenCTI for up to date vulnerability / threat information.

This project involved deploying EC2 instances and tightly controlled security groups using AWS CloudFormation to enforce least-privilege network access and minimise exposed ports. Activity was monitored and validated using AWS CloudTrail to ensure full visibility of infrastructure changes and support auditability.

In this lab, I simulated an ARP flooding attack using Scapy and analysed traffic behaviour with Wireshark to understand Layer 2 attack patterns. Detection and mitigation were implemented using Snort with custom rules to identify and reduce malicious ARP activity.

The importance of contemporaneous notes in digital forensics. A simulation where I act as a digital forensics expert to find malicious images from a USB drive taken as evidence.
