Topic: Cybersecurity
In 2026, cybersecurity employers won't just read your resume, they'll inspect your GitHub, your lab writeups, and your CTF badges.
These 30 hands-on projects span network defense, application security, cloud hardening, incident response, compliance, and cryptography. Each produces a tangible artifact, a tool, a report, a lab environment, that proves you can operate real security tools like Wireshark, Nmap, Burp Suite, Metasploit, Splunk, and OWASP ZAP under realistic constraints.
Start with the beginner tier to build foundational fluency, then progress to intermediate and advanced projects that mirror real SOC, red team, and cloud security workflows. Document every step, publish sanitized writeups, and link your repositories in your portfolio.
Beginner Projects (1–4 hours each)
Build core tool familiarity and produce your first portfolio artifacts with guided, low-risk labs.
Home Network Vulnerability Scan with Nmap
beginner · 2-3 hours
Scan your home network, identify open ports and services, and produce a prioritized remediation report with screenshots and Nmap scripts used.
Skills: Nmap scripting, Network reconnaissance, Report writing
Why it stands out: high
Wireshark Traffic Analysis of a Simulated Attack
beginner · 3-4 hours
Capture and analyze a PCAP from a public malware-traffic-analysis exercise, identifying C2 beacons, DNS tunneling, and suspicious TLS certificates.
Skills: Packet analysis, Protocol dissection, Threat hunting
Why it stands out: high
OWASP ZAP Baseline Scan on a Vulnerable Web App
beginner · 2-3 hours
Run an automated baseline scan against OWASP Juice Shop, triage alerts, and write a concise executive summary with false-positive notes.
Skills: OWASP ZAP, Web vulnerability scanning, Triage
Why it stands out: high
Password Cracking Lab with Hashcat
beginner · 2-4 hours
Crack a set of provided NTLM and SHA-256 hashes using wordlists and rules, then document password policy weaknesses and mitigation strategies.
Skills: Hashcat, Password policy analysis, Cryptography basics
Why it stands out: medium
Phishing Email Triage with Splunk
beginner · 3-4 hours
Ingest a sample phishing email dataset into Splunk, build a dashboard for sender reputation and URL extraction, and write an incident summary.
Skills: Splunk SPL, Email header analysis, Incident documentation
Why it stands out: high
Firewall Rule Audit with pfSense
beginner · 3-4 hours
Configure a pfSense VM, create a least-privilege rule set for a small network, and document the audit process with before/after rule tables.
Skills: Firewall configuration, Network segmentation, Change documentation
Why it stands out: medium
CTF Writeup: TryHackMe Pre-Security Path
beginner · 2-3 hours
Complete a beginner TryHackMe room, capture flags, and publish a step-by-step writeup with screenshots and lessons learned.
Skills: Linux CLI, Enumeration, Technical writing
Why it stands out: high
SSL/TLS Configuration Checker with Python
beginner · 3-4 hours
Write a Python script that connects to a host, retrieves the certificate, checks expiry and cipher suite, and outputs a JSON report.
Skills: Python sockets, TLS fundamentals, Automation
Why it stands out: medium
Security Awareness Poster and Quiz
beginner · 2-3 hours
Design a one-page phishing awareness poster and a 10-question quiz, then deploy it via Google Forms and analyze results.
Skills: Security awareness, Content design, Data analysis
Why it stands out: medium
Vulnerability Report for a Public CVE
beginner · 3-4 hours
Pick a recent CVE, reproduce it in a lab, and write a vulnerability report with CVSS score, impact, and remediation steps.
Skills: CVE analysis, CVSS scoring, Vulnerability reporting
Why it stands out: high
Intermediate Projects (5–12 hours each)
Combine multiple tools and frameworks to simulate real security operations, red team, and cloud security tasks.
SIEM Home Lab with Splunk and Sysmon
intermediate · 8-12 hours
Build a Splunk instance ingesting Sysmon logs from a Windows VM, create detection rules for common attacks, and document the architecture.
Skills: Splunk administration, Sysmon, Detection engineering
Why it stands out: excellent
Metasploit Exploitation Walkthrough on Metasploitable
intermediate · 6-8 hours
Exploit three vulnerabilities in Metasploitable 2 using Metasploit, capture screenshots, and write a red team report with mitigation advice.
Skills: Metasploit, Exploitation, Red team reporting
Why it stands out: high
Burp Suite Web App Penetration Test
intermediate · 10-12 hours
Perform a manual web app pentest against DVWA or Juice Shop using Burp Suite, covering SQLi, XSS, and CSRF, and deliver a full report.
Skills: Burp Suite, Web app pentesting, Report writing
Why it stands out: excellent
Incident Response Playbook for Ransomware
intermediate · 6-8 hours
Create a ransomware IR playbook aligned with NIST SP 800-61, including detection, containment, eradication, and recovery steps.
Skills: Incident response, NIST framework, Playbook development
Why it stands out: high
Cloud Security Posture Review on AWS Free Tier
intermediate · 8-10 hours
Deploy a small AWS environment, run Prowler or ScoutSuite, remediate findings, and document the before/after security posture.
Skills: AWS security, Cloud scanning, Remediation
Why it stands out: excellent
Network Traffic Anomaly Detection with Zeek
intermediate · 8-12 hours
Deploy Zeek on a home network, generate traffic, and write scripts to detect port scans and unusual DNS queries, then visualize with Kibana.
Skills: Zeek, Network monitoring, Log analysis
Why it stands out: high
Cryptography Challenge: Implement AES and RSA
intermediate · 8-10 hours
Implement AES-256-CBC and RSA-OAEP from scratch in Python, then write tests and a comparison of performance and security trade-offs.
Skills: Cryptography, Python, Secure coding
Why it stands out: high
Compliance Gap Assessment for ISO 27001
intermediate · 6-8 hours
Perform a mock ISO 27001 gap assessment for a fictional company, produce a findings register, and draft a remediation roadmap.
Skills: ISO 27001, Compliance auditing, Risk management
Why it stands out: medium
CTF Writeup: Hack The Box Easy Machine
intermediate · 5-8 hours
Root an easy HTB machine, document enumeration, exploitation, and privilege escalation, and publish a polished writeup.
Skills: Enumeration, Privilege escalation, Writeup skills
Why it stands out: excellent
API Security Testing with Postman and OWASP ZAP
intermediate · 8-10 hours
Test a REST API for broken authentication, rate limiting, and injection flaws using Postman collections and ZAP, then report findings.
Skills: API security, Postman, OWASP ZAP
Why it stands out: high
Digital Forensics: Memory Analysis with Volatility
intermediate · 6-8 hours
Analyze a provided memory dump using Volatility 3, extract processes, network connections, and malware artifacts, and write a forensic report.
Skills: Volatility, Memory forensics, Evidence handling
Why it stands out: high
Zero Trust Architecture Design Document
intermediate · 6-8 hours
Design a zero trust architecture for a hybrid workforce, including identity, device, network, and application pillars, with a deployment roadmap.
Skills: Zero trust, Architecture design, Technical writing
Why it stands out: medium
Advanced Projects (15–30 hours each)
Tackle complex, multi-component projects that demonstrate deep expertise and end-to-end security engineering.
Build a Mini SOC with Wazuh and TheHive
advanced · 20-30 hours
Deploy Wazuh for endpoint detection, TheHive for case management, and integrate them to automate alert creation and response workflows.
Skills: SOC operations, Wazuh, TheHive, Automation
Why it stands out: excellent
Red Team vs Blue Team Home Lab
advanced · 25-30 hours
Set up an isolated lab with Kali and Windows targets, simulate an APT attack, and document detection and response from the blue team perspective.
Skills: Red teaming, Blue teaming, Lab design
Why it stands out: excellent
Cloud Incident Response Simulation on AWS
advanced · 15-20 hours
Simulate a compromised AWS account, investigate CloudTrail and GuardDuty findings, and produce an IR report with containment and recovery steps.
Skills: Cloud IR, AWS CloudTrail, GuardDuty
Why it stands out: excellent
Custom SIEM Detection Rules for MITRE ATT&CK
advanced · 20-25 hours
Map 10 MITRE ATT&CK techniques to Splunk detection rules, test them with Atomic Red Team, and document coverage and false positives.
Skills: Detection engineering, MITRE ATT&CK, Atomic Red Team
Why it stands out: excellent
Full Web App Pentest with Custom Exploit Development
advanced · 25-30 hours
Conduct a full pentest against a custom vulnerable app, develop a working exploit for a novel vulnerability, and present a professional report.
Skills: Exploit development, Pentesting, Reporting
Why it stands out: excellent
Secure Software Development Lifecycle (SSDLC) Implementation
advanced · 15-20 hours
Create an SSDLC policy, integrate SAST/DAST into a CI/CD pipeline, and demonstrate a vulnerability being caught and fixed.
Skills: SSDLC, CI/CD security, SAST/DAST
Why it stands out: high
Threat Modeling for a Microservices Application
advanced · 15-18 hours
Perform STRIDE threat modeling on a microservices architecture, produce a threat model, and propose mitigations with a risk matrix.
Skills: Threat modeling, STRIDE, Risk assessment
Why it stands out: high
Cryptographic Protocol Analysis with ProVerif
advanced · 20-25 hours
Model and analyze a custom authentication protocol in ProVerif, identify vulnerabilities, and propose a fixed version with formal verification.
Skills: Formal methods, Cryptography, Protocol analysis
Why it stands out: excellent
Your Portfolio Is Your Proof of Work
- Create a dedicated portfolio site with project summaries, links to GitHub, and downloadable reports.
- For each project, state the problem, your approach, tools used, and measurable outcomes.
- Include a 'Skills Matrix' mapping projects to job requirements (e.g., SIEM, pentesting, cloud).
- Showcase at least one end-to-end project that covers detection, response, and remediation.
- Regularly update your portfolio with new CTF writeups and lab experiments to show continuous learning.
Tips that make the difference
- Always sanitize and anonymize data before publishing writeups; use lab environments or public datasets.
- Record short video walkthroughs of your projects to demonstrate tool proficiency and communication skills.
- Link each project to a specific framework (NIST, MITRE ATT&CK, OWASP) to show industry alignment.
- Include a 'lessons learned' section in every writeup to highlight critical thinking and growth.
- Version control everything, scripts, reports, and configs, on GitHub with clear READMEs.
- Contribute to open-source security tools or CTF platforms to build a public track record.
Ready to Build Your Cybersecurity Portfolio?
Start any of these projects on Edirae, track your progress, and share your work with a community of learners and mentors.
Start learning free