Cybersecurity / Security Operations
Catnip Games International: SOC Automation and Incident Response Platform
This cybersecurity project presents the design and implementation of a prototype Security Operations Centre (SOC) automation and incident-response platform for Catnip Games International. The scenario addresses security challenges affecting a gaming organisation operating more than 300 Linux servers across two data centres, including credential-stuffing bot attacks, compromised player accounts, phishing campaigns and delayed coordination during security incidents. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete The proposed solution integrates TheHive 5, Cortex 3, Elasticsearch, Cassandra and Python-based automation, with MISP explored for threat-intelligence integration. TheHive functions as the central incident and case-management platform, Cortex provides automated observable analysis, Elasticsearch supports search and log storage, Cassandra provides persistent case and alert storage, and Python scripts automate alert ingestion and workflow activities through REST APIs. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete Implementation includes environment configuration, Docker deployment, API integration, automated alert generation, incident-response playbooks, KPI monitoring and backup procedures. Three attack scenarios are modelled: bot attacks, account takeover and phishing. Alerts are automatically ingested into TheHive, converted into cases and processed through analyst triage, investigation and resolution workflows. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete The project also develops structured response playbooks covering triage, containment, investigation, recovery and post-incident actions for each security scenario. Operational metrics are visualised through a KPI dashboard measuring alert volumes, response times, Mean Time to Detect (MTTD), Mean Time to Respond/Resolve (MTTR) and platform availability. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete Overall, the work demonstrates practical application of SOC architecture, security automation, incident management, threat analysis, containerised infrastructure, API-based integration, operational metrics and cyber-response procedures within a realistic gaming-industry security scenario. Catnip_Games_SOC_Complete Overview word count: approximately 330 words. Important before putting the presentation on a public Reference Library: redact any API keys/authentication tokens and other live credentials shown in the technical slides. The presentation includes API-key material in the Cortex and Python automation sections, so those credentials should also be revoked/rotated if they were ever active. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete
Read Model Answer →
1,500 words
Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs
This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.
Read Model Answer →