Cybersecurity Projects

Completed cybersecurity projects and the roadmap I’m building next.

This page includes completed case studies and planned projects across SOC analysis, detection engineering, security architecture, system hardening, cloud security, and API security.

5

Completed Projects

23

Total Portfolio Roadmap

18

Planned Projects

Category

Status

Showing 23 projects

Security Lab

Completed

Security Lab Architecture and Setup

Security Operations / Security Engineering

Built a virtualized security lab using Wazuh, Kali Linux, Linux Server, Windows Endpoint, Sysmon, and an isolated internal network for threat simulation and detection.

WazuhVirtualBoxKali LinuxSysmonLog Ingestion

Security Architecture

Completed

Secure Network Architecture Design & Risk Assessment

Junior Security Engineer / Security Architect Track

Designed a secure segmented network architecture for Acme AeroTech using VLANs, a DMZ, firewall rules, least privilege, and risk-based decision making.

Network SegmentationRisk AssessmentDMZFirewall Rules

Detection Engineering

Completed

Custom Detection Engineering and Incident Analysis Using Wazuh SIEM

SOC Analyst / Detection Engineering

Created and validated a custom Wazuh detection rule for SSH brute-force activity using Kali Linux, Hydra, Linux authentication logs, and Level 12 alert validation.

WazuhHydraSSH Brute ForceMITRE T1110Log Analysis

SOC / Security Analyst

Completed

SSH Brute Force Detection with Layered Wazuh Rules

SOC Analyst / Detection Engineering

Implemented layered Wazuh SIEM correlation rules to detect SSH brute-force activity, escalating from early warning to high-severity alerts using Hydra attack simulation.

WazuhHydraSSHMITRE T1110Layered Detection

Application Security

Completed

API Security Assessment & Hardening

API Security / Security Engineering

Identified and secured API vulnerabilities by implementing JWT authentication, RBAC, rate limiting, input validation, and security logging in a Node.js/Express REST API.

API SecurityJWTRBACRate LimitingZodInput ValidationNode.jsExpressSecurity Logging

SOC / Security Analyst

Coming Soon

Phishing Analysis

SOC Analyst

Analyze simulated phishing artifacts, investigate indicators, document findings, and recommend mitigation steps.

PhishingEmail AnalysisIOCsInvestigation
Project page coming soon
Coming soon — no project page yet

SOC / Security Analyst

Coming Soon

PowerShell Threat Hunt

Threat Hunting

Hunt for suspicious PowerShell activity using Windows logs, Sysmon telemetry, and SIEM-based investigation.

PowerShellSysmonWindows LogsThreat Hunting
Project page coming soon
Coming soon — no project page yet

SOC / Security Analyst

Coming Soon

Web Log Analysis

Security Analyst

Review web server logs for suspicious behavior, identify patterns, and document investigation findings.

Web LogsNginxLog AnalysisInvestigation
Project page coming soon
Coming soon — no project page yet

SOC / Security Analyst

Coming Soon

Malware Alert Triage

SOC Analyst

Triage malware-related alerts, review evidence, determine severity, and recommend containment steps.

Alert TriageMalwareEvidence Collection
Project page coming soon
Coming soon — no project page yet

SOC / Security Analyst

Coming Soon

SIEM Alert Tuning

Detection Support

Tune noisy alerts, reduce false positives, adjust severity, and improve SIEM detection quality.

SIEMAlert TuningFalse PositivesDetection Logic
Project page coming soon
Coming soon — no project page yet

SOC / Security Analyst

Coming Soon

Lateral Movement Detection

Detection Engineering

Simulate and detect movement between systems, review logs, and map detection opportunities.

Lateral MovementWindows LogsWazuhMITRE ATT&CK
Project page coming soon
Coming soon — no project page yet

SOC / Security Analyst

Coming Soon

IOC Threat Intel

Threat Intelligence

Use indicators such as IPs, domains, hashes, and artifacts to enrich investigations and document findings.

Threat IntelIOCsEnrichmentInvestigation
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

Linux Hardening

Junior Security Engineer

Review Linux configurations, SSH security, permissions, firewall settings, updates, and audit checks.

LinuxSSHHardeningFirewall
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

Windows Hardening

Junior Security Engineer

Review Windows security settings, logging, endpoint visibility, account hygiene, and baseline controls.

WindowsSysmonEndpoint Security
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

Vulnerability Scan

Vulnerability Management

Identify weaknesses, validate findings, prioritize risk, and document remediation recommendations.

Vulnerability ManagementNmapRisk Ranking
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

Firewall Review

Security Engineering

Review firewall rules, exposed ports, allowed services, and network boundary controls.

FirewallNetwork SecurityAccess Control
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

Nginx Security

Web Security

Review Nginx configuration, headers, TLS, logging, access controls, and hardening recommendations.

NginxTLSWeb SecurityLogging
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

IAM Review

Identity Security

Review users, roles, permissions, access patterns, and least privilege recommendations.

IAMLeast PrivilegeAccess Review
Project page coming soon
Coming soon — no project page yet

Security Engineering

Coming Soon

Detection Rule Engineering

Detection Engineering

Build, test, validate, and document detection rules for realistic attack scenarios.

Detection LogicWazuh RulesValidation
Project page coming soon
Coming soon — no project page yet

Cloud / Architecture

Coming Soon

Cloud Misconfiguration

Cloud Security Support

Review insecure cloud settings, public exposure, weak permissions, logging gaps, and remediation steps.

Cloud SecurityMisconfigurationIAMLogging
Project page coming soon
Coming soon — no project page yet

Cloud / Architecture

Coming Soon

API Security Testing

API Security Support

Test API authentication, authorization, input validation, logging, and data exposure risks.

API SecurityAuthInput ValidationOWASP
Project page coming soon
Coming soon — no project page yet

Cloud / Architecture

Coming Soon

Zero Trust Architecture

Security Engineering

Design a Zero Trust-style architecture using identity-aware access, segmentation, least privilege, and monitoring.

Zero TrustIdentitySegmentationLeast Privilege
Project page coming soon
Coming soon — no project page yet

Cloud / Architecture

Coming Soon

Logging Strategy

Security Engineering / SOC

Plan what should be logged, where logs should go, how they support detection, and how coverage can be improved.

LoggingSIEMMonitoringDetection Coverage
Project page coming soon
Coming soon — no project page yet

A quick note on this page

I didn’t want this to be just a list of projects. Each completed case study represents the full process: setting up the environment, testing the scenario, collecting evidence, troubleshooting problems, and explaining what I learned from it. The projects marked as coming soon are part of my roadmap. They give me a clear direction instead of jumping between random topics, and as each one is completed, it will become a full case study with evidence and documentation.

My goal is for this page to show progression over time. I am not trying to rush through projects just to add more cards. I want each project to help me become better at the work and make that growth visible.

Contact Me