
210.1K
CYCyber security projects in 2026 👀
1️⃣ Build a Mini SOC Lab (Blue Team)
Spin up a home lab with Windows + Linux VMs. Forward logs into a SIEM (Wazuh/Splunk). Create detections for brute force, PowerShell abuse, and privilege escalation. Document your detection logic.
2️⃣ Threat Hunt With MITRE Mapping (Threat Hunting)
Use log data and hunt for techniques from the MITRE ATT&CK framework
3️⃣ Phishing Campaign Simulation (Security Awareness / Red Team)
Use a phishing simulation platform in a controlled lab. Measure click rates, credential submissions, and build a remediation plan.
4️⃣ Web App Pentest on a Vulnerable App (Offensive Security)
Deploy OWASP Juice Shop. Find auth bypass, IDOR, XSS, SQLi. Write a real pentest-style report with severity ratings and remediation steps.
5️⃣ Malware Traffic Analysis (DFIR)
Analyze a PCAP in Wireshark. Identify C2 traffic, DNS tunneling, beaconing intervals. Write a timeline of compromise.
6️⃣ Active Directory Attack & Defense (Identity Security)
Set up an AD lab. Execute Kerberoasting and Pass-the-Hash attacks.
7️⃣ Cloud Misconfiguration Audit (Cloud Security)
Deploy a misconfigured AWS environment. Identify exposed S3 buckets, IAM privilege escalation paths, and overly permissive security groups. Fix them and document impact.
8️⃣ Incident Response Playbook (IR Engineering)
Create a full ransomware response playbook: detection, containment, eradication, recovery, lessons learned. Map actions to NIST phases.
9️⃣ Build a Password Cracking Rig (Offensive + Defensive Insight)
Use Hashcat in a lab. Compare password complexity vs length. Demonstrate why reuse is catastrophic. Turn findings into an awareness presentation.
🔟 Detection Engineering Project (Advanced Blue Team)
Write custom Sigma rules. Convert them to your SIEM query language. Test against simulated attacker behavior and tune for false positives.
#cybersecurity #cybersecuritytraining
@cybersecdyl










