Skip to main content

Research & Labs

Research & Labs

This section is for hands-on lab work and technical notes.

The project gallery has the full course-coded evidence map. This page is narrower: ServiceNow SecOps workflow work, malware/security labs, and the technical lab collections that best show how I work through systems, evidence, and process.

How to read this section: Start with ServiceNow SecOps if you are reviewing role fit. Start with CYBER 366 if you want malware analysis. Start with CYBER 262 or IST 451 if you want broader security foundations.


Start Here
#

ServiceNow SecOps Lab Hub
#

This is the most career-aligned lab section. It focuses on Vulnerability Response workflow: vulnerable item triage, ownership, remediation tracking, validation, exceptions, and closure.

This is where I would send someone first for ServiceNow SecOps or Vulnerability Response conversations.

Primary Focus ServiceNow SecOps

ServiceNow VR Triage Checklist
#

A practical checklist for thinking through vulnerable item intake, risk review, assignment group ownership, remediation path, exception handling, validation, and closure.

This is shorter than the lab hub and easier to review quickly.

Vulnerability Response Checklist

Malware and Security Lab Collections
#

CYBER 366: Malware Analytics & Reverse Engineering Lab Collection
#

This is the strongest malware-analysis lab collection in the portfolio.

It covers static analysis, dynamic analysis, packed executables, UPX, FLOSS, PE inspection, ProcMon, RegShot, IDA Pro, Ghidra, Binary Ninja, anti-debugging behavior, and keylogging indicators.

Malware Analysis Reverse Engineering

CYBER 262: Security Foundations Lab Collection
#

A hands-on security foundations collection covering Linux log analysis, Python parsing, endpoint protection, Wazuh HIDS, Snort NIDS, Splunk, two-factor authentication, and buffer overflow concepts.

This page shows the base layer behind later malware, forensics, and incident response work.

Security Foundations Hands-On Labs

IST 451: Security Labs Collection
#

A broader security lab collection covering service identification, Apache hardening, OpenVAS, SQL injection concepts, malware analysis, IDS concepts, wireless security, and privilege escalation concepts.

This is a supporting lab collection, not the first page I would send someone to, but it adds useful breadth.

Security Labs Vulnerability Analysis

What This Section Shows
#

Area
Evidence
Why It Matters
ServiceNow SecOps
SecOps lab hub and VR triage checklist.
Primary Career Fit
Vulnerability Response
Workflow thinking around vulnerable item review, assignment, remediation, exception handling, validation, and closure.
VR Workflow
Malware Analysis
CYBER 366 lab work with static analysis, dynamic analysis, unpacking, reverse-engineering tools, and behavior interpretation.
Technical Depth
Detection Foundations
Wazuh, Snort, Splunk, endpoint protection, logs, IDS concepts, and security monitoring foundations.
SOC-Relevant
Security Lab Breadth
Web security, vulnerability scanning, IDS concepts, wireless security, malware investigation, and privilege escalation concepts from IST 451.
Supporting Evidence

Tools Referenced in These Labs
#

This is not a mastery claim for every tool. It is a map of tools I used or studied in the lab work summarized here.

Tool / Concept
Used For
Evidence
ServiceNow SecOps / VR
Vulnerable item triage, ownership routing, remediation workflow, validation, exception handling, and closure thinking.
SecOps Hub
PEiD, UPX, FLOSS
Executable metadata review, packed executable identification, unpacking, decoded strings, and stack-string review.
CYBER 366
ProcMon, RegShot, Process Explorer
Dynamic analysis, process behavior, registry activity, file-system writes, and clean-state comparison.
CYBER 366
IDA Pro, Ghidra, Binary Ninja
Disassembly, decompilation, function review, string references, imported API interpretation, and control-flow reasoning.
CYBER 366
Wazuh, Snort, Splunk
Host-based detection, network intrusion detection, log review, alerting concepts, and SIEM-style investigation foundations.
CYBER 262
OpenVAS, Apache, SQL Injection Concepts
Service identification, web server hardening, vulnerability scanning, SQL injection concepts, and defensive security lab work.
IST 451

Lab-Heavy Work Outside This Section
#

Some of the strongest hands-on work lives under Projects instead of Research & Labs because those pages are bigger than a simple lab note.

CYBER 440 Capstone
#

The best incident response and forensic investigation story in the portfolio.

Flagship

IST 454 Computer & Cyber Forensics
#

Forensic imaging, hash verification, registry analysis, data carving, and deleted file recovery.

Forensics

IST 456 Security & Risk Management
#

Enigma Glass SIEM-style labs covering ransomware, compromised credentials, and data exfiltration.

Risk + SOC

SRA 221 Information Security Foundations
#

Earlier security-tool exposure: OWASP ZAP, Wireshark, SPARTA, OpenVPN, pfSense, Active Directory, forensics, and Splunk.

Foundational


How I Treat Lab Writeups
#

Keep the Method
#

I summarize the workflow, tools, findings, and lessons learned.

Method

Remove the Sensitive Parts
#

I do not publish raw submissions, malware samples, private screenshots, credentials, exact lab artifacts, or full solution steps.

Redacted

Connect It to Roles
#

The goal is not to show that I completed a class. The goal is to show what the work proves about how I investigate, document, and think through security problems.

Evidence


Quick Actions
#