Ticket #0001 Priority High Status Open Assigned Recruiter (you)

Trent Barber

Cybersecurity Student & Aspiring SOC Analyst

Rising senior studying Cybersecurity at the University of South Florida, working toward Security+ certification, with hands-on reverse engineering and malware analysis experience through USF's WhiteHatters Computer Security Club. Building a home lab in Microsoft Sentinel, Defender XDR, and KQL to bridge classroom fundamentals with real SOC tooling.

#0002 Reference System Capabilities Inventory

Capabilities

Skills and tools, organized the way a SOC would inventory them — not a decorative skill cloud.

Detection & SIEM

Microsoft Sentinel / Defender XDR

Home-lab build using Azure free tier; analytics rules, incident triage, KQL queries.

Query Language

KQL

Log Analytics and Sentinel query writing — auth failures, process creation, network events.

Reverse Engineering

Ghidra

Binary analysis for CTF challenges — extracting credentials and unlocking protected files.

Malware Analysis

Static / Dynamic Analysis

Lab work on DLL hijacking and credential theft techniques (GINA-based case study).

Hardening

DISA STIGs / VMware

Windows hardening portfolio project applying DoD security technical implementation guides.

Scripting

Python / PowerShell

Small automations for log parsing, IOC enrichment, and operational tooling.

#0003 Ongoing Project Case Files

Case Files

Each entry below is a real project — swap in your write-ups, screenshots, and repo links as you finish them.

CASE-01 — Windows Hardening Portfolio

In Progress

Applying DISA STIGs to a Windows VM built in VMware, documenting each hardening step and its security rationale as a reproducible playbook. [Add a short summary of what you hardened and what you measured once the project is further along.]

DISA STIG VMware Documentation

CASE-02 — WhiteHatters CTF: Reverse Engineering

Resolved

Competed in FinalPrepCTF with USF's WhiteHatters Computer Security Club. Used Ghidra to reverse-engineer a compiled binary, extract embedded credentials, and unlock the challenge file — placing well in the competition. [Add specifics: which techniques, tools, and what made the binary tricky.]

Ghidra Binary Analysis CTF

CASE-03 — Malware Analysis: DLL Hijacking

Resolved

Lab analysis of a sample exhibiting GINA DLL hijacking behavior for credential theft. Walked through static and dynamic analysis to identify the hijack point and theft mechanism. [Add tools used — e.g. PE viewer, sandbox, debugger — and key findings.]

Malware Analysis Windows Internals

CASE-04 — Sentinel / KQL Home Lab

Planned

Azure Sentinel + Defender XDR lab environment: ingesting Windows event logs, writing detection rules, and building an investigation workbook. [Fill in once the lab is live — this is the project most directly aimed at the Sentinel/KQL preferred qualifications.]

Sentinel KQL Detection Engineering
#0004 In Progress Certification & Education Timeline

Certification Path

Held

Rapid7 InsightAppSec Certified Specialist

Application security scanning specialist certification.

In Progress

CompTIA Security+

Following a structured 6-week study plan alongside coursework and work schedule.

Planned Next

BTL1 or eJPT

Hands-on practitioner-level certification, chosen based on which fits the target role better.

Expected

B.S. Cybersecurity — University of South Florida

Coursework spanning security operations, networks, HCI security, and applied labs.