Dockerized Zeek Pipeline for DNS Exfiltration Detection
Built a containarized DNS threat-detection pipeline using Zeek, FastAPI, and Random Forest ML to analyze raw PCAP traffic and detect DNS exfiltration attacks with 98% malicious recall, leveraging advanced telemetry features like Shannon entropy and subdomain analysis for protocol-aware forensic detection.