Research

Research and investigation

Technical investigations, secure-code reviews, infrastructure labs, and historical study notes with the method, evidence, and practical context preserved.

Secure Software Engineering

Reviewing an Integer Overflow in MIT Kerberos

Secure-software engineering case study tracing CVE-2018-5709 through the MIT Kerberos 1.16 database-dump parser, reviewing the integer boundary, mitigation, testing strategy, and development controls that would prevent the same class of defect.

  • C
  • MIT Kerberos
  • Secure Code Review
  • CWE-190
Digital Forensics

Network Forensics Investigation

Individual forensic investigation of three packet captures using evidence hashing, interface-level preprocessing, Zeek correlation, file reconstruction, decoding, steganography analysis, and timeline-driven reporting.

  • Wireshark
  • Zeek
  • CyberChef
  • Linux
Human-Centred Security

Phishing Resilience and Authentication Design

Human-centred security research connecting phishing pressure, organisational context, continuous awareness work, usable authentication, password management, multi-factor controls, and operational response.

  • Phishing Simulation
  • Security Awareness
  • Human Factors
  • Multi-Factor Authentication
Malware Analysis

WannaCry Malware Analysis

Controlled analysis of a supplied WannaCry sample using static inspection, decompilation, isolated execution, memory forensics, process monitoring, and network-traffic review.

  • Ghidra
  • Volatility
  • Wireshark
  • FTK Imager
Threat Hunting

Network Forensics and Threat Hunting Labs

A 2022 lab series correlating packets, Zeek, Security Onion and Sysmon to reconstruct suspicious activity and expose each evidence source's limits.

  • Security Onion
  • Zeek
  • Wireshark
  • TShark
Digital Forensics

Windows Endpoint Forensics Investigation

Collaborative examination of two Windows workstation images, correlating registry artefacts, Sysmon, event logs, prefetch, shellbags, LNK files and mapped-share evidence to reconstruct part of a wider domain compromise.

  • FTK Imager
  • Magnet AXIOM
  • Registry Explorer
  • PECmd