Research

Research and investigation

Technical investigations, secure-code reviews, infrastructure labs, and historical study notes with the method, evidence, and practical context preserved.

Secure Software Engineering

Reviewing an Integer Overflow in MIT Kerberos

Secure-programming review of CVE-2018-5709 in MIT Kerberos 1.16, tracing a database-dump integer conversion and the bounds check used to reject invalid key-data sizes.

  • C
  • MIT Kerberos
  • Secure Code Review
  • CWE-190
Digital Forensics

Network Forensics Investigation

Individual investigation of three supplied packet captures using hashing, Wireshark, Zeek, file reconstruction, decoding, and timeline-driven evidence analysis.

  • Wireshark
  • Zeek
  • CyberChef
  • Linux
Human-Centred Security

Phishing Resilience and Authentication Design

Human-centred security research on phishing susceptibility, continuous awareness work, usable authentication, password management, and multi-factor controls.

  • Phishing Simulation
  • Security Awareness
  • Multi-Factor Authentication
  • Password Management
Malware Analysis

WannaCry Malware Analysis

Controlled analysis of a supplied WannaCry sample using static inspection, decompilation, isolated execution, memory forensics, process monitoring, and network-traffic review.

  • Ghidra
  • Volatility
  • Wireshark
  • FTK Imager
Threat Hunting

Network Forensics and Threat Hunting Labs

A semester of practical investigation work using Security Onion, Zeek, Sysmon, Velociraptor, Snort, packet analysis, and endpoint telemetry to trace suspicious activity.

  • Security Onion
  • Zeek
  • Wireshark
  • TShark
Digital Forensics

Windows Endpoint Forensics Investigation

Collaborative examination of two supplied Windows workstation images, correlating registry artefacts, event logs, prefetch, link files, shellbags, and network-share traces to reconstruct a domain compromise.

  • FTK Imager
  • Magnet AXIOM
  • Registry Explorer
  • PECmd
Lab Notes

Cyber Security Law, Compliance, and Evidence

Historical information-assurance notes comparing legal and compliance frameworks through the security work they create: access control, logging, retention, breach response, audit evidence, and accountability.

  • Information Assurance
  • Privacy
  • Compliance
Lab Notes

Risk Management in Cyber Security

Historical information-assurance notes on bias, risk assessment, prioritisation, and the NIST Risk Management Framework.

  • NIST RMF
  • Information Assurance
Lab Notes

Active Directory Lab Basics

Historical lab note on building a small Windows Server Active Directory environment with DNS, domain joining, user management, and security-risk observations.

  • Active Directory
  • Windows Server
  • DNS
  • LDAP
Lab Notes

Introduction to Docker

Historical Docker lab note covering container images, registries, service deployment, port publishing, persistence, troubleshooting, and container security basics.

  • Docker
  • Linux
  • Containers
Information Assurance

Incident Response and Information Governance

Information-assurance coursework connecting data classification, governance, incident triage, evidence preservation, communications, containment, recovery, and post-incident review.

  • Incident Response
  • Data Classification
  • Information Governance
  • Digital Forensics