Project library
30 projects, ranked
Why finishing one of these matters
Something to say
Interviews ask what you have done. A finished project answers with specifics instead of coursework.
Numbers on your résumé
Records searched, findings confirmed, tests added. Figures a reader can check against your report.
Tools on the page
Each project leaves you with four or five named tools and a framework you have actually used.
Proof you finish
A public repository with a readable history shows follow-through, which is rarer than skill at this stage.
Pick one and finish it
Everything runs on public data, published reports or a lab on your own machine. Easy projects prove you can finish and publish something; hard ones are the projects an interviewer spends the most time asking about.
- EasyGood first projectA weekend of work. Start here if you have never published a project.
- MediumSolid portfolio pieceTwo or three sessions. Enough depth to carry an interview answer.
- HardStrongest résumé pieceThe ones worth the most on a résumé: real scope, real decisions, and plenty to talk about.
30 projects. Ranked for a first portfolio, easiest wins first.
- EasyRanked 1. Easy. Good first project. Alert Queue TriageWork a small queue of practice alerts and decide which ones are real.SOC Analysis4-6 h
- MediumRanked 2. Medium. Solid portfolio piece. Failed-Login HuntSearch a public authentication dataset for password spraying and prove or disprove it.Threat Hunting / Detection5-8 h
- EasyRanked 3. Easy. Good first project. Account Compromise PlaybookRun a fictional compromised-account incident and write the playbook it produces.Incident Response4-6 h
- EasyRanked 4. Easy. Good first project. Fake Internship Campaign BriefResearch a documented job-scam campaign from public sources and brief a non-technical team.Threat Intelligence4-6 h
- HardRanked 5. Hard. Strongest résumé piece. Incident Timeline ReconstructionRebuild what happened on a practice disk image, artifact by artifact.Digital Forensics6-10 h
- HardRanked 6. Hard. Strongest résumé piece. Vulnerable App Test ReportTest a deliberately vulnerable app in your own lab and report three findings properly.Offensive Security6-10 h
- MediumRanked 7. Medium. Solid portfolio piece. Broken Access Control FixBuild a two-user app, break its record access, fix it and keep it fixed.Application / Product Security5-8 h
- EasyRanked 8. Easy. Good first project. Cloud Template HardeningScan an infrastructure template, fix what it exposes and automate the check.Cloud Security4-6 h
- MediumRanked 9. Medium. Solid portfolio piece. Role-Based Access LabDesign member, officer and admin roles, then test joining, changing role and leaving.Identity and Access Management5-8 h
- EasyRanked 10. Easy. Good first project. Student Org Risk RegisterAssess a fictional organization's platform and rank the risks with reasoning.Governance, Risk, and Compliance4-6 h
- HardRanked 11. Hard. Strongest résumé piece. Segmented Lab NetworkBuild two network zones, write default-deny rules and test what really gets blocked.Network Security6-10 h
- EasyRanked 12. Easy. Good first project. Malware Report ComparisonCompare two published analyses of related samples and publish a cited table.Malware Analysis3-5 h
- EasyRanked 13. Easy. Good first project. Phishing Report TriageWork a batch of reported emails and decide which are phishing, safe or unclear.SOC Analysis3-5 h
- MediumRanked 14. Medium. Solid portfolio piece. Detection Noise ReviewFind the rules that cry wolf, tune one, and measure the difference.SOC Analysis4-6 h
- MediumRanked 15. Medium. Solid portfolio piece. Beaconing Traffic HuntLook for machines phoning home on a schedule inside public network logs.Threat Hunting / Detection5-8 h
- HardRanked 16. Hard. Strongest résumé piece. Sigma Rule PackWrite five detection rules and test each against attack and normal data.Threat Hunting / Detection6-10 h
- MediumRanked 17. Medium. Solid portfolio piece. Ransomware TabletopRun a discussion exercise with injects and capture the decisions people struggle with.Incident Response4-6 h
- EasyRanked 18. Easy. Good first project. Browser Artifact ReviewReconstruct a browsing session from history, downloads and cache in a practice image.Digital Forensics3-5 h
- MediumRanked 19. Medium. Solid portfolio piece. USB Device Usage ReviewWork out which removable devices were used, when, and what that does and does not prove.Digital Forensics4-6 h
- MediumRanked 20. Medium. Solid portfolio piece. Threat Actor ProfileBuild a sourced profile of one publicly documented group and what it means locally.Threat Intelligence5-8 h
- MediumRanked 21. Medium. Solid portfolio piece. Authorized Web Recon MethodologyWrite and follow a repeatable recon process against your own lab application.Offensive Security4-6 h
- HardRanked 22. Hard. Strongest résumé piece. API Authorization LabTest an API you built for object and function level authorization flaws.Offensive Security6-10 h
- MediumRanked 23. Medium. Solid portfolio piece. Secure Code Review PackReview a small open-source project and write findings a maintainer could act on.Application / Product Security5-8 h
- HardRanked 24. Hard. Strongest résumé piece. CI Security GateAdd dependency, secret and static checks to a pipeline without blocking the team.Application / Product Security4-6 h
- MediumRanked 25. Medium. Solid portfolio piece. Cloud Logging BaselineDefine what a small cloud account must log, and prove the template delivers it.Cloud Security4-6 h
- HardRanked 26. Hard. Strongest résumé piece. Least-Privilege Policy LabTake a wildcard cloud policy and cut it down to only what the app needs.Cloud Security5-8 h
- HardRanked 27. Hard. Strongest résumé piece. Joiner, Mover, Leaver AutomationScript the access changes for joining, changing role and leaving, then prove they ran.Identity and Access Management6-10 h
- MediumRanked 28. Medium. Solid portfolio piece. Control Evidence PackPick five controls and collect the evidence that would satisfy an auditor.Governance, Risk, and Compliance4-6 h
- EasyRanked 29. Easy. Good first project. Firewall Rule ReviewAudit a messy rule set, find what is redundant or too broad, and rewrite it.Network Security3-5 h
- EasyRanked 30. Easy. Good first project. Sandbox Report SummaryTurn a long public sandbox report into a one-page summary defenders can use.Malware Analysis2-4 h
What happens after you finish one
Give it a name of its own, publish it on GitHub with your notes and evidence, and put the numbers you counted into one résumé line. Every project page walks through all three.