Lab & Projects

Practical implementations of defensive security, threat analysis, and GRC.

Active / Completed

Defensive Security Environment (SIEM Lab)

Tech Stack: Wazuh SIEM, ELK Stack, Kali Linux, Ubuntu Server, Windows 10 Targets

To validate and operationalize the methodologies tested in the CompTIA CySA+ certification, I engineered a continuous virtual enterprise environment designed to simulate real-world attacks and execute incident response workflows.

Architecture & Deployment

Threat Detection & Log Analysis


In Progress

Enterprise Active Directory & Threat Hunting

Tech Stack: Windows Server 2022, Active Directory, Sysmon, Splunk, BloodHound

Currently expanding my home lab infrastructure to include a multi-forest Active Directory environment. The goal of this project is to deeply understand Windows enterprise architecture, how threat actors move laterally, and how to detect advanced persistent threats (APTs) at the endpoint level.


Planned: Q4 2026

Cloud Security Posture Management (CSPM) Assessment

Tech Stack: Microsoft Azure, Azure Sentinel, Terraform, CIS Benchmarks

Bridging my experience in GRC/IT Auditing with cloud infrastructure. This upcoming project focuses on identifying, auditing, and remediating cloud misconfigurations at scale.


Planned: Q1 2027

Automated Incident Response Pipeline (SOAR)

Tech Stack: TheHive, Cortex XSOAR, Python, REST APIs

A capstone project aimed at maturing my SOC capabilities by transitioning from manual log analysis to automated orchestration and response.


Published

Research: Insider Threats & Social Engineering Vulnerabilities

Publication: Generation Cooked (Jan 2026)

A comprehensive research project analyzing the human element of cybersecurity and enterprise risk management.