Skip to main content

Research & Labs

Research & Labs

This section highlights hands-on lab work and technical notes that support my cybersecurity foundation.

The project gallery contains the full academic evidence map. This page is narrower: it focuses on ServiceNow SecOps workflow work, malware analysis, security foundations, and lab collections that show how I work through systems, evidence, tools, and process.

How to read this section: Start with ServiceNow SecOps for role fit, CYBER 366 for malware analysis, CYBER 262 for security foundations, and IST 451 for broader security lab exposure.


Primary Lab Evidence
#

ServiceNow SecOps Lab Hub
#

The most career-aligned lab section.

It focuses on Vulnerability Response workflow: vulnerable item triage, ownership, remediation tracking, validation, exception handling, and closure.

Primary Focus ServiceNow SecOps

ServiceNow VR Triage Checklist
#

A practical checklist for thinking through vulnerable item intake, risk review, assignment group ownership, remediation path, exception handling, validation, and closure.

Vulnerability Response Checklist

CYBER 366: Malware Analytics & Reverse Engineering
#

My strongest malware-analysis lab collection.

It covers static analysis, dynamic analysis, packed executables, UPX, FLOSS, PE inspection, ProcMon, RegShot, IDA Pro, Ghidra, Binary Ninja, anti-debugging behavior, and keylogging indicators.

Malware Analysis Reverse Engineering

Supporting Lab Collections
#

CYBER 262: Security Foundations Lab Collection
#

Hands-on security foundations work covering Linux log analysis, Python parsing, endpoint protection, Wazuh HIDS, Snort NIDS, Splunk, two-factor authentication, and buffer overflow concepts.

Security Foundations Hands-On Labs

IST 451: Security Labs Collection
#

A broader security lab collection covering service identification, Apache hardening, OpenVAS, SQL injection concepts, malware analysis, IDS concepts, wireless security, and privilege escalation concepts.

Security Labs Vulnerability Analysis

Academic Projects Gallery#

Larger project writeups live in the academic projects gallery, including incident response, digital forensics, governance, cloud, HCI, privacy, software development, and risk analysis.

Course-Coded Evidence Project Gallery

What This Section Demonstrates
#

Area
What It Shows
Signal
ServiceNow SecOps
Workflow thinking around vulnerable item review, assignment, remediation, exception handling, validation, closure, and analyst-supported decision making.
Primary Career Fit
Malware Analysis
Static and dynamic analysis, unpacking, strings review, behavioral observation, process activity, registry review, and reverse-engineering tool exposure.
Technical Depth
Detection Foundations
Wazuh, Snort, Splunk, endpoint protection, logs, IDS concepts, alerting concepts, and SIEM-style investigation foundations.
SOC-Relevant
Security Lab Breadth
Web security, vulnerability scanning, IDS concepts, wireless security, malware investigation, Apache hardening, and privilege escalation concepts.
Supporting Evidence

Tools and Concepts Referenced
#

This is not a mastery claim for every tool. It is a map of tools and concepts used or studied in the lab work summarized here.

Tool / Concept
Used For
Evidence
ServiceNow SecOps / VR
Vulnerable item triage, ownership routing, remediation workflow, validation, exception handling, and closure thinking.
SecOps Hub
PEiD, UPX, FLOSS
Executable metadata review, packed executable identification, unpacking, decoded strings, and stack-string review.
CYBER 366
ProcMon, RegShot, Process Explorer
Dynamic analysis, process behavior, registry activity, file-system writes, and clean-state comparison.
CYBER 366
IDA Pro, Ghidra, Binary Ninja
Disassembly, decompilation, function review, string references, imported API interpretation, and control-flow reasoning.
CYBER 366
Wazuh, Snort, Splunk
Host-based detection, network intrusion detection, log review, alerting concepts, and SIEM-style investigation foundations.
CYBER 262
OpenVAS, Apache, SQL Injection Concepts
Service identification, web server hardening, vulnerability scanning, SQL injection concepts, and defensive security lab work.
IST 451

How I Treat Lab Writeups
#

Keep the Method
#

I summarize the workflow, tools, findings, reasoning, and lessons learned.

Method

Remove Sensitive Details
#

I do not publish raw submissions, malware samples, private screenshots, credentials, exact lab artifacts, or full solution steps.

Redacted

Connect Labs to Roles
#

The goal is not to show that I completed a class. The goal is to show what the work proves about how I investigate, document, and think through security problems.

Evidence


Continue Reviewing
#