Live Project
The Tech Academy’s Live Project portion of the cybersecurity bootcamp. Offensive and defensive security work (OWASP Juice Shop, Burp Suite, Wireshark) with incident report writeups.
Overview
This repository tracks work on The Tech Academy’s Live Project: applying offensive and defensive security techniques in a simulated professional environment. Work is organized into stories (offensive, defensive, and setup), each with its own incident report documenting what was investigated, how, what was found, and what the fix or takeaway is.
This repository is updated as stories are completed, not assembled at the end.
Core Technologies
- Environment: Kali Linux, KVM/virt-manager
- Offensive: OWASP Juice Shop, Burp Suite, FoxyProxy
- Defensive: Wireshark, VirusTotal
- Research: ExploitDB, GTFOBins, Rapid7, CVE Details, CIS Security
Structure
setup/- Offensive Setup stories (Kali VM, Juice Shop, Burp Suite)offensive/- web application security stories against OWASP Juice Shopdefensive/- network forensics and malware investigation stories
Setup
- Install Kali Linux VMKali build on KVM/virt-manager and a clean-baseline snapshot
- Create Juice Shop AppOWASP Juice Shop deployed and run via Docker
- Intro - Burp Suiteintercepting proxy configured, traffic capture and request modification
Offensive
- Admin Log InSQL injection auth bypass
- User Log InTargeted SQLi after user enumeration
- Reset Admin PasswordBurp Intruder brute force
- Admin AccessMass assignment on user registration
- Admin PageClient-side route discovery + IDOR on baskets + admin panel abuse
- CAPTCHA ExploitReusable CAPTCHA + no rate limiting, Burp Intruder flood
- Access Secured DocumentsExposed /ftp/ directory, confidential file access
- Download Secured DocumentsPoison null byte extension-filter bypass
- HTTP RequestsRequest tampering: basket IDOR + zero-star feedback via improper input validation
Defensive
- Wireshark IntroOkay-Boomer pcap analysis: host/OS fingerprinting, PE file carving, Trickbot confirmed via VirusTotal
- Malware TrafficExploit kit chain reconstruction: Flash exploit + hidden iframe, executable disguised as text/html, ransomware confirmed via VirusTotal
- Malware AnalysisMulti-family infection: Word doc embedded in HTML, Hancitor check-in, Ficker Stealer download, Cobalt Strike beaconing
- PowerShell Script AnalysisStatic analysis of a PowerShell keylogger: user32.dll API imports, hardcoded SMTP exfiltration, log deleted after send
- Linux Server LogsBash history reconstruction:
.phtmlwebshell slips a.php-only upload filter, then a SUID-Python privilege escalation attempt - Erik’s Coffee Packet AnalysisPCAP triage of a two-host network: Kerberos host/user identification, Qakbot delivered via a zip-wrapped VBScript downloader, confirmed via VirusTotal
- Find the CulpritPost-infection C2 analysis: Zeus config hidden inside a valid JPEG, fixed-interval check-ins over HTTP, encrypted upload following bank-related host activity
- Ransomware AttackLive infection triage on a provided Windows 10 image: fake Firefox binary in AppData,
.funfile encryption, Jigsaw identified via PE metadata and hash lookup, files recovered and malware removed - Malware Deep InvestigationPCAP + IDS alert triage on an AD network: Kerberos host/user identification, Ursnif banking trojan confirmed by signature and C2 behavior, delivery traced from a webmail phishing email through an ad-redirect chain to encrypted
/api1/C2