Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

221 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ IBM Cybersecurity Analyst Professional Certificate Portfolio

IBM Cybersecurity

IBM Cybersecurity Analyst Security+ CYSA+ Wireshark Nmap Splunk Linux Python Docker

🎯 Overview

Welcome to my comprehensive portfolio documenting the completion of the IBM Cybersecurity Analyst Professional Certificate! This repository showcases hands-on labs, projects, and assessments covering the complete cybersecurity analyst workflow - from threat detection and network security to incident response and digital forensics.

πŸ† Professional Certificate Details

  • Certificate: IBM Cybersecurity Analyst Professional Certificate
  • Provider: IBM via Coursera
  • Focus Areas: Security Operations, Incident Response, Network Security, Digital Forensics, Compliance
  • Skills Acquired: Threat Intelligence, Vulnerability Assessment, Security Monitoring, SIEM, EDR, Firewall Management, Encryption, Penetration Testing

πŸ“š Course Structure & Portfolio Contents

1. 🌐 Introduction to Cybersecurity Tools & Cyberattacks

  • Topics Covered: Cybersecurity history, attack types, defense strategies, X-Force Threat Intelligence
  • Key Labs:
    • CIPHER/ - Interactive cybersecurity glossary
    • PATHOGEN/ - Malware type identification lab
    • DECEIVER/ - Social engineering attack simulator
    • FORTRESS/ - Security controls classification
    • SENTINEL/ - Insider threat mitigation
    • RKHUNTER LIVE/ - Malware scanning with rkhunter
    • Final Project: Secure Access - TechSolutions Inc. Security Assessment

2. πŸ” Cybersecurity Essentials

  • Topics Covered: CIA triad, password management, physical security, data breaches
  • Key Labs:
    • Password policy enforcement in Windows
    • Browser security configuration
    • Windows Defender Antivirus management
    • Windows Firewall configuration
    • Windows Update management
    • Interactive Tools: HACKNET/ - Hacker Typer simulation

3. πŸ—οΈ Cybersecurity Architecture

  • Topics Covered: Security frameworks (NIST), IAM, endpoint security, network security architecture
  • Key Labs:
    • Security architecture diagram creation (Draw.io)
    • X-Force Threat Exchange analysis
    • Jackson Corporation security recommendations
    • Secure network diagram design
    • Final Project: Network Security Improvement Recommendations

4. πŸ“‹ Cybersecurity Compliance Framework, Standards & Regulations

  • Topics Covered: HIPAA, GDPR, NIST CSF, ISO 27001, COBIT, ITIL, OWASP
  • Key Labs:
    • NIST CSF alignment assessment
    • Asset management lifecycle
    • GRC tools evaluation (MetricStream)
    • OWASP use case analysis
    • Global cybersecurity law application

5. πŸ–₯️ Operating Systems: Overview, Administration, and Security

  • Topics Covered: Windows & Linux administration, user management, file permissions, containers
  • Key Labs:
    • KERNEL/ - Linux command mastery
    • Windows Server feature exploration
    • Linux user & group management
    • File explorer administration
    • Command prompt tools (ipconfig, netstat, chkdsk, sfc)
    • Docker & container security
    • Windows Defender Firewall configuration
    • Final Project: Cyber Secure Inc. - Windows & Linux security tasks

6. πŸ’Ύ Database Essentials and Vulnerabilities

  • Topics Covered: SQL fundamentals, database security, SQL injection attacks
  • Key Labs:
    • SELECT, INSERT, UPDATE, DELETE operations
    • COUNT, DISTINCT, LIMIT queries
    • SQL Injection Attack Lab - Authentication bypass, data extraction
    • MySQL user account management
    • Database encryption (AES)
    • Role-based access control

7. πŸ”¬ Penetration Testing, Threat Hunting, and Cryptography

  • Topics Covered: Nmap scanning, vulnerability assessment, encryption (AES/RSA), threat intelligence
  • Key Labs:
    • Network protocol analysis with Wireshark
    • Port scanning with Nmap (CLI & Zenmap GUI)
    • Google Dorking techniques
    • X-Force threat report analysis
    • Symmetric Encryption with AES-256-CBC
    • Asymmetric Encryption with RSA
    • Nessus vulnerability scanning (credentialed & non-credentialed)
    • Splunk security monitoring & alerting
    • TheHive incident response platform
    • Snyk code repository scanning
    • Cryptanalysis with CrypTool2
    • Final Project: Vulnerability analysis + secure encryption implementation

8. 🚨 Incident Response and Digital Forensics

  • Topics Covered: NIST/SANS frameworks, evidence handling, forensic tools, log analysis
  • Key Labs:
    • Autopsy - Digital forensics investigation
    • FTK Imager - Forensic imaging & evidence acquisition
    • Velociraptor - Endpoint forensics & IR
    • Volatility - Memory forensics analysis
    • KAPE - Triage forensics & evidence collection
    • Cowrie honeypot - Log investigation
    • SecureSync Corporation - Data breach simulation
    • Final Project: Complete incident response & forensics investigation

9. πŸ“‘ Computer Networks and Network Security

  • Topics Covered: TCP/IP, routing/switching, firewalls, IDS/IPS, DHCP, DNS filtering
  • Key Labs:
    • Network structure design (Draw.io)
    • Wireshark traffic analysis (TCP vs UDP)
    • Windows Firewall configuration (inbound/outbound rules)
    • DHCP server installation & configuration
    • DNS filtering implementation
    • Port & protocol exploration
    • Intrusion Detection System activity
    • OpenEDR endpoint protection
    • SOHO network security (WPA3, SSID)
    • Final Project: Network design & security configuration

10. 🧠 Generative AI: Boost Your Cybersecurity Career

  • Topics Covered: AI in SOC operations, threat intelligence, incident response automation
  • Key Labs:
    • Attack pattern analysis with Watsonx
    • Incident report & playbook generation (ChatGPT)
    • Alert generation & response (Claude AI)
    • Malicious code prevention using AI
    • Training AI with incident data
    • Threat intelligence automation
    • Content filtering with generative AI
    • Final Project: Cybersecurity with Generative AI

11. πŸ“Š Cybersecurity Assessment - CompTIA Security+ & CYSA+

  • Topics Covered: Exam preparation, domain mastery, glossary review
  • Key Resources:
    • security_plus_all_5_domains.html - Complete Security+ review
    • cysa_plus_all_4_domains.html - Complete CYSA+ review
    • CompTIA certification study guides
    • Practice exam instructions

12. πŸ“š Cybersecurity Case Studies and Capstone Project

  • Topics Covered: Real-world breach analysis, ransomware trends, insider threats
  • Case Studies:
    • Target Kill Chain Analysis (2014 breach)
    • Facebook & Google phishing case study
    • Cisco Cyber Threat Trends Report
    • Digital forensics failures
    • Largest cybersecurity fines in history
    • Penetration testing tales
    • Final Project: Analyzing a Data Breach - Comprehensive investigation

13. πŸ’Ό Cybersecurity Job Search, Resume, and Interview Prep

  • Topics Covered: Career planning, resume writing, interview techniques, STAR method
  • Key Resources:
    • cyberprep.html - Interactive career preparation tool
    • Resume & cover letter templates
    • NICE framework career pathways
    • Mock interview critiques
    • Elevator pitch development
    • Professional portfolio creation

14. πŸŽ“ Introduction to Cybersecurity Careers

  • Topics Covered: Career paths, certifications, skills mapping, job roles
  • Key Labs:
    • Cybersecurity career path exploration (CyberSeek)
    • Skills-to-job role mapping
    • Certification roadmap (CompTIA, ISC2, EC-Council, GIAC)
    • Final Project: Personal cybersecurity career plan

πŸ› οΈ Technical Skills Demonstrated

Security Operations & Monitoring

Splunk TheHive QRadar

Network Security

Wireshark Nmap Nessus

Digital Forensics

Autopsy Volatility FTK Imager

Operating Systems

Windows Server Linux Docker

Cryptography

OpenSSL AES RSA

Security Frameworks

NIST ISO 27001 HIPAA GDPR

πŸ“ Repository Structure

IBM-Cybersecurity-Analyst-Portfolio/
β”‚
β”œβ”€β”€ πŸ“ Introduction to Cybersecurity Tools & Cyberattacks/
β”‚   β”œβ”€β”€ πŸ§ͺ CIPHER/ - Interactive glossary
β”‚   β”œβ”€β”€ 🦠 PATHOGEN/ - Malware identification
β”‚   β”œβ”€β”€ 🎭 DECEIVER/ - Social engineering simulator
β”‚   β”œβ”€β”€ 🏰 FORTRESS/ - Security controls
β”‚   └── 🎯 Final Project - Secure Access
β”‚
β”œβ”€β”€ πŸ“ Cybersecurity Essentials/
β”‚   β”œβ”€β”€ πŸ”‘ Password policy enforcement
β”‚   β”œβ”€β”€ 🌐 Browser security settings
β”‚   β”œβ”€β”€ πŸ›‘οΈ Windows Defender & Firewall
β”‚   └── HACKNET/ - Hacker Typer
β”‚
β”œβ”€β”€ πŸ“ Cybersecurity Architecture/
β”‚   β”œβ”€β”€ πŸ“ Security architecture diagrams
β”‚   β”œβ”€β”€ πŸ” X-Force Threat Exchange
β”‚   └── 🏒 Jackson Corporation project
β”‚
β”œβ”€β”€ πŸ“ Compliance Framework & Standards/
β”‚   β”œβ”€β”€ πŸ“‹ NIST CSF alignment
β”‚   β”œβ”€β”€ πŸ“Š GRC tools evaluation
β”‚   └── 🌍 Global law application
β”‚
β”œβ”€β”€ πŸ“ Operating Systems Security/
β”‚   β”œβ”€β”€ 🐧 KERNEL/ - Linux command lab
β”‚   β”œβ”€β”€ πŸͺŸ Windows Server administration
β”‚   β”œβ”€β”€ 🐳 Docker containers
β”‚   └── 🎯 Final Project - Cyber Secure Inc.
β”‚
β”œβ”€β”€ πŸ“ Database Essentials & Vulnerabilities/
β”‚   β”œβ”€β”€ πŸ“ SQL fundamentals
β”‚   β”œβ”€β”€ πŸ’‰ SQL injection attacks
β”‚   └── πŸ” Database encryption & access control
β”‚
β”œβ”€β”€ πŸ“ Penetration Testing & Cryptography/
β”‚   β”œβ”€β”€ πŸ” Network scanning (Nmap/Wireshark)
β”‚   β”œβ”€β”€ πŸ”“ Google Dorking
β”‚   β”œβ”€β”€ πŸ” AES/RSA encryption
β”‚   β”œβ”€β”€ πŸ“Š Splunk monitoring
β”‚   β”œβ”€β”€ πŸ› Nessus vulnerability scanning
β”‚   β”œβ”€β”€ πŸ₯ TheHive incident response
β”‚   └── 🎯 Final Project - Vulnerability analysis
β”‚
β”œβ”€β”€ πŸ“ Incident Response & Digital Forensics/
β”‚   β”œβ”€β”€ πŸ”¬ Autopsy forensics
β”‚   β”œβ”€β”€ πŸ’Ύ FTK Imager
β”‚   β”œβ”€β”€ πŸš€ Velociraptor
β”‚   β”œβ”€β”€ 🧠 Volatility memory forensics
β”‚   β”œβ”€β”€ πŸ“¦ KAPE triage
β”‚   └── 🎯 Final Project - SecureSync breach
β”‚
β”œβ”€β”€ πŸ“ Computer Networks & Security/
β”‚   β”œβ”€β”€ 🌐 Network design (Draw.io)
β”‚   β”œβ”€β”€ πŸ“‘ Wireshark traffic analysis
β”‚   β”œβ”€β”€ πŸ”₯ Windows Firewall rules
β”‚   β”œβ”€β”€ πŸ“‘ DHCP configuration
β”‚   └── 🎯 Final Project - Network security design
β”‚
β”œβ”€β”€ πŸ“ Generative AI for Cybersecurity/
β”‚   β”œβ”€β”€ πŸ€– Watsonx attack analysis
β”‚   β”œβ”€β”€ πŸ’¬ ChatGPT playbook generation
β”‚   β”œβ”€β”€ 🧠 Claude AI incident response
β”‚   └── 🎯 Final Project - Cyber AI
β”‚
β”œβ”€β”€ πŸ“ CompTIA Security+ & CYSA+/
β”‚   β”œβ”€β”€ πŸ“š Security+ 5 domains
β”‚   β”œβ”€β”€ πŸ“š CYSA+ 4 domains
β”‚   └── πŸ“ Exam prep materials
β”‚
β”œβ”€β”€ πŸ“ Case Studies & Capstone/
β”‚   β”œβ”€β”€ πŸ“° Target breach analysis
β”‚   β”œβ”€β”€ πŸ” Facebook/Google phishing
β”‚   └── 🎯 Final Project - Data breach investigation
β”‚
└── πŸ“ Career Preparation/
    β”œβ”€β”€ πŸ’Ό cyberprep.html
    β”œβ”€β”€ πŸ“„ Resume & cover letter templates
    └── 🎀 Interview prep & STAR method

πŸš€ Key Projects Showcase

🌟 Featured: SecureSync Corporation Data Breach Investigation

  • Scope: Complete IR simulation from detection to remediation
  • Tools: Autopsy, Velociraptor, Splunk, TheHive
  • Outcome: Root cause analysis, containment strategy, forensic report

🌟 Featured: Penetration Testing Lab

  • Scope: Full vulnerability assessment of target network
  • Tools: Nessus, Nmap, Metasploit (simulated), Wireshark
  • Outcome: 40+ vulnerabilities identified, prioritized remediation plan

🌟 Featured: SQL Injection Attack Lab

  • Scope: Hands-on exploitation of vulnerable database
  • Techniques: Authentication bypass, data extraction, blind SQLi
  • Outcome: Complete attack chain documentation & defensive measures

πŸ“ˆ Key Achievements

βœ… Completed 14-course professional certificate
βœ… 150+ hands-on cybersecurity labs
βœ… Mastered SIEM tools (Splunk, QRadar)
βœ… Performed digital forensics with industry tools
βœ… Conducted vulnerability assessments (Nessus, Nmap)
βœ… Implemented encryption (AES-256, RSA)
βœ… Responded to simulated breaches (IR lifecycle)
βœ… Earned CompTIA Security+ & CYSA+ preparation

🎯 Learning Outcomes

  • Security Operations - Monitor, detect, and respond to security incidents
  • Network Defense - Configure firewalls, IDS/IPS, and secure network architecture
  • Threat Intelligence - Analyze threat reports and IoCs from X-Force Exchange
  • Vulnerability Management - Scan, assess, and remediate system weaknesses
  • Digital Forensics - Acquire, analyze, and report on digital evidence
  • Incident Response - Execute NIST/SANS IR frameworks end-to-end
  • Compliance - Apply HIPAA, GDPR, NIST, ISO standards
  • Cryptography - Implement symmetric/asymmetric encryption
  • Penetration Testing - Perform authorized security assessments
  • Cloud Security - Secure containers (Docker) and cloud environments

🎯 Core Competencies

Domain Skills
Network Security Wireshark, Nmap, Windows Firewall, DHCP, DNS filtering, IDS/IPS
Vulnerability Management Nessus, Nmap/Zenmap, Google Dorking, vulnerability assessment
Security Monitoring Splunk, TheHive, OpenEDR, SIEM analysis
Digital Forensics Autopsy, FTK Imager, Volatility, KAPE, Velociraptor
Incident Response NIST/SANS frameworks, log analysis, Cowrie honeypot
Cryptography AES-256-CBC, RSA, OpenSSL, cryptanalysis with CrypTool2
Compliance NIST CSF, HIPAA, GDPR, ISO 27001, OWASP
Operating Systems Windows Server, Linux (Kali/Ubuntu), Docker containers

πŸ“Έ Lab Evidence Portfolio

🌐 Network Security & Traffic Analysis

TCP vs UDP Traffic Analysis with Wireshark

Captured and analyzed live network traffic to understand protocol behavior

Evidence Analysis
Wireshark download Action: Installed Wireshark from official source
Start capture Action: Initiated packet capture on network interface
TCP handshake Finding: Identified TCP 3-way handshake (SYN, SYN-ACK, ACK) establishing connection
UDP packets Finding: UDP packets showing connectionless transmission without handshake
UDP header Finding: Examined UDP header structure (source/dest ports, length, checksum)

πŸ› οΈ Tools: Wireshark, Windows Command Prompt πŸ“ Summary: Successfully distinguished TCP (connection-oriented, reliable) vs UDP (connectionless, faster) protocols through live traffic capture and analysis.


DNS Filtering Implementation

Configured Windows Firewall to block DNS traffic to specific domains

Evidence Analysis
DNS Rule Block Action: Created outbound rule blocking UDP port 53 (DNS) for google.com
nslookup failing Finding: nslookup google.com failed - DNS resolution blocked
nslookup working Finding: After disabling rule, DNS resolution restored
DNS cache flush Action: Executed ipconfig /flushdns to clear cache

πŸ› οΈ Tools: Windows Defender Firewall with Advanced Security, nslookup πŸ“ Summary: Implemented DNS-layer filtering to block domain resolution, demonstrating content filtering capabilities at the network level.


Port Scanning with Nmap (CLI & Zenmap GUI)

Discovered open ports, running services, and OS fingerprinting

Evidence Analysis
Nmap version Action: Verified Nmap installation (nmap --version)
Basic scan Finding: Basic scan revealed open ports on target
Aggressive scan Finding: -A flag enabled OS detection, version detection, and traceroute
Zenmap results Finding: Zenmap GUI displaying port states (open/filtered/closed) with service versions
Topology tab Finding: Visual network topology mapping of discovered hosts

πŸ› οΈ Tools: Nmap CLI, Zenmap, Kali Linux container (Docker) πŸ“ Summary: Performed comprehensive network reconnaissance including SYN scans, service version detection, and OS fingerprinting on test targets (scanme.nmap.org).


πŸ”₯ Firewall Configuration & Access Control

Windows Firewall with Advanced Security

Created granular inbound/outbound rules with scope restrictions

Evidence Analysis
Rule Type selection Action: Created custom firewall rule (not using presets)
Scope configuration Finding: Restricted rule scope to specific remote IP addresses
IP address added Action: Added specific IP addresses to rule scope
Block action Finding: Configured rule to block rather than allow traffic
Ping blocked Finding: ICMP ping to blocked IP address failed - rule successfully enforced

πŸ› οΈ Tools: Windows Defender Firewall with Advanced Security, ping, Control Panel πŸ“ Summary: Created scope-restricted firewall rules demonstrating principle of least privilege at network level.


SOHO Network Security Configuration

Secured home/small office router with WPA3 encryption

Evidence Analysis
Linksys emulator Action: Accessed Linksys E7350 router configuration interface
WPA3 selected Finding: Configured WPA3 Personal encryption (latest standard)
Passphrase set Action: Set strong passphrase for wireless authentication
Admin password Finding: Changed default administrator credentials

πŸ› οΈ Tools: Linksys E7350 emulator, VULTR πŸ“ Summary: Hardened SOHO network configuration including WPA3 encryption, strong passphrases, and administrative password change.


🦠 Vulnerability Assessment & Penetration Testing

Nessus Vulnerability Scanning (Credentialed & Non-Credentialed)

Performed authenticated vulnerability scan on Windows target

Evidence Analysis
Nessus installation Action: Installed Tenable Nessus Essentials on Windows
Scan configuration Action: Configured credentialed scan with Windows credentials
41 vulnerabilities Finding: Credentialed scan identified 41 vulnerabilities on Windows VM
Critical vulnerabilities Finding: Multiple critical severity vulnerabilities requiring immediate patching
SSL vulnerability Finding: SSL/TLS certificate vulnerability identified

πŸ› οΈ Tools: Tenable Nessus Essentials, VirtualBox, Windows Target VM πŸ“ Summary: Demonstrated difference between credentialed (more accurate, 41 findings) vs non-credentialed scanning. Identified specific CVEs and provided remediation priorities.


Google Dorking for OSINT

Used advanced Google search operators for security reconnaissance

Evidence Analysis
Filetype search Action: filetype:pdf "confidential" - Found sensitive PDF documents
Site operator Finding: Discovered exposed PDF files with sensitive content
Combined operators Action: site:gov "security assessment" filetype:pdf
Admin panels Finding: Located exposed admin login portals via intitle:"admin panel"

πŸ› οΈ Tools: Google Chrome, Google search operators πŸ“ Summary: Demonstrated OSINT capabilities using legal Google Dorking techniques. Identified exposed admin panels, sensitive file types, and directory listings.


πŸ” Cryptography Implementation

Symmetric Encryption with AES-256-CBC

Implemented file encryption using industry-standard AES

Evidence Analysis
OpenSSL version Action: Verified OpenSSL 3.x installation
Generate AES key Action: Generated 256-bit encryption key
Encryption command Action: openssl enc -aes-256-cbc -salt -in file.txt -out file.enc
Encrypted file Finding: Encrypted output appears as unreadable binary data
Decryption Finding: Successfully decrypted using -d flag and same key

πŸ› οΈ Tools: OpenSSL CLI, Windows Terminal πŸ“ Summary: Implemented AES-256-CBC encryption for files, including key generation, salting, and secure decryption. Demonstrated both password-based and key-file encryption methods.


Asymmetric Encryption with RSA

Public/private key pair generation and hybrid encryption

Evidence Analysis
Generate private key Action: openssl genrsa -out private.pem 2048 - Generated 2048-bit RSA private key
Generate public key Action: openssl rsa -in private.pem -pubout -out public.pem
Encrypt with public Finding: Encrypted file using recipient's public key (only private key can decrypt)

πŸ› οΈ Tools: OpenSSL CLI πŸ“ Summary: Created RSA key pair, distributed public key, encrypted files for intended recipient only. Demonstrated asymmetric encryption for secure key exchange.


🚨 SIEM & Security Monitoring

Splunk Security Monitoring & Alerting

Ingested security logs, created dashboards, configured alerts

Evidence Analysis
Splunk login Action: Deployed Splunk Enterprise locally, accessed web interface
Add data Action: Ingested BOTS v3 dataset (pre-captured security data)
Dashboard creation Action: Created custom security monitoring dashboard
Brute force detection Finding: Detected failed login attempts >10 from same source - brute force pattern
Alert creation Action: Configured alert for privilege escalation events
Geolocation hunting Finding: Mapped login attempts by geolocation to identify anomalous access

πŸ› οΈ Tools: Splunk Enterprise, BOTS v3 dataset πŸ“ Summary: Built complete SIEM workflow: data ingestion β†’ searching β†’ dashboarding β†’ alerting. Detected brute force attacks, privilege abuse, and lateral movement patterns.


πŸ’Ύ Digital Forensics & Incident Response

Autopsy Digital Forensics Investigation

Analyzed disk image, recovered deleted files, generated forensic report

Evidence Analysis
Autopsy case creation Action: Created new forensic case in Autopsy
Add evidence Action: Loaded disk image (.E01 format) as evidence
Deleted files Finding: Located deleted files recoverable from unallocated space
Email extraction Finding: Extracted email artifacts with timestamps and content
Timeline analysis Finding: Created chronological timeline of file system events
Generate report Action: Generated comprehensive HTML forensic report

πŸ› οΈ Tools: Autopsy, FTK Imager, NPS-2010-emails.E01 evidence file πŸ“ Summary: Conducted complete disk forensics investigation including file carving, metadata extraction, email analysis, and timeline reconstruction.


Memory Forensics with Volatility

Analyzed memory dump for running processes, network connections, and malware artifacts

Evidence Analysis
Volatility installation Action: Installed Volatility 3 for memory analysis
Memory dump Action: Acquired memory dump from target VM
Profile detection Finding: Identified correct OS profile for memory dump

πŸ› οΈ Tools: Volatility 3, VirtualBox, Windows memory dump πŸ“ Summary: Performed memory forensics to identify rogue processes, hidden network connections, and potential malware persistence mechanisms.


Cowrie Honeypot Log Investigation

Analyzed attacker interaction logs from SSH honeypot

Evidence Analysis
Cowrie logs Finding: Multiple failed login attempts from same source IP
Command logs Finding: Attacker executed reconnaissance commands (cat /etc/passwd, uname -a)
Malicious download Finding: Attempted download of suspicious payload from external server

πŸ› οΈ Tools: Cowrie honeypot logs, terminal analysis πŸ“ Summary: Analyzed real attacker behavior in safe honeypot environment, documenting TTPs including credential brute forcing and privilege escalation attempts.


πŸ—„οΈ Database Security & SQL Injection

SQL Injection Attack Lab

Exploited vulnerable database to bypass authentication and extract data

Evidence Analysis
Create vulnerable DB Action: Created MySQL database with intentionally vulnerable login form
Authentication bypass Finding: ' OR '1'='1 payload bypassed login without valid credentials
Data extraction Finding: Used UNION attack to extract user table data
Blind SQL injection Finding: Boolean-based blind injection to enumerate database schema

πŸ› οΈ Tools: MySQL, phpMyAdmin, custom vulnerable web app πŸ“ Summary: Successfully demonstrated authentication bypass, data extraction, and schema enumeration. Documented defensive measures including parameterized queries and least privilege.


MySQL User Access Control & Encryption

Implemented role-based access control and column-level encryption

Evidence Analysis
Create user Action: Created restricted MySQL user account
Grant privileges Action: Granted SELECT-only access on specific tables
Encrypt column Finding: Implemented AES_ENCRYPT() for sensitive PII columns

πŸ› οΈ Tools: MySQL, phpMyAdmin πŸ“ Summary: Implemented defense-in-depth database security including account management, RBAC, and data-at-rest encryption.


πŸ“Š Network Design & Security Architecture

Network Diagram Creation (Draw.io)

Designed secure network architectures with DMZ, firewalls, and segmentation

Evidence Analysis
Draw.io interface Action: Used Draw.io for network topology design
Network hierarchy Finding: Created hierarchical network showing core, distribution, access layers
Router and switch Finding: Designed perimeter router feeding internal switch infrastructure

πŸ› οΈ Tools: Draw.io, Lucidchart-style diagramming πŸ“ Summary: Created professional network diagrams including DMZ segmentation, firewall placement, and security zones.


TechSafe Ltd. Network Design (Final Project)

Complete network security configuration with access controls

Evidence Analysis
TechSafe diagram Action: Designed complete corporate network with segmented VLANs
Subnet calculation Finding: Calculated CIDR subnets for each department (HR, Finance, Engineering)
RDP restriction Action: Created firewall rule restricting RDP (3389) to authorized subnets only

πŸ› οΈ Tools: Draw.io, Windows Firewall, subnet calculators πŸ“ Summary: Architected secure network from scratch including IP scheme, VLAN segmentation, and restrictive firewall policies.


πŸŽ“ Interactive Security Simulators (Custom HTML Tools)

Simulator Purpose Live Demo
HACKNET Hacker Typer simulation for security awareness Click to Hack β†’
RKHUNTER LIVE Malware detection with rkhunter Click to Scan β†’
DECEIVER Social engineering attack simulator Click to Deceive β†’
PATHOGEN Malware type identification lab Click to Infect β†’
FORTRESS Security controls classification Click to Fortify β†’
SENTINEL Insider threat mitigation scenarios Click to Monitor β†’
NEXUS Security assessment tool Click to Assess β†’
CYBERSEC Cybersecurity glossary with flashcards Click to Decode β†’
KERNEL Linux command interactive lab Click to Terminal β†’
VAULT Authentication methods explorer Click to Authenticate β†’
STRATOS Cloud container security simulator Click to Deploy β†’
CyberPrep Career preparation toolkit Click to Prepare β†’

πŸ›‘οΈ Security Tools Mastered

Category Tools
SIEM Splunk, IBM QRadar
Firewall Windows Defender Firewall, pfSense
IDS/IPS Snort, OpenEDR
Forensics Autopsy, FTK Imager, Volatility, KAPE, Velociraptor
Network Analysis Wireshark, Nmap, Zenmap
Vulnerability Scanning Nessus, Snyk
Endpoint Security Velociraptor, Windows Defender
Encryption OpenSSL (AES, RSA)
IR Platform TheHive, Cowrie
Compliance MetricStream GRC

πŸš€ Getting Started

Prerequisites

  • Windows 10/11 or Linux (Ubuntu/Kali)
  • VirtualBox (for VM-based labs)
  • Docker Desktop
  • Python 3.8+
  • Modern web browser

Setup Instructions

  1. Clone the repository:
    git clone https://github.com/Willie-Conway/IBM-Cybersecurity-Analyst-Portfolio.git
  2. Navigate to specific lab directories
  3. Follow individual lab README files
  4. Launch HTML-based simulators directly in browser
  5. For VM labs, import OVA files into VirtualBox

πŸ“œ Certifications Preparation

This portfolio includes comprehensive preparation materials for:

  • CompTIA Security+ (SY0-701)
  • CompTIA Cybersecurity Analyst (CYSA+) (CS0-003)

Interactive study tools:

  • security_plus_all_5_domains.html - All 5 domains with flashcards
  • cysa_plus_all_4_domains.html - All 4 domains with practice scenarios

🀝 Contributing

This portfolio is a personal showcase of my cybersecurity learning journey. Feedback and suggestions for improvement are welcome!

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ“§ Contact

Willie Conway


⭐ If this portfolio helps your cybersecurity journey, please give it a star! ⭐


Last Updated: May 2026 Status: 🟒 Active Development
Certification Status: βœ… Completed


"The art of cybersecurity is not just about building walls - it's about understanding how to find the doors, windows, and hidden passages before the adversary does."

About

Professional portfolio showcasing the IBM Cybersecurity Analyst Certificate journey πŸ†. Features 14 courses, 150+ labs, network security πŸ”’, digital forensics πŸ”, penetration testing 🎯, incident response 🚨, SIEM monitoring (Splunk) πŸ“Š, SQL injection πŸ’‰, and encryption (AES/RSA) πŸ”. Demonstrates end-to-end security operations expertise.

Topics

Resources

Stars

Watchers

Forks

Contributors

Languages