Automated security response
Built Splunk SOAR workflows for malicious links and suspicious mailbox activity, combining multiple data sources with an in-house LLM verdict, ticketing, Azure token revocation, account lockout and stakeholder notification.
