Skip to main content
PORTFOLIO

Projects

Security tools, forensic investigations, and research projects built from the ground up.

Nether's Gate

Private
Advanced2024 to 2025

Custom C/C++ malware framework implementing shellcode encryption (AES/RC4), payload staging, process injection, and sandbox evasion. Built as a red team loader to demonstrate and study EDR bypass techniques in controlled environments.

C++Windows APIShellcode InjectionAES/RC4 EncryptionSandbox EvasionQt

SUMCESA: Cyber Essentials Automation

Advanced2025

Full-stack Python/Flask platform that automates UK Cyber Essentials self-assessment. It inventories installed software, correlates versions against the NVD/CVE database, scores each finding with CVSS, and generates export-ready PDF compliance reports. Integrated Groq Llama API for AI-assisted risk narrative.

PythonFlaskNVD/CVE APIGroq Llama APICVSS ScoringPDF Export

Windows Write Blocker

Beginner2023

Forensic-grade GUI tool built with Python that applies Windows registry-level write protection to internal and external drives, preventing evidence tampering during DFIR acquisition. Features auto device detection, activity logging, and one-click CSV export for chain-of-custody documentation.

Pythontkinter/ttkbootstrapWindows RegistryPyInstaller EXE

Lone Wolf DFIR Case

Intermediate2023

End-to-end forensic investigation of the Digital Corpora 2018 Lone Wolf scenario, covering hash-verified image acquisition, MFT and registry artifact analysis, email and browser forensics, full timeline reconstruction, and a legal-standard investigative report linking digital evidence to suspect activity.

AutopsyVolatilityWiresharkFTK ImagerTimeline Explorer
View Report3.6 MB PDF

Narcos DFIR Case

Advanced2024

Collaborative advanced investigation on the 50 GB Digital Corpora 2019 Narcos dataset, covering multi-analyst evidence verification, deleted file carving, communication interception analysis, malware artifact correlation across disk and memory, and a comprehensive case report with suspect attribution.

AutopsyVolatilityWiresharkPythonSQLiteFTK

Mr. Evil Investigation

Intermediate2024

NIST CFREDS Mr. Evil forensic challenge. Identified 6+ hacking tools on a Dell CPi notebook, reconstructed the OS activity timeline, analysed IRC logs and email artifacts, extracted network traces from PCAP, and attributed suspect identity through digital evidence. Delivered a legal-ready court report.

AutopsyWiresharkEmail ForensicsPCAP AnalysisDFIR Reporting

Secure Donation Portal

Intermediate2024

Security-first full-stack donation platform with JWT authentication, Google reCAPTCHA v3, role-based access control (donor/admin/manager), case management workflows, parameterised SQL queries preventing injection, and CSRF-protected API endpoints.

ReactNode.jsMySQLJWTreCAPTCHA v3BcryptCORS Policy

Want something like this built?

Most of these started as a gap in the available tooling. If you need a custom security tool, a forensic investigation, or a penetration test against your own environment, tell me the problem and I will tell you what it needs.