Skip to content
View Bikash-Raya's full-sized avatar

Block or report Bikash-Raya

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Bikash-Raya/README.md

Bikash Raya

Typing SVG
Building hands-on security skills — Not just coursework — Fully documented proof of work



👋 Who I Am

IT professional with 3+ years in IT desktop support, transitioning into cybersecurity.

My hands-on labs cover the full security operations lifecycle: SIEM deployment, threat detection, vulnerability management, incident response, threat hunting, web application security, cloud IAM, and GRC policy development all built in Azure cloud and on-premises environments.


Skills

Skill Associated Project
SIEM Deployment & Incident Response SOC Incident Response Lab
GeoIP Threat Intelligence & Log Enrichment GeoIP Watchlist & Attack Map Lab
Threat Hunting & IOC Investigation Threat Hunting Lab
Web App Exploit Detection & Containment Vulnerable Web Server RCE Lab
Hybrid Cloud Endpoint Monitoring Hybrid Endpoint Monitoring Lab
Honeynet Deployment & Live Attack Detection Azure Honeynet Lab
Credentialed Vulnerability Scanning Nessus Vulnerability Management Lab
Web App DAST Assessment OWASP ZAP Lab
Windows/Linux/AD Hardening System Hardening Lab
AD Privilege Escalation Enumeration BloodHound & SharpHound Lab
Cloud IAM, RBAC & MFA Azure IAM Security Lab
Azure Identity & RBAC Configuration Azure Cloud — Identity & RBAC Lab
Azure VM Provisioning & User Lifecycle Management Azure Windows VM Administration Lab
On-Prem AD Domain Controller & DNS Configuration On-Prem AD, DC, Windows 11 & Linux Lab
Enterprise Network Design & Firewall Deployment Enterprise IT Infrastructure Design & Deployment
GRC Policy & Incident Playbook Development Policy and Playbook Development
Risk Assessment & Controls Mapping Cyber Risk Assessment

Hands-on cybersecurity labs

🔵 Security Operations & Incident Response

Project What I Did Tools / Skills Report
SOC Incident Response Lab • Deployed Windows Server (victim) and Ubuntu (attacker) VMs; ran Hydra RDP brute force and detected login events via KQL (Event IDs 4624/4625)
• Built a custom analytics rule mapped to MITRE T1110; performed full SOC incident response in Defender XDR
Microsoft Sentinel · Defender XDR · Hydra · KQL · Sysmon · Azure NSG · AMA · DCR · MITRE ATT&CK 🔗 View
GeoIP Watchlist & Global Attack Map Lab • Exposed Web01 for ~2 days to collect 4,270+ real-world RDP attacks from global threat actors
• Built a KQL workbook using ipv4_lookup() to enrich attacker IPs and render a global heat map
Microsoft Sentinel · KQL · ipv4_lookup() · Watchlist · Workbook · Defender XDR 🔗 View
Threat Hunting Lab • Followed CISA Advisory AA25-141b; simulated LummaC2 execution and ingested Sysmon logs via custom DCR
• Ran 5 KQL hunting queries mapped to MITRE ATT&CK; confirmed IOC detection against IP 94.158.244.69
Microsoft Sentinel · Sysmon · KQL · CISA AA25-141b · MITRE ATT&CK · PS2EXE · IOC Investigation 🔗 View
Vulnerable Web Server — RCE Detection & IR Lab • Deployed a PHP web app with a deliberate command injection flaw (CWE-78); executed a 7-stage attack chain (recon → RCE → host discovery → user enumeration → process discovery → network discovery → payload retrieval)
• Ingested Apache logs into Sentinel via Custom Logs AMA; real attacker 103.168.66.101 independently exploited the app generating 82 correlated events; contained via NSG Deny rule
Microsoft Sentinel · Apache Logs · KQL · CWE-78 · MITRE ATT&CK · NSG Containment · Custom Logs AMA 🔗 View
Hybrid Endpoint Monitoring Lab • Onboarded Windows, Linux, and Azure endpoints into a hybrid SIEM lab via Azure Arc
• Built KQL detection rules and triggered and resolved a real incident in Sentinel
Microsoft Sentinel · Azure Arc · AMA · Log Analytics · KQL · DCR · RBAC 🔗 View
Azure Honeynet, SQL Server & Live Attack Detection Lab • Deployed Windows and Linux VMs as honeypots with open NSGs; set up SQL Server, ingested logs via Log Analytics, DCR, and NSG Flow Logs
• Enriched alerts with GeoIP watchlist and confirmed live real-world attack detection using KQL
Microsoft Sentinel · Azure NSG · SQL Server · Log Analytics · KQL · Defender for Cloud 🔗 View

🔴 Vulnerability Management

Project What I Did Tools / Skills Report
Nessus Vulnerability Management Lab • Built an Active Directory lab; deployed Nessus Essentials on Kali Linux and ran credentialed scans with GPO-based access
• Remediated SMB Signing (Plugin 57608) via GPO, 7-Zip Critical CVEs, and conducted a web app scan with 18 findings
Tenable Nessus · Kali Linux · Active Directory · GPO · CVSS · SMB Hardening · Windows Server 🔗 View
OWASP ZAP — Web App Security Assessment Lab • Performed a full DAST assessment against testasp.vulnweb.com using OWASP ZAP 2.17.0
• Confirmed SQL Injection, DOM/Reflected XSS, Path Traversal, and Open Redirect across 21 alerts mapped to OWASP Top 10
OWASP ZAP · DAST · SQL Injection · XSS · Path Traversal · OWASP Top 10 · Kali Linux 🔗 View

🛡️ System Hardening & AD Security

Project What I Did Tools / Skills Report
System Hardening Lab — Linux, Windows Server & Active Directory • Audited Kali Linux with Lynis (baseline 62/100) and remediated AppArmor, auditd, kernel sysctl, and password policy
• Compared Windows Server 2022 against Microsoft Security Baseline via Policy Analyzer and deployed Secure_Baseline GPO; ran PingCastle against biksec.com, identified NTLMv1 weakness (15 risk points) and remediated via GPO
Lynis · Microsoft Security Compliance Toolkit · Policy Analyzer · PingCastle · GPO · AppArmor · auditd 🔗 View
AD Enumeration — BloodHound & SharpHound • Ran SharpHound on BIKSEC-DC01 to collect AD data; installed BloodHound on Kali Linux with Neo4j and ran Cypher queries to explore the domain
• Created a nested group misconfiguration (Braya → HelpDesk Team → IT Operations → Server Admins); BloodHound surfaced the privilege escalation path; remediated and validated on re-scan
SharpHound · BloodHound · Neo4j · Cypher · Active Directory · Privilege Escalation · MITRE ATT&CK T1069 🔗 View

☁️ Cloud & Identity

Project What I Did Tools / Skills Report
Azure IAM Security Lab • Provisioned a test user and Security Group in Entra ID; assigned Reader RBAC role and validated least-privilege access
• Configured MFA via Microsoft Authenticator and reviewed sign-in logs
Microsoft Entra ID · Azure RBAC · MFA · Sign-in Logs · Least Privilege 🔗 View
Azure Cloud — Identity & RBAC Lab • Provisioned Windows Server via Azure CLI and configured dynamic group membership
• Implemented custom RBAC roles for delegated access control
Azure CLI · Entra ID · Dynamic Groups · RBAC 🔗 View
Azure Windows VM Administration Lab • Provisioned a Windows 11 VM in Azure; configured RDP access, user accounts, and RBAC
• Performed troubleshooting and decommissioned the environment
Azure · Windows 11 · RDP · Entra ID · RBAC 🔗 View

📋 GRC & Risk Management

Project What I Did Tools / Skills Report
Policy and Playbook Development • Developed a Phishing Incident Response Playbook with severity classification, containment tracks, and HIPAA breach notification procedures
• Wrote a Password & Authentication Policy aligned to NIST SP 800-63B, ISO 27001:2022, and NIST CSF
NIST CSF · ISO 27001:2022 · NIST SP 800-63B · HIPAA · Policy Writing · Incident Playbook · GRC 🔗 View
Cyber Risk Assessment • Conducted a full information security risk assessment for a fictional LMS; produced Asset Register, Threat Catalogue, and Risk Scoring Matrix
• Delivered a Controls Register (NIST CSF), Risk Treatment Plan, and Risk Register
NIST CSF · Risk Assessment · Risk Register · Asset Classification · Control Mapping 🔗 View

🏗️ Infrastructure

Project What I Did Tools / Skills Report
On-Prem AD, DC, Windows 11 & Linux • Built a virtualised on-prem network with Windows Server 2022 as Domain Controller
• Joined Windows 11 and Kali Linux clients; configured AD DS, DNS, and resolved cross-platform connectivity issues
VMware · Windows Server 2022 · Active Directory · DNS · Kali Linux · PowerShell 🔗 View
Enterprise IT Infrastructure Design & Deployment • Designed and deployed a full enterprise network for a simulated college with AD OU structure, RBAC, and Microsoft 365 integration
Active Directory · Microsoft 365 · RBAC 🔗 View

🎓 Certifications & Professional Training

Qualification Provider Credential
CompTIA Security+ CompTIA 🔗 Certificate
Google Cybersecurity Professional Certificate Coursera 🔗 Certificate
SC-200: Microsoft Security Operations Analyst Udemy 🔗 Certificate
Tata Cybersecurity Simulation Forage 🔗 Certificate
AIG Cybersecurity Simulation Forage 🔗 Certificate
ANZ Cyber Security Management Simulation Forage 🔗 Certificate
Mastercard Cybersecurity Simulation Forage 🔗 Certificate
Telstra Cybersecurity Simulation Forage 🔗 Certificate
Datacom Cybersecurity Simulation Forage 🔗 Certificate

📫 Get in Touch

 

Pinned Loading

  1. AD-Enumeration-Bloodhound-Sharphound AD-Enumeration-Bloodhound-Sharphound Public

  2. Nessus-Vulnerability-Management-Lab Nessus-Vulnerability-Management-Lab Public

  3. Sentinel-Defender-XDR-SOC-Incident-Response-lab Sentinel-Defender-XDR-SOC-Incident-Response-lab Public

  4. system-hardening-lab-linux-windows-active-directory system-hardening-lab-linux-windows-active-directory Public

  5. Threat-Hunting-Lab-Sentinel-Sysmon--lummac2- Threat-Hunting-Lab-Sentinel-Sysmon--lummac2- Public

  6. vulnerable-webserver-rce-detection-incident-response- vulnerable-webserver-rce-detection-incident-response- Public