← All projects

Live Project

The Tech Academy’s Live Project portion of the cybersecurity bootcamp. Offensive and defensive security work (OWASP Juice Shop, Burp Suite, Wireshark) with incident report writeups.

Overview

This repository tracks work on The Tech Academy’s Live Project: applying offensive and defensive security techniques in a simulated professional environment. Work is organized into stories (offensive, defensive, and setup), each with its own incident report documenting what was investigated, how, what was found, and what the fix or takeaway is.

This repository is updated as stories are completed, not assembled at the end.

Core Technologies

  • Environment: Kali Linux, KVM/virt-manager
  • Offensive: OWASP Juice Shop, Burp Suite, FoxyProxy
  • Defensive: Wireshark, VirusTotal
  • Research: ExploitDB, GTFOBins, Rapid7, CVE Details, CIS Security

Structure

  • setup/ - Offensive Setup stories (Kali VM, Juice Shop, Burp Suite)
  • offensive/ - web application security stories against OWASP Juice Shop
  • defensive/ - network forensics and malware investigation stories

Setup

Offensive

Defensive

  • Wireshark IntroOkay-Boomer pcap analysis: host/OS fingerprinting, PE file carving, Trickbot confirmed via VirusTotal
  • Malware TrafficExploit kit chain reconstruction: Flash exploit + hidden iframe, executable disguised as text/html, ransomware confirmed via VirusTotal
  • Malware AnalysisMulti-family infection: Word doc embedded in HTML, Hancitor check-in, Ficker Stealer download, Cobalt Strike beaconing
  • PowerShell Script AnalysisStatic analysis of a PowerShell keylogger: user32.dll API imports, hardcoded SMTP exfiltration, log deleted after send
  • Linux Server LogsBash history reconstruction: .phtml webshell slips a .php-only upload filter, then a SUID-Python privilege escalation attempt
  • Erik’s Coffee Packet AnalysisPCAP triage of a two-host network: Kerberos host/user identification, Qakbot delivered via a zip-wrapped VBScript downloader, confirmed via VirusTotal
  • Find the CulpritPost-infection C2 analysis: Zeus config hidden inside a valid JPEG, fixed-interval check-ins over HTTP, encrypted upload following bank-related host activity
  • Ransomware AttackLive infection triage on a provided Windows 10 image: fake Firefox binary in AppData, .fun file encryption, Jigsaw identified via PE metadata and hash lookup, files recovered and malware removed
  • Malware Deep InvestigationPCAP + IDS alert triage on an AD network: Kerberos host/user identification, Ursnif banking trojan confirmed by signature and C2 behavior, delivery traced from a webmail phishing email through an ad-redirect chain to encrypted /api1/ C2

View on GitHub ↗

← All projects