← Back to Home

Projects

Hands-on forensics, CTF, and security lab work — each one investigated, documented, and written up the way I'd report it on the job.

Network Forensics

Lumma Stealer — C2 Beacon Analysis

Analyzed PCAP traffic to detect Lumma Stealer command-and-control beaconing, identified the infected host, fingerprinted the victim machine, and extracted indicators of compromise for the incident.

Wireshark tshark IOC Extraction

NetSupport RAT — C2 Traffic Investigation

Investigated PCAP data to detect and confirm NetSupport RAT C2 traffic, identified the compromised host on the network, and documented indicators of compromise for response.

Wireshark tshark Host Isolation
HackTheBox — CTF Writeups

Sherlock: Vantage — Cloud Forensics

Investigated an OpenStack breach using tshark-based packet analysis to reconstruct the attack timeline and identify the compromised cloud resource.

Cloud Forensics tshark

Sherlock: Brutus — SSH Brute-Force DFIR

Performed digital forensics on auth.log and wtmp data to investigate an SSH brute-force attack, identify the attacker's access pattern, and determine the scope of compromise.

DFIR Log Analysis

Sherlock: MangoBleed — Endpoint Forensics

Triaged a compromised MongoDB server from a UAC-collected artifact set, identifying the initial-access CVE, attacker persistence, privilege escalation, and lateral movement, then summarized findings as an incident assessment.

DFIR Endpoint Forensics

Sherlock: Telly — Network Forensics

Analyzed network telemetry from a compromised backup server after a DLP alert, reconstructing a Telnet-based exploit and exfiltration path via Wireshark and SQLite artifact analysis.

Wireshark Network Forensics
Security Labs & Certifications

Security Labs

50+ Vulnerabilities Identified. Conducted network traffic analysis with Wireshark and performed vulnerability scanning using Nessus. Practiced Active Directory attack and defense techniques in self-built lab environments.

Web Application Penetration Testing Lab

Simulated real-world attacks on vulnerable web applications using Burp Suite, Nmap, and manual testing techniques. Identified and reported multiple critical flaws including SQL injection and XSS.