Rising senior studying Cybersecurity at the University of South Florida, working toward Security+ certification, with hands-on reverse engineering and malware analysis experience through USF's WhiteHatters Computer Security Club. Building a home lab in Microsoft Sentinel, Defender XDR, and KQL to bridge classroom fundamentals with real SOC tooling.
Skills and tools, organized the way a SOC would inventory them — not a decorative skill cloud.
Home-lab build using Azure free tier; analytics rules, incident triage, KQL queries.
Log Analytics and Sentinel query writing — auth failures, process creation, network events.
Binary analysis for CTF challenges — extracting credentials and unlocking protected files.
Lab work on DLL hijacking and credential theft techniques (GINA-based case study).
Windows hardening portfolio project applying DoD security technical implementation guides.
Small automations for log parsing, IOC enrichment, and operational tooling.
Each entry below is a real project — swap in your write-ups, screenshots, and repo links as you finish them.
Applying DISA STIGs to a Windows VM built in VMware, documenting each hardening step and its security rationale as a reproducible playbook. [Add a short summary of what you hardened and what you measured once the project is further along.]
Competed in FinalPrepCTF with USF's WhiteHatters Computer Security Club. Used Ghidra to reverse-engineer a compiled binary, extract embedded credentials, and unlock the challenge file — placing well in the competition. [Add specifics: which techniques, tools, and what made the binary tricky.]
Lab analysis of a sample exhibiting GINA DLL hijacking behavior for credential theft. Walked through static and dynamic analysis to identify the hijack point and theft mechanism. [Add tools used — e.g. PE viewer, sandbox, debugger — and key findings.]
Azure Sentinel + Defender XDR lab environment: ingesting Windows event logs, writing detection rules, and building an investigation workbook. [Fill in once the lab is live — this is the project most directly aimed at the Sentinel/KQL preferred qualifications.]
Application security scanning specialist certification.
Following a structured 6-week study plan alongside coursework and work schedule.
Hands-on practitioner-level certification, chosen based on which fits the target role better.
Coursework spanning security operations, networks, HCI security, and applied labs.