Building hands-on security skills — Not just coursework — Fully documented proof of work
IT professional with 3+ years in IT desktop support, transitioning into cybersecurity.
My hands-on labs cover the full security operations lifecycle: SIEM deployment, threat detection, vulnerability management, incident response, threat hunting, web application security, cloud IAM, and GRC policy development all built in Azure cloud and on-premises environments.
| Skill | Associated Project |
|---|---|
| SIEM Deployment & Incident Response | SOC Incident Response Lab |
| GeoIP Threat Intelligence & Log Enrichment | GeoIP Watchlist & Attack Map Lab |
| Threat Hunting & IOC Investigation | Threat Hunting Lab |
| Web App Exploit Detection & Containment | Vulnerable Web Server RCE Lab |
| Hybrid Cloud Endpoint Monitoring | Hybrid Endpoint Monitoring Lab |
| Honeynet Deployment & Live Attack Detection | Azure Honeynet Lab |
| Credentialed Vulnerability Scanning | Nessus Vulnerability Management Lab |
| Web App DAST Assessment | OWASP ZAP Lab |
| Windows/Linux/AD Hardening | System Hardening Lab |
| AD Privilege Escalation Enumeration | BloodHound & SharpHound Lab |
| Cloud IAM, RBAC & MFA | Azure IAM Security Lab |
| Azure Identity & RBAC Configuration | Azure Cloud — Identity & RBAC Lab |
| Azure VM Provisioning & User Lifecycle Management | Azure Windows VM Administration Lab |
| On-Prem AD Domain Controller & DNS Configuration | On-Prem AD, DC, Windows 11 & Linux Lab |
| Enterprise Network Design & Firewall Deployment | Enterprise IT Infrastructure Design & Deployment |
| GRC Policy & Incident Playbook Development | Policy and Playbook Development |
| Risk Assessment & Controls Mapping | Cyber Risk Assessment |
| Project | What I Did | Tools / Skills | Report |
|---|---|---|---|
| SOC Incident Response Lab | • Deployed Windows Server (victim) and Ubuntu (attacker) VMs; ran Hydra RDP brute force and detected login events via KQL (Event IDs 4624/4625) • Built a custom analytics rule mapped to MITRE T1110; performed full SOC incident response in Defender XDR |
Microsoft Sentinel · Defender XDR · Hydra · KQL · Sysmon · Azure NSG · AMA · DCR · MITRE ATT&CK | 🔗 View |
| GeoIP Watchlist & Global Attack Map Lab | • Exposed Web01 for ~2 days to collect 4,270+ real-world RDP attacks from global threat actors • Built a KQL workbook using ipv4_lookup() to enrich attacker IPs and render a global heat map |
Microsoft Sentinel · KQL · ipv4_lookup() · Watchlist · Workbook · Defender XDR | 🔗 View |
| Threat Hunting Lab | • Followed CISA Advisory AA25-141b; simulated LummaC2 execution and ingested Sysmon logs via custom DCR • Ran 5 KQL hunting queries mapped to MITRE ATT&CK; confirmed IOC detection against IP 94.158.244.69 |
Microsoft Sentinel · Sysmon · KQL · CISA AA25-141b · MITRE ATT&CK · PS2EXE · IOC Investigation | 🔗 View |
| Vulnerable Web Server — RCE Detection & IR Lab | • Deployed a PHP web app with a deliberate command injection flaw (CWE-78); executed a 7-stage attack chain (recon → RCE → host discovery → user enumeration → process discovery → network discovery → payload retrieval) • Ingested Apache logs into Sentinel via Custom Logs AMA; real attacker 103.168.66.101 independently exploited the app generating 82 correlated events; contained via NSG Deny rule |
Microsoft Sentinel · Apache Logs · KQL · CWE-78 · MITRE ATT&CK · NSG Containment · Custom Logs AMA | 🔗 View |
| Hybrid Endpoint Monitoring Lab | • Onboarded Windows, Linux, and Azure endpoints into a hybrid SIEM lab via Azure Arc • Built KQL detection rules and triggered and resolved a real incident in Sentinel |
Microsoft Sentinel · Azure Arc · AMA · Log Analytics · KQL · DCR · RBAC | 🔗 View |
| Azure Honeynet, SQL Server & Live Attack Detection Lab | • Deployed Windows and Linux VMs as honeypots with open NSGs; set up SQL Server, ingested logs via Log Analytics, DCR, and NSG Flow Logs • Enriched alerts with GeoIP watchlist and confirmed live real-world attack detection using KQL |
Microsoft Sentinel · Azure NSG · SQL Server · Log Analytics · KQL · Defender for Cloud | 🔗 View |
| Project | What I Did | Tools / Skills | Report |
|---|---|---|---|
| Nessus Vulnerability Management Lab | • Built an Active Directory lab; deployed Nessus Essentials on Kali Linux and ran credentialed scans with GPO-based access • Remediated SMB Signing (Plugin 57608) via GPO, 7-Zip Critical CVEs, and conducted a web app scan with 18 findings |
Tenable Nessus · Kali Linux · Active Directory · GPO · CVSS · SMB Hardening · Windows Server | 🔗 View |
| OWASP ZAP — Web App Security Assessment Lab | • Performed a full DAST assessment against testasp.vulnweb.com using OWASP ZAP 2.17.0 • Confirmed SQL Injection, DOM/Reflected XSS, Path Traversal, and Open Redirect across 21 alerts mapped to OWASP Top 10 |
OWASP ZAP · DAST · SQL Injection · XSS · Path Traversal · OWASP Top 10 · Kali Linux | 🔗 View |
| Project | What I Did | Tools / Skills | Report |
|---|---|---|---|
| System Hardening Lab — Linux, Windows Server & Active Directory | • Audited Kali Linux with Lynis (baseline 62/100) and remediated AppArmor, auditd, kernel sysctl, and password policy • Compared Windows Server 2022 against Microsoft Security Baseline via Policy Analyzer and deployed Secure_Baseline GPO; ran PingCastle against biksec.com, identified NTLMv1 weakness (15 risk points) and remediated via GPO |
Lynis · Microsoft Security Compliance Toolkit · Policy Analyzer · PingCastle · GPO · AppArmor · auditd | 🔗 View |
| AD Enumeration — BloodHound & SharpHound | • Ran SharpHound on BIKSEC-DC01 to collect AD data; installed BloodHound on Kali Linux with Neo4j and ran Cypher queries to explore the domain • Created a nested group misconfiguration (Braya → HelpDesk Team → IT Operations → Server Admins); BloodHound surfaced the privilege escalation path; remediated and validated on re-scan |
SharpHound · BloodHound · Neo4j · Cypher · Active Directory · Privilege Escalation · MITRE ATT&CK T1069 | 🔗 View |
| Project | What I Did | Tools / Skills | Report |
|---|---|---|---|
| Azure IAM Security Lab | • Provisioned a test user and Security Group in Entra ID; assigned Reader RBAC role and validated least-privilege access • Configured MFA via Microsoft Authenticator and reviewed sign-in logs |
Microsoft Entra ID · Azure RBAC · MFA · Sign-in Logs · Least Privilege | 🔗 View |
| Azure Cloud — Identity & RBAC Lab | • Provisioned Windows Server via Azure CLI and configured dynamic group membership • Implemented custom RBAC roles for delegated access control |
Azure CLI · Entra ID · Dynamic Groups · RBAC | 🔗 View |
| Azure Windows VM Administration Lab | • Provisioned a Windows 11 VM in Azure; configured RDP access, user accounts, and RBAC • Performed troubleshooting and decommissioned the environment |
Azure · Windows 11 · RDP · Entra ID · RBAC | 🔗 View |
| Project | What I Did | Tools / Skills | Report |
|---|---|---|---|
| Policy and Playbook Development | • Developed a Phishing Incident Response Playbook with severity classification, containment tracks, and HIPAA breach notification procedures • Wrote a Password & Authentication Policy aligned to NIST SP 800-63B, ISO 27001:2022, and NIST CSF |
NIST CSF · ISO 27001:2022 · NIST SP 800-63B · HIPAA · Policy Writing · Incident Playbook · GRC | 🔗 View |
| Cyber Risk Assessment | • Conducted a full information security risk assessment for a fictional LMS; produced Asset Register, Threat Catalogue, and Risk Scoring Matrix • Delivered a Controls Register (NIST CSF), Risk Treatment Plan, and Risk Register |
NIST CSF · Risk Assessment · Risk Register · Asset Classification · Control Mapping | 🔗 View |
| Project | What I Did | Tools / Skills | Report |
|---|---|---|---|
| On-Prem AD, DC, Windows 11 & Linux | • Built a virtualised on-prem network with Windows Server 2022 as Domain Controller • Joined Windows 11 and Kali Linux clients; configured AD DS, DNS, and resolved cross-platform connectivity issues |
VMware · Windows Server 2022 · Active Directory · DNS · Kali Linux · PowerShell | 🔗 View |
| Enterprise IT Infrastructure Design & Deployment | • Designed and deployed a full enterprise network for a simulated college with AD OU structure, RBAC, and Microsoft 365 integration |
Active Directory · Microsoft 365 · RBAC | 🔗 View |
| Qualification | Provider | Credential |
|---|---|---|
| CompTIA Security+ | CompTIA | 🔗 Certificate |
| Google Cybersecurity Professional Certificate | Coursera | 🔗 Certificate |
| SC-200: Microsoft Security Operations Analyst | Udemy | 🔗 Certificate |
| Tata Cybersecurity Simulation | Forage | 🔗 Certificate |
| AIG Cybersecurity Simulation | Forage | 🔗 Certificate |
| ANZ Cyber Security Management Simulation | Forage | 🔗 Certificate |
| Mastercard Cybersecurity Simulation | Forage | 🔗 Certificate |
| Telstra Cybersecurity Simulation | Forage | 🔗 Certificate |
| Datacom Cybersecurity Simulation | Forage | 🔗 Certificate |