Welcome to my comprehensive portfolio documenting the completion of the IBM Cybersecurity Analyst Professional Certificate! This repository showcases hands-on labs, projects, and assessments covering the complete cybersecurity analyst workflow - from threat detection and network security to incident response and digital forensics.
- Certificate: IBM Cybersecurity Analyst Professional Certificate
- Provider: IBM via Coursera
- Focus Areas: Security Operations, Incident Response, Network Security, Digital Forensics, Compliance
- Skills Acquired: Threat Intelligence, Vulnerability Assessment, Security Monitoring, SIEM, EDR, Firewall Management, Encryption, Penetration Testing
- Topics Covered: Cybersecurity history, attack types, defense strategies, X-Force Threat Intelligence
- Key Labs:
CIPHER/- Interactive cybersecurity glossaryPATHOGEN/- Malware type identification labDECEIVER/- Social engineering attack simulatorFORTRESS/- Security controls classificationSENTINEL/- Insider threat mitigationRKHUNTER LIVE/- Malware scanning with rkhunter- Final Project: Secure Access - TechSolutions Inc. Security Assessment
- Topics Covered: CIA triad, password management, physical security, data breaches
- Key Labs:
- Password policy enforcement in Windows
- Browser security configuration
- Windows Defender Antivirus management
- Windows Firewall configuration
- Windows Update management
- Interactive Tools:
HACKNET/- Hacker Typer simulation
- Topics Covered: Security frameworks (NIST), IAM, endpoint security, network security architecture
- Key Labs:
- Security architecture diagram creation (Draw.io)
- X-Force Threat Exchange analysis
- Jackson Corporation security recommendations
- Secure network diagram design
- Final Project: Network Security Improvement Recommendations
- Topics Covered: HIPAA, GDPR, NIST CSF, ISO 27001, COBIT, ITIL, OWASP
- Key Labs:
- NIST CSF alignment assessment
- Asset management lifecycle
- GRC tools evaluation (MetricStream)
- OWASP use case analysis
- Global cybersecurity law application
- Topics Covered: Windows & Linux administration, user management, file permissions, containers
- Key Labs:
KERNEL/- Linux command mastery- Windows Server feature exploration
- Linux user & group management
- File explorer administration
- Command prompt tools (ipconfig, netstat, chkdsk, sfc)
- Docker & container security
- Windows Defender Firewall configuration
- Final Project: Cyber Secure Inc. - Windows & Linux security tasks
- Topics Covered: SQL fundamentals, database security, SQL injection attacks
- Key Labs:
- SELECT, INSERT, UPDATE, DELETE operations
- COUNT, DISTINCT, LIMIT queries
- SQL Injection Attack Lab - Authentication bypass, data extraction
- MySQL user account management
- Database encryption (AES)
- Role-based access control
- Topics Covered: Nmap scanning, vulnerability assessment, encryption (AES/RSA), threat intelligence
- Key Labs:
- Network protocol analysis with Wireshark
- Port scanning with Nmap (CLI & Zenmap GUI)
- Google Dorking techniques
- X-Force threat report analysis
- Symmetric Encryption with AES-256-CBC
- Asymmetric Encryption with RSA
- Nessus vulnerability scanning (credentialed & non-credentialed)
- Splunk security monitoring & alerting
- TheHive incident response platform
- Snyk code repository scanning
- Cryptanalysis with CrypTool2
- Final Project: Vulnerability analysis + secure encryption implementation
- Topics Covered: NIST/SANS frameworks, evidence handling, forensic tools, log analysis
- Key Labs:
- Autopsy - Digital forensics investigation
- FTK Imager - Forensic imaging & evidence acquisition
- Velociraptor - Endpoint forensics & IR
- Volatility - Memory forensics analysis
- KAPE - Triage forensics & evidence collection
- Cowrie honeypot - Log investigation
- SecureSync Corporation - Data breach simulation
- Final Project: Complete incident response & forensics investigation
- Topics Covered: TCP/IP, routing/switching, firewalls, IDS/IPS, DHCP, DNS filtering
- Key Labs:
- Network structure design (Draw.io)
- Wireshark traffic analysis (TCP vs UDP)
- Windows Firewall configuration (inbound/outbound rules)
- DHCP server installation & configuration
- DNS filtering implementation
- Port & protocol exploration
- Intrusion Detection System activity
- OpenEDR endpoint protection
- SOHO network security (WPA3, SSID)
- Final Project: Network design & security configuration
- Topics Covered: AI in SOC operations, threat intelligence, incident response automation
- Key Labs:
- Attack pattern analysis with Watsonx
- Incident report & playbook generation (ChatGPT)
- Alert generation & response (Claude AI)
- Malicious code prevention using AI
- Training AI with incident data
- Threat intelligence automation
- Content filtering with generative AI
- Final Project: Cybersecurity with Generative AI
- Topics Covered: Exam preparation, domain mastery, glossary review
- Key Resources:
security_plus_all_5_domains.html- Complete Security+ reviewcysa_plus_all_4_domains.html- Complete CYSA+ review- CompTIA certification study guides
- Practice exam instructions
- Topics Covered: Real-world breach analysis, ransomware trends, insider threats
- Case Studies:
- Target Kill Chain Analysis (2014 breach)
- Facebook & Google phishing case study
- Cisco Cyber Threat Trends Report
- Digital forensics failures
- Largest cybersecurity fines in history
- Penetration testing tales
- Final Project: Analyzing a Data Breach - Comprehensive investigation
- Topics Covered: Career planning, resume writing, interview techniques, STAR method
- Key Resources:
cyberprep.html- Interactive career preparation tool- Resume & cover letter templates
- NICE framework career pathways
- Mock interview critiques
- Elevator pitch development
- Professional portfolio creation
- Topics Covered: Career paths, certifications, skills mapping, job roles
- Key Labs:
- Cybersecurity career path exploration (CyberSeek)
- Skills-to-job role mapping
- Certification roadmap (CompTIA, ISC2, EC-Council, GIAC)
- Final Project: Personal cybersecurity career plan
IBM-Cybersecurity-Analyst-Portfolio/
β
βββ π Introduction to Cybersecurity Tools & Cyberattacks/
β βββ π§ͺ CIPHER/ - Interactive glossary
β βββ π¦ PATHOGEN/ - Malware identification
β βββ π DECEIVER/ - Social engineering simulator
β βββ π° FORTRESS/ - Security controls
β βββ π― Final Project - Secure Access
β
βββ π Cybersecurity Essentials/
β βββ π Password policy enforcement
β βββ π Browser security settings
β βββ π‘οΈ Windows Defender & Firewall
β βββ HACKNET/ - Hacker Typer
β
βββ π Cybersecurity Architecture/
β βββ π Security architecture diagrams
β βββ π X-Force Threat Exchange
β βββ π’ Jackson Corporation project
β
βββ π Compliance Framework & Standards/
β βββ π NIST CSF alignment
β βββ π GRC tools evaluation
β βββ π Global law application
β
βββ π Operating Systems Security/
β βββ π§ KERNEL/ - Linux command lab
β βββ πͺ Windows Server administration
β βββ π³ Docker containers
β βββ π― Final Project - Cyber Secure Inc.
β
βββ π Database Essentials & Vulnerabilities/
β βββ π SQL fundamentals
β βββ π SQL injection attacks
β βββ π Database encryption & access control
β
βββ π Penetration Testing & Cryptography/
β βββ π Network scanning (Nmap/Wireshark)
β βββ π Google Dorking
β βββ π AES/RSA encryption
β βββ π Splunk monitoring
β βββ π Nessus vulnerability scanning
β βββ π₯ TheHive incident response
β βββ π― Final Project - Vulnerability analysis
β
βββ π Incident Response & Digital Forensics/
β βββ π¬ Autopsy forensics
β βββ πΎ FTK Imager
β βββ π Velociraptor
β βββ π§ Volatility memory forensics
β βββ π¦ KAPE triage
β βββ π― Final Project - SecureSync breach
β
βββ π Computer Networks & Security/
β βββ π Network design (Draw.io)
β βββ π‘ Wireshark traffic analysis
β βββ π₯ Windows Firewall rules
β βββ π‘ DHCP configuration
β βββ π― Final Project - Network security design
β
βββ π Generative AI for Cybersecurity/
β βββ π€ Watsonx attack analysis
β βββ π¬ ChatGPT playbook generation
β βββ π§ Claude AI incident response
β βββ π― Final Project - Cyber AI
β
βββ π CompTIA Security+ & CYSA+/
β βββ π Security+ 5 domains
β βββ π CYSA+ 4 domains
β βββ π Exam prep materials
β
βββ π Case Studies & Capstone/
β βββ π° Target breach analysis
β βββ π Facebook/Google phishing
β βββ π― Final Project - Data breach investigation
β
βββ π Career Preparation/
βββ πΌ cyberprep.html
βββ π Resume & cover letter templates
βββ π€ Interview prep & STAR method
- Scope: Complete IR simulation from detection to remediation
- Tools: Autopsy, Velociraptor, Splunk, TheHive
- Outcome: Root cause analysis, containment strategy, forensic report
- Scope: Full vulnerability assessment of target network
- Tools: Nessus, Nmap, Metasploit (simulated), Wireshark
- Outcome: 40+ vulnerabilities identified, prioritized remediation plan
- Scope: Hands-on exploitation of vulnerable database
- Techniques: Authentication bypass, data extraction, blind SQLi
- Outcome: Complete attack chain documentation & defensive measures
β
Completed 14-course professional certificate
β
150+ hands-on cybersecurity labs
β
Mastered SIEM tools (Splunk, QRadar)
β
Performed digital forensics with industry tools
β
Conducted vulnerability assessments (Nessus, Nmap)
β
Implemented encryption (AES-256, RSA)
β
Responded to simulated breaches (IR lifecycle)
β
Earned CompTIA Security+ & CYSA+ preparation
- Security Operations - Monitor, detect, and respond to security incidents
- Network Defense - Configure firewalls, IDS/IPS, and secure network architecture
- Threat Intelligence - Analyze threat reports and IoCs from X-Force Exchange
- Vulnerability Management - Scan, assess, and remediate system weaknesses
- Digital Forensics - Acquire, analyze, and report on digital evidence
- Incident Response - Execute NIST/SANS IR frameworks end-to-end
- Compliance - Apply HIPAA, GDPR, NIST, ISO standards
- Cryptography - Implement symmetric/asymmetric encryption
- Penetration Testing - Perform authorized security assessments
- Cloud Security - Secure containers (Docker) and cloud environments
| Domain | Skills |
|---|---|
| Network Security | Wireshark, Nmap, Windows Firewall, DHCP, DNS filtering, IDS/IPS |
| Vulnerability Management | Nessus, Nmap/Zenmap, Google Dorking, vulnerability assessment |
| Security Monitoring | Splunk, TheHive, OpenEDR, SIEM analysis |
| Digital Forensics | Autopsy, FTK Imager, Volatility, KAPE, Velociraptor |
| Incident Response | NIST/SANS frameworks, log analysis, Cowrie honeypot |
| Cryptography | AES-256-CBC, RSA, OpenSSL, cryptanalysis with CrypTool2 |
| Compliance | NIST CSF, HIPAA, GDPR, ISO 27001, OWASP |
| Operating Systems | Windows Server, Linux (Kali/Ubuntu), Docker containers |
Captured and analyzed live network traffic to understand protocol behavior
π οΈ Tools: Wireshark, Windows Command Prompt π Summary: Successfully distinguished TCP (connection-oriented, reliable) vs UDP (connectionless, faster) protocols through live traffic capture and analysis.
Configured Windows Firewall to block DNS traffic to specific domains
π οΈ Tools: Windows Defender Firewall with Advanced Security, nslookup π Summary: Implemented DNS-layer filtering to block domain resolution, demonstrating content filtering capabilities at the network level.
Discovered open ports, running services, and OS fingerprinting
π οΈ Tools: Nmap CLI, Zenmap, Kali Linux container (Docker) π Summary: Performed comprehensive network reconnaissance including SYN scans, service version detection, and OS fingerprinting on test targets (scanme.nmap.org).
Created granular inbound/outbound rules with scope restrictions
π οΈ Tools: Windows Defender Firewall with Advanced Security, ping, Control Panel π Summary: Created scope-restricted firewall rules demonstrating principle of least privilege at network level.
Secured home/small office router with WPA3 encryption
π οΈ Tools: Linksys E7350 emulator, VULTR π Summary: Hardened SOHO network configuration including WPA3 encryption, strong passphrases, and administrative password change.
Performed authenticated vulnerability scan on Windows target
π οΈ Tools: Tenable Nessus Essentials, VirtualBox, Windows Target VM π Summary: Demonstrated difference between credentialed (more accurate, 41 findings) vs non-credentialed scanning. Identified specific CVEs and provided remediation priorities.
Used advanced Google search operators for security reconnaissance
π οΈ Tools: Google Chrome, Google search operators π Summary: Demonstrated OSINT capabilities using legal Google Dorking techniques. Identified exposed admin panels, sensitive file types, and directory listings.
Implemented file encryption using industry-standard AES
π οΈ Tools: OpenSSL CLI, Windows Terminal π Summary: Implemented AES-256-CBC encryption for files, including key generation, salting, and secure decryption. Demonstrated both password-based and key-file encryption methods.
Public/private key pair generation and hybrid encryption
π οΈ Tools: OpenSSL CLI π Summary: Created RSA key pair, distributed public key, encrypted files for intended recipient only. Demonstrated asymmetric encryption for secure key exchange.
Ingested security logs, created dashboards, configured alerts
π οΈ Tools: Splunk Enterprise, BOTS v3 dataset π Summary: Built complete SIEM workflow: data ingestion β searching β dashboarding β alerting. Detected brute force attacks, privilege abuse, and lateral movement patterns.
Analyzed disk image, recovered deleted files, generated forensic report
π οΈ Tools: Autopsy, FTK Imager, NPS-2010-emails.E01 evidence file π Summary: Conducted complete disk forensics investigation including file carving, metadata extraction, email analysis, and timeline reconstruction.
Analyzed memory dump for running processes, network connections, and malware artifacts
| Evidence | Analysis |
|---|---|
![]() |
Action: Installed Volatility 3 for memory analysis |
![]() |
Action: Acquired memory dump from target VM |
![]() |
Finding: Identified correct OS profile for memory dump |
π οΈ Tools: Volatility 3, VirtualBox, Windows memory dump π Summary: Performed memory forensics to identify rogue processes, hidden network connections, and potential malware persistence mechanisms.
Analyzed attacker interaction logs from SSH honeypot
π οΈ Tools: Cowrie honeypot logs, terminal analysis π Summary: Analyzed real attacker behavior in safe honeypot environment, documenting TTPs including credential brute forcing and privilege escalation attempts.
Exploited vulnerable database to bypass authentication and extract data
π οΈ Tools: MySQL, phpMyAdmin, custom vulnerable web app π Summary: Successfully demonstrated authentication bypass, data extraction, and schema enumeration. Documented defensive measures including parameterized queries and least privilege.
Implemented role-based access control and column-level encryption
| Evidence | Analysis |
|---|---|
![]() |
Action: Created restricted MySQL user account |
![]() |
Action: Granted SELECT-only access on specific tables |
![]() |
Finding: Implemented AES_ENCRYPT() for sensitive PII columns |
π οΈ Tools: MySQL, phpMyAdmin π Summary: Implemented defense-in-depth database security including account management, RBAC, and data-at-rest encryption.
Designed secure network architectures with DMZ, firewalls, and segmentation
π οΈ Tools: Draw.io, Lucidchart-style diagramming π Summary: Created professional network diagrams including DMZ segmentation, firewall placement, and security zones.
Complete network security configuration with access controls
π οΈ Tools: Draw.io, Windows Firewall, subnet calculators π Summary: Architected secure network from scratch including IP scheme, VLAN segmentation, and restrictive firewall policies.
| Simulator | Purpose | Live Demo |
|---|---|---|
| HACKNET | Hacker Typer simulation for security awareness | Click to Hack β |
| RKHUNTER LIVE | Malware detection with rkhunter | Click to Scan β |
| DECEIVER | Social engineering attack simulator | Click to Deceive β |
| PATHOGEN | Malware type identification lab | Click to Infect β |
| FORTRESS | Security controls classification | Click to Fortify β |
| SENTINEL | Insider threat mitigation scenarios | Click to Monitor β |
| NEXUS | Security assessment tool | Click to Assess β |
| CYBERSEC | Cybersecurity glossary with flashcards | Click to Decode β |
| KERNEL | Linux command interactive lab | Click to Terminal β |
| VAULT | Authentication methods explorer | Click to Authenticate β |
| STRATOS | Cloud container security simulator | Click to Deploy β |
| CyberPrep | Career preparation toolkit | Click to Prepare β |
| Category | Tools |
|---|---|
| SIEM | Splunk, IBM QRadar |
| Firewall | Windows Defender Firewall, pfSense |
| IDS/IPS | Snort, OpenEDR |
| Forensics | Autopsy, FTK Imager, Volatility, KAPE, Velociraptor |
| Network Analysis | Wireshark, Nmap, Zenmap |
| Vulnerability Scanning | Nessus, Snyk |
| Endpoint Security | Velociraptor, Windows Defender |
| Encryption | OpenSSL (AES, RSA) |
| IR Platform | TheHive, Cowrie |
| Compliance | MetricStream GRC |
- Windows 10/11 or Linux (Ubuntu/Kali)
- VirtualBox (for VM-based labs)
- Docker Desktop
- Python 3.8+
- Modern web browser
- Clone the repository:
git clone https://github.com/Willie-Conway/IBM-Cybersecurity-Analyst-Portfolio.git
- Navigate to specific lab directories
- Follow individual lab README files
- Launch HTML-based simulators directly in browser
- For VM labs, import OVA files into VirtualBox
This portfolio includes comprehensive preparation materials for:
- CompTIA Security+ (SY0-701)
- CompTIA Cybersecurity Analyst (CYSA+) (CS0-003)
Interactive study tools:
security_plus_all_5_domains.html- All 5 domains with flashcardscysa_plus_all_4_domains.html- All 4 domains with practice scenarios
This portfolio is a personal showcase of my cybersecurity learning journey. Feedback and suggestions for improvement are welcome!
This project is licensed under the MIT License - see the LICENSE file for details.
Willie Conway
- GitHub: @Willie-Conway
- LinkedIn: Willie Conway
- Email: hire.willie.conway@gmail.com
β If this portfolio helps your cybersecurity journey, please give it a star! β
Last Updated: May 2026
Status: π’ Active Development
Certification Status: β
Completed
"The art of cybersecurity is not just about building walls - it's about understanding how to find the doors, windows, and hidden passages before the adversary does."


























































.png)












