The lab / 11 documented projects

Built to learn.
Tested to defend.

Detection pipelines, malware investigations, and adversary emulation. Each project includes the architecture, the evidence, and the lessons from getting it to work.

PROJECT INDEX / 01—11Case studies + source code
Wazuh alert detail for a C2 beaconing detection, rule 100103
AI-Augmented SOC07

PFA-SOC-IA

A local Gemma2 9B model triages real Wazuh detections and hands off to TheHive, Cortex, and MISP — 100% MITRE match vs. 40% for the SIEM baseline alone, with severity routing kept strictly off the LLM's own output.

WazuhShuffleGemma2 9BTheHiveMISP
SOC dashboard showing successful exploitation against the vulnerable gateway mode
Web App Security08

Web App Testing Playground

A dual-mode hardening gateway that runs the same OWASP Top 10 exploits against a vulnerable and a hardened path of one app — plus a self-discovered drive-by localhost RCE and a stateful SIEM correlation engine.

OWASP Top 10OWASP ZAPNode.jsDocker
Incident Response10

Incident Response Playbooks

Five NIST SP 800-61 / SANS-aligned runbooks — phishing, malware, account compromise, data breach, DDoS — each built as a decision tree, not a checklist, so any analyst on shift handles it the same way.

NIST SP 800-61SANSMarkdownDecision Trees
Beyond the screenshots

Let's talk details.

Happy to walk through the architecture, the failed attempts, or the design decisions.