Detection lab - build the attack, then catch it
Proxmox, Windows Server 2022, Active Directory, Sysmon, Wazuh, Atomic Red Team- Two-domain lab where I execute ATT&CK techniques and then write detections for them
- Twelve Sigma rules published with the false positives each one produced in my own environment, which is the part most repositories leave out
- github.com/aisharahman/detection-lab
Phish-report - reported email triage helper
Python, Microsoft Graph API, VirusTotal API- Parses a reported email, extracts headers, URLs and attachment hashes, and produces a one-page summary for the analyst
- Cut my own average triage time during the internship from about 12 minutes to about 4
- Deliberately does not auto-close anything - it gathers, a human decides
BSides Canberra CTF 2025
Team event, 60 teams- Placed 9th. Wrote up the two forensics challenges I solved, including the one that took me four hours and should have taken forty minutes