Topic: Cybersecurity
In cybersecurity, a certificate opens doors, but a portfolio proves you can walk through them. Build projects that show you can defend, attack, and respond.
These 20 hands-on projects cover network security, application security, cloud security, incident response, compliance, and cryptography. Each project produces tangible artifacts, tools, reports, writeups, that demonstrate real-world skills to employers.
Start with beginner projects to build fundamentals, then progress to advanced ones. Document each project thoroughly on GitHub or a blog. Focus on quality over quantity; 5-7 polished projects are better than 20 incomplete ones.
Beginner Projects (1-2 hours each)
Build foundational skills with guided, low-risk projects using standard tools like Wireshark and Nmap.
Network Traffic Analysis with Wireshark
beginner · 2-3 hours
Capture and analyze network traffic to identify protocols, detect anomalies, and extract files from packet captures.
Skills: Wireshark, Network Protocol Analysis, Packet Inspection
Why it stands out: high
Network Reconnaissance with Nmap
beginner · 1-2 hours
Perform host discovery, port scanning, and service enumeration on a lab network, then document findings.
Skills: Nmap, Network Scanning, Enumeration
Why it stands out: high
OWASP ZAP Baseline Scan
beginner · 2-3 hours
Run an automated vulnerability scan on a vulnerable web app (e.g., DVWA) and interpret the results.
Skills: OWASP ZAP, Web App Security, Vulnerability Assessment
Why it stands out: high
Password Cracking with Hashcat
beginner · 2-4 hours
Crack weak password hashes using dictionary and brute-force attacks, then write a report on password policies.
Skills: Hashcat, Cryptography, Password Security
Why it stands out: medium
SIEM Log Analysis with Splunk
beginner · 3-4 hours
Ingest sample logs into Splunk, create dashboards, and detect brute-force attempts.
Skills: Splunk, SIEM, Log Analysis
Why it stands out: high
CTF Writeup: TryHackMe Beginner Room
beginner · 2-3 hours
Complete a beginner CTF room and write a detailed walkthrough explaining each step and tool used.
Skills: CTF, Problem Solving, Technical Writing
Why it stands out: high
Firewall Rule Configuration
beginner · 2-3 hours
Set up a basic firewall (iptables/ufw) on a Linux VM, create rules to allow/block traffic, and test them.
Skills: Firewall, Linux, Network Security
Why it stands out: medium
Phishing Email Analysis
beginner · 1-2 hours
Analyze a sample phishing email, extract headers, identify red flags, and write an incident report.
Skills: Email Security, Incident Response, Threat Analysis
Why it stands out: high
Intermediate Projects (3-6 hours each)
Apply tools in realistic scenarios, from vulnerability exploitation to cloud security and incident response.
Web App Penetration Test with Burp Suite
intermediate · 5-8 hours
Perform a full penetration test on a vulnerable web app using Burp Suite, exploit findings, and write a professional report.
Skills: Burp Suite, Web App Pentesting, Report Writing
Why it stands out: excellent
Metasploit Exploitation Lab
intermediate · 3-5 hours
Exploit a known vulnerability in a Metasploitable VM, gain shell access, and document the attack chain.
Skills: Metasploit, Exploitation, Post-Exploitation
Why it stands out: high
SIEM Incident Response Scenario
intermediate · 4-6 hours
Simulate a security incident, use Splunk to investigate logs, and create an incident response report.
Skills: Splunk, Incident Response, Threat Hunting
Why it stands out: excellent
Cloud Security Posture Review (AWS)
intermediate · 4-6 hours
Deploy a vulnerable AWS environment, identify misconfigurations, and remediate them following CIS benchmarks.
Skills: Cloud Security, AWS, Compliance
Why it stands out: excellent
Cryptography Challenge: Build a Cipher
intermediate · 3-5 hours
Implement a classical cipher (e.g., Vigenère) and then break it using cryptanalysis techniques.
Skills: Cryptography, Python, Cryptanalysis
Why it stands out: medium
Network Intrusion Detection with Snort
intermediate · 4-6 hours
Set up Snort, write custom rules to detect suspicious traffic, and test with simulated attacks.
Skills: Snort, IDS, Network Security
Why it stands out: high
Compliance Audit: GDPR/PCI DSS
intermediate · 5-7 hours
Conduct a mock compliance audit for a small business, identify gaps, and create a remediation plan.
Skills: Compliance, Risk Assessment, Auditing
Why it stands out: high
Malware Analysis Sandbox
intermediate · 4-6 hours
Analyze a benign malware sample in a sandbox, document behavior, and extract IOCs.
Skills: Malware Analysis, Sandboxing, IOC Extraction
Why it stands out: high
Advanced Projects (8-15 hours each)
Tackle complex, multi-tool projects that simulate real-world security engineering and response.
Build a Home SOC Lab
advanced · 10-15 hours
Set up a home SOC with SIEM, IDS, and endpoint monitoring, then simulate attacks and practice detection.
Skills: SIEM, IDS, Incident Response, Network Security
Why it stands out: excellent
Full-Scope Red Team Engagement
advanced · 12-20 hours
Conduct a red team engagement against a lab environment, from reconnaissance to persistence, and write a report.
Skills: Penetration Testing, Red Teaming, Report Writing
Why it stands out: excellent
Cloud Security Automation with Terraform
advanced · 8-12 hours
Use Terraform to deploy a secure AWS environment with automated compliance checks and monitoring.
Skills: Cloud Security, Terraform, Automation, Compliance
Why it stands out: excellent
Incident Response Tabletop Exercise
advanced · 8-10 hours
Design and facilitate a tabletop exercise for a ransomware scenario, including injects and after-action report.
Skills: Incident Response, Scenario Design, Communication
Why it stands out: high
Turn Projects into a Job-Winning Portfolio
- Create a personal website or GitHub Pages to host your portfolio.
- Include a mix of offensive, defensive, and compliance projects to show versatility.
- For each project, highlight the problem, your approach, tools used, and outcomes.
- Add a 'Skills' section that maps your projects to in-demand cybersecurity competencies.
- Regularly update your portfolio with new projects and certifications.
Tips that make the difference
- Document every project with a clear README, screenshots, and lessons learned.
- Use version control (GitHub) to showcase your work and commit regularly.
- Focus on quality: a deep dive into one project is better than superficial coverage of many.
- Always work in isolated lab environments and never test on systems you don't own.
- Write blog posts or create videos explaining your process to reinforce learning.
- Seek feedback from peers or mentors on your writeups and reports.
Ready to Build Your Cybersecurity Portfolio?
Start your first project on Edirae today and showcase your skills to employers. Join our community and get feedback from experts.
Start learning free