Projects
Incident Response PlayBook
Overview
The Incident Response Playbook simulates ransomware attacks and practices full-cycle response. Built in an isolated lab with pfSense, ELK Stack, Wazuh, Sysmon, and Metasploit, it follows the NIST 800-61 framework for detection, containment, eradication, and recovery. The project included forensic evidence collection and detailed documentation to strengthen both attacker and defender perspectives.
Technologies Used
- pfSense firewall
- Windows Server
- Linux (Apache, Postfix)
- ELK Stack
- Wazuh
- Sysmon
- Metasploit
- DVWA
- Kali Linux
Key Learnings
Learned how to integrate SIEM tools, analyze alerts, and document incidents in line with cybersecurity frameworks. Gained practical skills in log analysis, forensic data collection, and developing playbooks that apply to both corporate and law enforcement SOC workflows.
Sports Connect
Overview
Sports Connect is a web application created to connect athletes, coaches, and teams. While primarily a development project, it emphasized secure user authentication and database access controls — introducing me to access management, data security, and protecting sensitive user information, which directly translates into SOC analyst responsibilities.
Technologies Used
- HTML/CSS
- JavaScript
- Responsive design
- User authentication
- Database management
Key Learnings
Gained foundational knowledge in securing web applications, including login workflows and database protection. Learned how access control ties into monitoring and how security-by-design complements SOC detection and response practices.
Law Enforcement SOC Project
Overview
The Law Enforcement SOC Project combines my Mini SOC lab with an expanded law enforcement focus. It begins with building a training SOC (log collection, SIEM dashboards, detection engineering, and case reporting) and extends into simulating protection of municipal infrastructure like 911 CAD systems, evidence databases, and surveillance networks. This project integrates custom SIEM detection rules, forensic playbooks, and court-admissible chain-of-custody documentation.