07 PROJECTS / CYBERSECURITY & INFRASTRUCTURE

Portfolio Projects

A showcase of my cybersecurity and infrastructure projects demonstrating hands-on experience with security tools and technologies.

PROJECT / 01

Honeynet in Azure

View on GitHub

A comprehensive honeypot network deployed in Microsoft Azure to monitor and analyze cyber threats in real-time.

Technologies Used

AzureSecurity AnalyticsSIEMThreat Detection

Key Highlights

  • Real-time threat monitoring
  • Automated incident response
  • Comprehensive logging and analysis
  • Geographic attack visualization
PROJECT / 02

Deploy Gophish on Railway

Deployed Gophish phishing framework on Railway platform for security awareness training and penetration testing.

Technologies Used

GophishRailwayDockerEmail Security

Key Highlights

  • Automated phishing campaigns
  • User awareness training
  • Campaign analytics and reporting
  • Cloud-based deployment
PROJECT / 03

Palo Alto Firewall Home Lab

Built a comprehensive home lab environment featuring Palo Alto Networks firewall configuration and security testing.

Technologies Used

Palo AltoNetwork SecurityVMwareLab Environment

Key Highlights

  • Advanced threat prevention
  • Network segmentation
  • Security policy configuration
  • Hands-on firewall management
PROJECT / 04

SIEM Threat-Detection Lab: Splunk & Atomic Red Team

Read the case study →

View on GitHub

A mini Security Operations Center (SOC) environment showcasing real-world threat detection using Splunk Enterprise, Sysmon, and Atomic Red Team with MITRE ATT&CK framework mapping.

Technologies Used

Splunk EnterpriseSysmonAtomic Red TeamVirtualBoxWindows 10Ubuntu Server

Key Highlights

  • End-to-end attacker simulation and detection
  • Real-time alerting and correlation logic
  • MITRE ATT&CK framework alignment
  • Comprehensive SIEM deployment and detection engineering
Explore technical details

Technical Implementation

  • Windows 10 VM configured as target endpoint with Splunk Universal Forwarder
  • Ubuntu Server VM hosting Splunk Enterprise for centralized log analysis
  • Sysmon deployment with SwiftOnSecurity configuration for enhanced telemetry
  • Atomic Red Team integration for safe adversarial behavior simulation
  • Real-time dashboards, alerts, and correlation searches in Splunk
  • Detection of brute-force attacks, malicious PowerShell, and persistence techniques

Implementation Details

  • VirtualBox setup with Windows 10 (victim) and Ubuntu Server (SIEM) VMs
  • Splunk Enterprise installation and configuration on Ubuntu Server
  • Splunk Universal Forwarder and Sysmon deployment on Windows 10
  • Log ingestion verification and search functionality testing
  • Atomic Red Team attack simulation execution on Windows endpoint
  • Dashboard creation for threat visualization and monitoring

MITRE ATT&CK Techniques

  • T1059.001: Command & Scripting Interpreter: PowerShell
  • T1110.001: Brute Force: Password Guessing
  • T1547.001: Boot/Logon Autostart Execution: Registry Keys
  • T1110 + T1078: Valid Accounts Used After Brute Force
  • T1059.001 + T1547.001: Multi-Stage Persistence with Scripting

Detection Use Cases

  • Suspicious PowerShell Execution detection and analysis
  • Brute Force Login Attempts monitoring and alerting
  • Registry Key Persistence technique identification
  • Brute Force followed by Successful Login correlation
  • PowerShell followed by Registry Persistence multi-stage detection

Splunk Features Implemented

  • Centralized log collection from Windows endpoints via Universal Forwarder
  • Real-time search and correlation capabilities with SPL queries
  • Custom dashboards for threat visualization and monitoring
  • Automated alerting for suspicious activities and IOCs
  • Saved searches and reports for ongoing threat hunting
  • Correlation logic for multi-stage attack detection

Key Outcomes

  • Enabled centralized log collection and comprehensive endpoint visibility
  • Successfully simulated real-world attacks aligned with MITRE ATT&CK framework
  • Developed robust detection content including dashboards, alerts, and SPL rules
  • Gained practical hands-on experience in SIEM deployment and detection engineering
PROJECT / 05RESEARCH

Remote Keylogger Research

Educational cybersecurity research project demonstrating keystroke logging techniques, steganography, and defensive countermeasures for security awareness.

Technologies Used

PythonPyInstallerSMTPSteganographyThreading

Key Highlights

  • Keystroke capture and logging
  • Remote data transmission via SMTP
  • Steganographic concealment techniques
  • Safety mechanisms and ethical considerations
Explore technical details

Technical Implementation

  • Cross-platform keystroke monitoring using pynput library
  • Secure SMTP transmission for remote data collection
  • File disguising as Windows system files (license_win64_details.txt)
  • Safety kill-switch via right control key for immediate termination
  • Host information gathering (IP, MAC, WiFi profiles, system details)
  • Threaded execution for seamless background operation

Implementation Details

  • GUI popup creation using tkinter for user interaction
  • Incremental data transmission at 500-byte file thresholds
  • PyInstaller compilation to standalone executable (.pyw extension)
  • WinRAR SFX archive packaging for steganographic deployment
  • Automatic cleanup and file deletion on program termination

Ethical Considerations

  • Developed strictly for educational and defensive security research
  • Includes built-in safety mechanisms to prevent misuse
  • Demonstrates attack vectors to improve defensive strategies
  • Used only in controlled environments with proper authorization
PROJECT / 06

PersistenceHunter

View on GitHub

PowerShell CLI tool for hunting Windows malware persistence mechanisms and suspicious autoruns across Registry, Services, Scheduled Tasks, and Startup Items.

Technologies Used

PowerShellWindows SecurityMalware AnalysisMITRE ATT&CKCLI Tools

Key Highlights

  • Automated detection of suspicious autoruns
  • Multi-mode analysis capabilities
  • MITRE ATT&CK framework alignment
  • CSV report generation for findings
Explore technical details

Technical Implementation

  • Analyzes Registry, Services, Scheduled Tasks, and Startup Items
  • Detects autoruns with invalid signatures and suspicious file paths
  • Identifies embedded IPs/domains in execution arguments
  • Monitors startup folder path changes via Registry
  • Detects bootstart key manipulation via Registry
  • Identifies suspicious shortcut targets in Startup Folder
  • Detects persistence via AppInitDLLs

Implementation Details

  • Multiple operation modes: Auto, All, Registry, Services, Tasks, Startup
  • Custom string hunting with user-defined suspicious indicators
  • Hash verification for remote execution (MD5: 1EEA002E9B5832AEE2D3D4E42B9C5054)
  • One-liner remote execution with integrity verification
  • Local and remote deployment options
  • Comprehensive CSV reporting functionality

MITRE ATT&CK Techniques

  • T1547: Boot or Logon Autostart Execution
  • T1053: Scheduled Task/Job
  • T1546.010: Event Triggered Execution: AppInit DLLs

Usage Examples

  • Remote execution with hash verification and auto mode
  • Local usage with custom string hunting parameters
  • Comprehensive autorun enumeration for manual review
  • Targeted analysis by specific persistence mechanism type
PROJECT / 07RESEARCH

Simulating a Local Network Attack: ARP Poisoning and Traffic Interception on a Home Wi-Fi Network

View on GitHub

Comprehensive demonstration of wireless network security testing including reconnaissance, WPA handshake capture, password cracking, and traffic analysis.

Technologies Used

Parrot OSAircrack-ng SuiteHashcatNmapEttercapWireshark

Key Highlights

  • Wireless network reconnaissance and monitoring
  • WPA handshake capture and analysis
  • Dictionary-based password cracking
  • ARP poisoning and man-in-the-middle attacks
Explore technical details

Technical Implementation

  • Monitor mode adapter configuration for passive scanning
  • EAPOL handshake capture during client reconnection
  • Hashcat integration with rockyou wordlist and best64 rules
  • Network topology mapping with vulnerability assessment
  • Real-time traffic interception via ARP poisoning
  • Comprehensive packet analysis and protocol inspection

Implementation Details

  • Airodump-ng for wireless network discovery and client association
  • Aireplay-ng for deauthentication attacks to force handshakes
  • Hashcat dictionary attacks with rule-based password mutations
  • Nmap network scanning for host discovery and service enumeration
  • Ettercap for ARP cache poisoning and traffic forwarding
  • Wireshark for deep packet inspection and protocol analysis

Attack Phases

  • Phase 1: Network reconnaissance using monitor mode scanning
  • Phase 2: Target selection and client association monitoring
  • Phase 3: Handshake capture through deauthentication attacks
  • Phase 4: Password cracking using dictionary and rule-based attacks
  • Phase 5: Network infiltration and internal reconnaissance
  • Phase 6: Man-in-the-middle positioning via ARP poisoning
  • Phase 7: Traffic interception and comprehensive packet analysis

Tools Used

  • airodump-ng: Wireless packet capture and network monitoring
  • aireplay-ng: Injection attacks and client deauthentication
  • hashcat: High-performance password recovery tool
  • nmap: Network discovery and security auditing
  • ettercap: Comprehensive suite for man-in-the-middle attacks
  • wireshark: Network protocol analyzer for traffic inspection

Ethical Considerations

  • Conducted exclusively on personal home network infrastructure
  • Demonstrates real-world attack vectors for defensive understanding
  • Educational research to improve wireless security awareness
  • Used only in controlled environments with proper authorization