Projects
Hands-on forensics, CTF, and security lab work — each one investigated, documented, and written up the way I'd report it on the job.
Lumma Stealer — C2 Beacon Analysis
Analyzed PCAP traffic to detect Lumma Stealer command-and-control beaconing, identified the infected host, fingerprinted the victim machine, and extracted indicators of compromise for the incident.
NetSupport RAT — C2 Traffic Investigation
Investigated PCAP data to detect and confirm NetSupport RAT C2 traffic, identified the compromised host on the network, and documented indicators of compromise for response.
Sherlock: Vantage — Cloud Forensics
Investigated an OpenStack breach using tshark-based packet analysis to reconstruct the attack timeline and identify the compromised cloud resource.
Sherlock: Brutus — SSH Brute-Force DFIR
Performed digital forensics on auth.log and wtmp data to investigate an SSH brute-force attack, identify the attacker's access pattern, and determine the scope of compromise.
Sherlock: MangoBleed — Endpoint Forensics
Triaged a compromised MongoDB server from a UAC-collected artifact set, identifying the initial-access CVE, attacker persistence, privilege escalation, and lateral movement, then summarized findings as an incident assessment.
Sherlock: Telly — Network Forensics
Analyzed network telemetry from a compromised backup server after a DLP alert, reconstructing a Telnet-based exploit and exfiltration path via Wireshark and SQLite artifact analysis.
Security Labs
50+ Vulnerabilities Identified. Conducted network traffic analysis with Wireshark and performed vulnerability scanning using Nessus. Practiced Active Directory attack and defense techniques in self-built lab environments.
Web Application Penetration Testing Lab
Simulated real-world attacks on vulnerable web applications using Burp Suite, Nmap, and manual testing techniques. Identified and reported multiple critical flaws including SQL injection and XSS.