Back to Portfolio
Security Research & Labs

Cybersecurity Portfolio

Most breaches aren't zero-days. They're known vulnerabilities nobody patched, on infrastructure nobody was watching, exploited by adversaries whose playbooks were already documented. This lab portfolio works that reality from both sides: run the attacks, then build the visibility that catches them.

Problem

Modern enterprise environments face increasing risks from unpatched vulnerabilities, lack of real-time infrastructure visibility, and sophisticated APT actors. Without a structured defensive framework, organizations remain reactive and exposed.

Solution

A holistic cybersecurity research system that combines proactive vulnerability management, real-time telemetry, and strategic threat intelligence. This approach shifts security from reactive to predictive.

Evidence across the security lifecycle

Threat intelligence & SecOps

Investigated suspicious domains and malware samples, extracted indicators, correlated reputation and sandbox evidence, and mapped observed behaviour to MITRE ATT&CK for technical and executive reporting.

Mirai analysis · Carbon Black alert investigation · ransomware, RAT and stealer triage

Cloud security implementation

Designed and validated an Azure network segmented with VNets, NSGs and application security groups, using role-based traffic rules and an implicit-deny posture.

Three access-path validation scenarios passed · production-hardening roadmap documented

Application & API security

Tested a controlled banking application through API enumeration, authentication analysis, JWT inspection and authorization checks, then documented an evidence-backed attack chain and remediation path.

Burp Suite · Swagger · JWT analysis · broken authorization testing

IAM, governance & compliance

Contributed to least-privilege and audit-log assessments, authored an AI governance policy aligned to ISO/IEC 27002:2022, and supported a PCI DSS v4.0.1 gap-assessment workflow.

RBAC · PAM · audit coverage · AI governance · PCI DSS

Public summaries intentionally omit client identities, infrastructure details, indicators of compromise, and confidential findings. Controlled labs and professional engagement contributions are labelled separately.

Architecture

Proactive Assessment Layer

Conducted structured vulnerability assessments using Nessus to identify misconfigurations and prioritize remediation paths based on CVSS scoring.

Nessus • CVSS 3.1

Infrastructure Observability

Implemented real-time monitoring infrastructure using Zabbix and SNMP to detect performance anomalies and ensure critical service availability.

Zabbix • SNMP

Offensive Security Testing

Performed controlled penetration testing on web applications, documenting SQLi and XSS vectors to develop secure coding remediation playbooks.

OWASP • Burp Suite

Threat Intelligence

Analyzed APT Tactics, Techniques, and Procedures (TTPs), mapping observations to the MITRE ATT&CK framework to improve defensive awareness.

MITRE ATT&CK • TTPs

Key Decisions

01Learn offense to build defense

ConsideredA purely defensive track — monitoring, patching, and policy without ever running an attack.

ChosePairing controlled penetration testing (SQLi and XSS against OWASP targets) with the remediation playbooks that follow. You defend better against attacks you have personally executed.

Trade-offLab scope must stay strictly controlled. The win: remediation guidance written from the attacker's side of the exploit.

02Prioritize by risk, not by list order

ConsideredTreating every scanner finding as equally urgent — the default posture that buries teams.

ChoseCVSS 3.1-scored prioritization of Nessus findings, so remediation effort lands on the highest-risk exposure first.

Trade-offLower-severity findings wait their turn. The win: finite security hours close the most dangerous gaps first — the way real teams have to operate.

03Map intelligence to a shared framework

ConsideredKeeping threat research as ad-hoc notes on APT campaigns.

ChoseMapping observed TTPs to MITRE ATT&CK, turning raw observations into named techniques a defense can be tested against.

Trade-offFramework discipline takes longer than free-form notes. The win: intelligence that translates directly into defensive coverage checks.

Technology

NessusZabbixSNMPBurp SuiteMITRE ATT&CKOWASP Juice ShopLinux/Windows Security

Outcome

Before

A reactive posture: unpatched vulnerabilities, no telemetry, and adversary behavior understood only after the incident.

After

A predictive posture: risk-ranked remediation, real-time observability, and threats mapped to ATT&CK before they are needed.

These controlled labs produced risk-ranked remediation notes, monitoring configurations, attack-path documentation, and ATT&CK-mapped threat analysis. Professional client engagements are represented separately and without confidential details.