SOC and Monitoring Labs
- I deployed Snort IDS and configured custom detection rules for brute force, SQL injection, and session hijacking attempts.
- I analyzed alerts generated by Snort and validated true positives using packet captures.
- I integrated security logs into the ELK Stack for centralized monitoring and event correlation.
Incident Detection and Web Security
- I used Burp Suite to inspect HTTP requests and identify injection points.
- I tested web applications against SQL injection attacks to validate ModSecurity effectiveness.
- I investigated session hijacking attempts using forged cookies and network traffic analysis.
Threat Simulation and Exploitation Labs
- I performed reconnaissance using Nmap to identify open ports and vulnerable services.
- I exploited known vulnerabilities on Metasploitable using Metasploit to understand attacker behavior.
- I documented attack paths and mapped them to defensive controls.
System and Network Security
- I hardened Linux systems by fixing misconfigurations and improving service permissions.
- I analyzed network traffic with Wireshark to identify suspicious patterns and anomalies.