Security Lab Architecture and Setup
Security Operations / Security Engineering
Built a virtualized security lab using Wazuh, Kali Linux, Linux Server, Windows Endpoint, Sysmon, and an isolated internal network for threat simulation and detection.
WazuhVirtualBoxKali LinuxSysmonLog Ingestion
Security Architecture
CompletedSecure Network Architecture Design & Risk Assessment
Junior Security Engineer / Security Architect Track
Designed a secure segmented network architecture for Acme AeroTech using VLANs, a DMZ, firewall rules, least privilege, and risk-based decision making.
Network SegmentationRisk AssessmentDMZFirewall Rules
Detection Engineering
CompletedCustom Detection Engineering and Incident Analysis Using Wazuh SIEM
SOC Analyst / Detection Engineering
Created and validated a custom Wazuh detection rule for SSH brute-force activity using Kali Linux, Hydra, Linux authentication logs, and Level 12 alert validation.
WazuhHydraSSH Brute ForceMITRE T1110Log Analysis
SOC / Security Analyst
CompletedSSH Brute Force Detection with Layered Wazuh Rules
SOC Analyst / Detection Engineering
Implemented layered Wazuh SIEM correlation rules to detect SSH brute-force activity, escalating from early warning to high-severity alerts using Hydra attack simulation.
WazuhHydraSSHMITRE T1110Layered Detection
Application Security
CompletedAPI Security Assessment & Hardening
API Security / Security Engineering
Identified and secured API vulnerabilities by implementing JWT authentication, RBAC, rate limiting, input validation, and security logging in a Node.js/Express REST API.
API SecurityJWTRBACRate LimitingZodInput ValidationNode.jsExpressSecurity Logging
SOC / Security Analyst
Coming SoonPhishing Analysis
SOC Analyst
Analyze simulated phishing artifacts, investigate indicators, document findings, and recommend mitigation steps.
PhishingEmail AnalysisIOCsInvestigation
Project page coming soon
Coming soon — no project page yet
SOC / Security Analyst
Coming SoonPowerShell Threat Hunt
Threat Hunting
Hunt for suspicious PowerShell activity using Windows logs, Sysmon telemetry, and SIEM-based investigation.
PowerShellSysmonWindows LogsThreat Hunting
Project page coming soon
Coming soon — no project page yet
SOC / Security Analyst
Coming SoonWeb Log Analysis
Security Analyst
Review web server logs for suspicious behavior, identify patterns, and document investigation findings.
Web LogsNginxLog AnalysisInvestigation
Project page coming soon
Coming soon — no project page yet
SOC / Security Analyst
Coming SoonMalware Alert Triage
SOC Analyst
Triage malware-related alerts, review evidence, determine severity, and recommend containment steps.
Alert TriageMalwareEvidence Collection
Project page coming soon
Coming soon — no project page yet
SOC / Security Analyst
Coming SoonSIEM Alert Tuning
Detection Support
Tune noisy alerts, reduce false positives, adjust severity, and improve SIEM detection quality.
SIEMAlert TuningFalse PositivesDetection Logic
Project page coming soon
Coming soon — no project page yet
SOC / Security Analyst
Coming SoonLateral Movement Detection
Detection Engineering
Simulate and detect movement between systems, review logs, and map detection opportunities.
Lateral MovementWindows LogsWazuhMITRE ATT&CK
Project page coming soon
Coming soon — no project page yet
SOC / Security Analyst
Coming SoonIOC Threat Intel
Threat Intelligence
Use indicators such as IPs, domains, hashes, and artifacts to enrich investigations and document findings.
Threat IntelIOCsEnrichmentInvestigation
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonLinux Hardening
Junior Security Engineer
Review Linux configurations, SSH security, permissions, firewall settings, updates, and audit checks.
LinuxSSHHardeningFirewall
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonWindows Hardening
Junior Security Engineer
Review Windows security settings, logging, endpoint visibility, account hygiene, and baseline controls.
WindowsSysmonEndpoint Security
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonVulnerability Scan
Vulnerability Management
Identify weaknesses, validate findings, prioritize risk, and document remediation recommendations.
Vulnerability ManagementNmapRisk Ranking
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonFirewall Review
Security Engineering
Review firewall rules, exposed ports, allowed services, and network boundary controls.
FirewallNetwork SecurityAccess Control
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonNginx Security
Web Security
Review Nginx configuration, headers, TLS, logging, access controls, and hardening recommendations.
NginxTLSWeb SecurityLogging
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonIAM Review
Identity Security
Review users, roles, permissions, access patterns, and least privilege recommendations.
IAMLeast PrivilegeAccess Review
Project page coming soon
Coming soon — no project page yet
Security Engineering
Coming SoonDetection Rule Engineering
Detection Engineering
Build, test, validate, and document detection rules for realistic attack scenarios.
Detection LogicWazuh RulesValidation
Project page coming soon
Coming soon — no project page yet
Cloud / Architecture
Coming SoonCloud Misconfiguration
Cloud Security Support
Review insecure cloud settings, public exposure, weak permissions, logging gaps, and remediation steps.
Cloud SecurityMisconfigurationIAMLogging
Project page coming soon
Coming soon — no project page yet
Cloud / Architecture
Coming SoonAPI Security Testing
API Security Support
Test API authentication, authorization, input validation, logging, and data exposure risks.
API SecurityAuthInput ValidationOWASP
Project page coming soon
Coming soon — no project page yet
Cloud / Architecture
Coming SoonZero Trust Architecture
Security Engineering
Design a Zero Trust-style architecture using identity-aware access, segmentation, least privilege, and monitoring.
Zero TrustIdentitySegmentationLeast Privilege
Project page coming soon
Coming soon — no project page yet
Cloud / Architecture
Coming SoonLogging Strategy
Security Engineering / SOC
Plan what should be logged, where logs should go, how they support detection, and how coverage can be improved.
LoggingSIEMMonitoringDetection Coverage
Project page coming soon
Coming soon — no project page yet