SOC Analyst Level 3 | Investigations | Offensive security | Engineering
Ciaran Byrne
Security operations informed by offensive research, forensics, and engineering
I work in enterprise security operations, investigating incidents, hunting for threats, and moving complex cases towards containment and response. My offensive work includes Windows payload development, exploit proofs of concept, internal-network pivoting, web application assessment, and the design of deliberately vulnerable cyber ranges. I use that attacker view to understand which controls failed, what evidence an action leaves, and which change actually makes a system harder to compromise.
Areas of work
Security operations, offensive research, forensics, and engineering
Security operations
Enterprise incident investigation, threat hunting, endpoint analysis, containment, escalation, and response handover.
Offensive security
Payload development, exploit validation, routed pivoting, web application testing, Active Directory attack paths, and adversary simulation in authorised environments.
Forensics and analysis
Malware analysis, network forensics, event correlation, reverse engineering, and evidence-led technical reporting.
Engineering
Cyber ranges, segmented infrastructure, backend services, automation, and the systems needed to make security work repeatable.
Selected projects
Systems I designed, built, or evaluated
Retiring the WordPress VPS I Built to Learn
A retrospective on the Docker-based WordPress platform I began building at university in 2021: how its security architecture evolved through experimentation, what failed in practice and what several years of operating it taught me.
- Docker
- Docker Compose
- Caddy
- WordPress
King of the Forest: Competitive Cyber Security Range
Honours project combining a Proxmox-based competitive cyber range with isolated team networks, intentionally vulnerable Linux and Active Directory hosts, and a custom scoring service.
- Proxmox VE
- OPNsense
- TrueNAS
- VXLAN
Authorised Payload Research Lab
Python and C++ framework for generating AES-encrypted Meterpreter payloads, resolving Windows APIs dynamically, and comparing self-injection with remote process injection under Defender.
- Python
- C++
- Windows API
- AES
Research and investigation
Investigations, malware analysis, and secure code review
Reviewing an Integer Overflow in MIT Kerberos
Secure-software engineering case study tracing CVE-2018-5709 through the MIT Kerberos 1.16 database-dump parser, reviewing the integer boundary, mitigation, testing strategy, and development controls that would prevent the same class of defect.
- C
- MIT Kerberos
- Secure Code Review
- CWE-190
Network Forensics Investigation
Individual forensic investigation of three packet captures using evidence hashing, interface-level preprocessing, Zeek correlation, file reconstruction, decoding, steganography analysis, and timeline-driven reporting.
- Wireshark
- Zeek
- CyberChef
- Linux
WannaCry Malware Analysis
Controlled analysis of a supplied WannaCry sample using static inspection, decompilation, isolated execution, memory forensics, process monitoring, and network-traffic review.
- Ghidra
- Volatility
- Wireshark
- FTK Imager
CTF walkthroughs
Hands-on attack paths and technical walkthroughs
Flatline Creator's Walkthrough
Beginner-focused creator walkthrough for my Flatline TryHackMe Windows room, covering FreeSWITCH enumeration, Python socket analysis, initial access and privilege escalation through insecure Windows service permissions.
- Nmap
- Python
- TCP Sockets
- FreeSWITCH
Alfred TryHackMe Walkthrough
Beginner-focused walkthrough of the Alfred TryHackMe Windows room, covering Jenkins default credentials, command execution through build steps, PowerShell reverse shells, Windows token privileges, Meterpreter, and SYSTEM escalation with Incognito.
- Nmap
- Jenkins
- Jetty
- PowerShell
Steel Mountain TryHackMe Walkthrough
Beginner-focused Steel Mountain walkthrough covering Windows service enumeration, Rejetto HFS remote command execution through Metasploit and a standalone Python exploit, and SYSTEM privilege escalation through an insecure unquoted service path.
- Nmap
- Rejetto HFS
- CVE-2014-6287
- Metasploit
Archive
Earlier technical work and coursework
The archive contains earlier work from systems administration, scripting, memory safety, embedded development, networking, and foundational security. It remains available as part of the progression towards the more complete work published across the rest of the site.
