Topic: Cybersecurity
In cybersecurity, a portfolio of hands-on projects speaks louder than any certification.
These 40 projects are designed to give you practical experience with the tools and challenges you'll face in 2026. From network scanning to cloud security, each project builds a tangible artifact you can showcase to employers.
Start with beginner projects to build fundamentals, then progress to advanced ones. Document each project thoroughly, include objectives, methodology, findings, and lessons learned. Publish your work on platforms like GitHub or a personal blog.
Beginner Projects (1-2 hours each)
Kickstart your cybersecurity journey with these foundational projects.
Network Scanning with Nmap
beginner · 2-3 hours
Use Nmap to scan a local network, identify live hosts, open ports, and services. Document your findings and potential risks.
Skills: Network scanning, Nmap, Risk assessment
Why it stands out: high
Packet Analysis with Wireshark
beginner · 2-3 hours
Capture and analyze network traffic to identify protocols, detect anomalies, and understand data flows.
Skills: Packet analysis, Wireshark, Protocol analysis
Why it stands out: high
Web Vulnerability Scan with OWASP ZAP
beginner · 2-4 hours
Run an automated scan on a deliberately vulnerable web app (e.g., DVWA) and report findings with remediation steps.
Skills: Web security, OWASP ZAP, Vulnerability reporting
Why it stands out: high
Password Cracking with John the Ripper
beginner · 1-2 hours
Crack password hashes using John the Ripper, analyze password strength, and create a report on password policies.
Skills: Password cracking, John the Ripper, Security policies
Why it stands out: medium
Basic SIEM Setup with Splunk
beginner · 2-3 hours
Install Splunk Free, ingest sample logs, and create a simple dashboard to monitor failed login attempts.
Skills: SIEM, Splunk, Log analysis
Why it stands out: high
CTF Writeup: TryHackMe Beginner Room
beginner · 2-4 hours
Complete a beginner-friendly CTF room on TryHackMe and write a detailed walkthrough of your approach and solutions.
Skills: CTF, Problem-solving, Technical writing
Why it stands out: high
Firewall Configuration with UFW
beginner · 1-2 hours
Set up and configure UFW on a Linux VM, create rules to allow/deny traffic, and test effectiveness.
Skills: Firewall, Linux, Network security
Why it stands out: medium
Phishing Email Analysis
beginner · 1-2 hours
Analyze a sample phishing email, identify red flags, and create an awareness guide for non-technical users.
Skills: Phishing analysis, Email security, Security awareness
Why it stands out: medium
Introduction to Cryptography: Caesar Cipher
beginner · 1-2 hours
Implement a Caesar cipher encryption/decryption tool in Python and document its weaknesses.
Skills: Cryptography, Python, Encryption
Why it stands out: medium
Security News Summary
beginner · 1-2 hours
Research a recent cybersecurity incident and write a summary of what happened, impact, and lessons learned.
Skills: Research, Incident analysis, Technical writing
Why it stands out: medium
Intermediate Projects (3-6 hours each)
Deepen your skills with hands-on challenges that simulate real-world scenarios.
Vulnerability Assessment with Nessus
intermediate · 4-6 hours
Perform a vulnerability scan on a target VM using Nessus Essentials, analyze results, and prioritize remediation.
Skills: Vulnerability assessment, Nessus, Risk prioritization
Why it stands out: high
Web App Penetration Testing with Burp Suite
intermediate · 5-8 hours
Use Burp Suite to test a web application for OWASP Top 10 vulnerabilities, exploit them, and document findings.
Skills: Web pentesting, Burp Suite, OWASP Top 10
Why it stands out: excellent
Incident Response Simulation: Ransomware
intermediate · 4-6 hours
Simulate a ransomware attack on a lab environment, follow incident response steps, and create an after-action report.
Skills: Incident response, Forensics, Reporting
Why it stands out: excellent
SIEM Dashboard for Threat Detection
intermediate · 5-7 hours
Build a Splunk dashboard that correlates logs from multiple sources to detect common attack patterns.
Skills: SIEM, Splunk, Threat detection
Why it stands out: high
Exploit Development with Metasploit
intermediate · 4-6 hours
Use Metasploit to exploit a known vulnerability in a lab machine, gain shell access, and document the process.
Skills: Exploitation, Metasploit, Post-exploitation
Why it stands out: high
Cloud Security: S3 Bucket Misconfiguration
intermediate · 3-5 hours
Set up an AWS S3 bucket with common misconfigurations, then audit and remediate them using AWS CLI and security tools.
Skills: Cloud security, AWS, Misconfiguration remediation
Why it stands out: high
CTF Writeup: HackTheBox Medium Machine
intermediate · 6-10 hours
Complete a medium-difficulty HackTheBox machine and write a detailed walkthrough including enumeration, exploitation, and privilege escalation.
Skills: Penetration testing, Enumeration, Privilege escalation
Why it stands out: excellent
Compliance Audit: PCI DSS Checklist
intermediate · 5-7 hours
Perform a mock PCI DSS compliance audit on a small network, identify gaps, and create a remediation plan.
Skills: Compliance, PCI DSS, Auditing
Why it stands out: high
Cryptography: Implement AES Encryption
intermediate · 3-4 hours
Write a Python script to encrypt and decrypt files using AES, and explain the importance of key management.
Skills: Cryptography, AES, Python
Why it stands out: medium
Network Traffic Analysis for Malware Detection
intermediate · 4-6 hours
Analyze a PCAP file containing malware traffic, identify indicators of compromise, and write a detection report.
Skills: Network forensics, Wireshark, Malware analysis
Why it stands out: high
Security Automation with Python
intermediate · 4-6 hours
Create a Python script that automates a security task, such as log parsing or vulnerability scanning.
Skills: Automation, Python, Scripting
Why it stands out: high
Wireless Security: WPA2 Cracking
intermediate · 3-5 hours
Capture a WPA2 handshake and attempt to crack it using aircrack-ng, then discuss mitigation strategies.
Skills: Wireless security, Aircrack-ng, Password cracking
Why it stands out: medium
Advanced Projects (8-15 hours each)
Tackle complex, multi-step projects that mirror professional cybersecurity tasks.
Full Penetration Test Report
advanced · 15-20 hours
Conduct a comprehensive penetration test on a lab environment, from reconnaissance to reporting, following a professional methodology.
Skills: Penetration testing, Reporting, Methodology
Why it stands out: excellent
Build a Home SIEM Lab
advanced · 10-15 hours
Set up a full SIEM lab with Splunk, configure log ingestion from multiple sources, and create detection rules for common attacks.
Skills: SIEM, Splunk, Log management
Why it stands out: excellent
Incident Response Plan Development
advanced · 8-12 hours
Create a complete incident response plan for a fictional organization, including playbooks for various attack types.
Skills: Incident response, Planning, Documentation
Why it stands out: high
Cloud Security Architecture Review
advanced · 12-15 hours
Design a secure cloud architecture on AWS, implement security controls, and perform a threat model.
Skills: Cloud security, AWS, Threat modeling
Why it stands out: excellent
Malware Analysis: Static and Dynamic
advanced · 10-15 hours
Analyze a malware sample using static and dynamic techniques, document behavior, and create IOCs.
Skills: Malware analysis, Reverse engineering, IOC creation
Why it stands out: excellent
Develop a Custom Exploit
advanced · 15-20 hours
Identify a vulnerability in a deliberately vulnerable application, develop an exploit, and write a proof-of-concept.
Skills: Exploit development, Vulnerability research, Programming
Why it stands out: excellent
Compliance Framework Implementation
advanced · 10-12 hours
Implement a compliance framework (e.g., NIST CSF) for a small business, including gap analysis and policy creation.
Skills: Compliance, NIST CSF, Policy development
Why it stands out: high
Advanced Cryptography: PKI Implementation
advanced · 8-10 hours
Set up a Public Key Infrastructure (PKI) with OpenSSL, issue certificates, and configure a secure web server.
Skills: Cryptography, PKI, OpenSSL
Why it stands out: high
Red Team vs Blue Team Exercise
advanced · 15-20 hours
Simulate a red team attack and blue team defense in a lab, documenting both perspectives and lessons learned.
Skills: Red teaming, Blue teaming, Collaboration
Why it stands out: excellent
Threat Hunting with ELK Stack
advanced · 12-15 hours
Set up ELK stack, ingest security logs, and perform threat hunting exercises to uncover simulated attacks.
Skills: Threat hunting, ELK, Log analysis
Why it stands out: excellent
Secure Code Review
advanced · 8-10 hours
Perform a secure code review on an open-source application, identify vulnerabilities, and suggest fixes.
Skills: Code review, Secure coding, Vulnerability identification
Why it stands out: high
Build a Honeypot Network
advanced · 10-12 hours
Deploy a honeypot (e.g., Cowrie) to attract attackers, capture their activity, and analyze the data.
Skills: Honeypots, Network security, Data analysis
Why it stands out: high
Expert Projects (20+ hours each)
Capstone-level projects that demonstrate mastery and can be flagship portfolio pieces.
End-to-End Security Assessment
advanced · 30-40 hours
Conduct a full security assessment for a mock organization, covering network, application, cloud, and compliance, and present a comprehensive report.
Skills: Security assessment, Reporting, Project management
Why it stands out: excellent
Develop a Security Tool
advanced · 25-35 hours
Create a custom security tool (e.g., vulnerability scanner, log analyzer) and release it as open-source on GitHub.
Skills: Tool development, Programming, Open-source
Why it stands out: excellent
Build a Cyber Range
advanced · 40-50 hours
Design and implement a cyber range with multiple vulnerable machines and a scoring system for CTF-style challenges.
Skills: Cyber range, Virtualization, CTF design
Why it stands out: excellent
Research and Publish a Vulnerability
advanced · 30-50 hours
Discover a vulnerability in an open-source project, responsibly disclose it, and publish a detailed writeup.
Skills: Vulnerability research, Responsible disclosure, Technical writing
Why it stands out: excellent
Incident Response Capstone: Simulated Breach
advanced · 25-35 hours
Lead a full incident response simulation from detection to recovery, including forensic analysis and post-incident review.
Skills: Incident response, Forensics, Leadership
Why it stands out: excellent
Cloud Security Posture Management (CSPM) Implementation
advanced · 20-30 hours
Implement a CSPM solution for a multi-cloud environment, automate compliance checks, and remediate issues.
Skills: Cloud security, CSPM, Automation
Why it stands out: excellent
Build a Portfolio That Gets You Hired
- Create a personal website or GitHub repository to showcase your projects with clear descriptions and links to code.
- Include a mix of project types: network, application, cloud, incident response, and compliance to show versatility.
- For each project, highlight the problem, your approach, tools used, and the outcome or impact.
- Add a 'Lessons Learned' section to demonstrate self-awareness and growth mindset.
- Engage with the community: Share your projects on LinkedIn, Twitter, and security forums to get feedback and visibility.
Tips that make the difference
- Document everything: Keep a detailed journal of your process, challenges, and solutions for each project.
- Version control: Use Git for all your scripts and configurations to demonstrate collaboration and history.
- Write for your audience: Tailor your writeups to both technical and non-technical readers to show communication skills.
- Automate where possible: Show efficiency by automating repetitive tasks with scripts.
- Stay ethical: Always obtain proper authorization before testing any system, and follow responsible disclosure.
- Continuously learn: After each project, reflect on what you could improve and what new skills you need.
Ready to Build Your Cybersecurity Portfolio?
Start your first project today on Edirae and join a community of learners showcasing their skills to employers.
Start learning free