SOC analyst | Offensive security | Investigations | Engineering
Ciaran Byrne
Offensive security, investigations and technical engineering
I work in security operations and use practical projects to explore authorised red-team techniques, digital forensics, infrastructure, secure software, and defensive visibility. This site records the systems I built, the investigations I completed, and the offensive research behind them.
Working areas
From adversarial testing to investigation and implementation
Offensive security
Authorised assessment, adversarial research, exploit-development study, and red-team methodology.
Investigations
Network forensics, log analysis, threat-hunting context, crash analysis, and structured technical reporting.
Security operations
Alert investigation, defensive visibility, detection behaviour, and incident-response context.
Engineering
Virtualised ranges, segmented networks, Python, PowerShell, C, C++, and systems integration.
Selected projects
Built and evaluated in controlled environments
King of the Forest: Competitive Cyber Security Range
Honours project combining a Proxmox-based competitive cyber range with isolated team networks, intentionally vulnerable Linux and Active Directory hosts, and a custom scoring service.
- Proxmox VE
- OPNsense
- TrueNAS
- VXLAN
Authorised Payload Research Lab
CMP320 / Advanced Ethical Hacking research into Python-driven Windows payload packaging, C++ template generation, self-injection and process-injection models, and the difference between static and runtime detection.
- Python
- C++
- Windows API
- AES
Internal Network Security Evaluation
Third-year assessment of an undocumented multi-subnet lab network, covering route-led discovery, controlled pivoting, host and service weaknesses, firewall review, and prioritised remediation.
- Kali Linux
- Nmap
- SSH
- NFS
Research and investigation
Technical work with the method left visible
Reviewing an Integer Overflow in MIT Kerberos
Secure-software engineering case study tracing CVE-2018-5709 through the MIT Kerberos 1.16 database-dump parser, reviewing the integer boundary, mitigation, testing strategy, and development controls that would prevent the same class of defect.
- C
- MIT Kerberos
- Secure Code Review
- CWE-190
Network Forensics Investigation
Individual forensic investigation of three packet captures using evidence hashing, interface-level preprocessing, Zeek correlation, file reconstruction, decoding, steganography analysis, and timeline-driven reporting.
- Wireshark
- Zeek
- CyberChef
- Linux
WannaCry Malware Analysis
Controlled analysis of a supplied WannaCry sample using static inspection, decompilation, isolated execution, memory forensics, process monitoring, and network-traffic review.
- Ghidra
- Volatility
- Wireshark
- FTK Imager
CTF walkthroughs
Machines, challenges and attack paths
Flatline Creator's Walkthrough
Beginner-focused creator walkthrough for my Flatline TryHackMe Windows room, covering FreeSWITCH enumeration, Python socket analysis, initial access and privilege escalation through insecure Windows service permissions.
- Nmap
- Python
- TCP Sockets
- FreeSWITCH
Alfred TryHackMe Walkthrough
Beginner-focused walkthrough of the Alfred TryHackMe Windows room, covering Jenkins default credentials, command execution through build steps, PowerShell reverse shells, Windows token privileges, Meterpreter, and SYSTEM escalation with Incognito.
- Nmap
- Jenkins
- Jetty
- PowerShell
Steel Mountain TryHackMe Walkthrough
Beginner-focused Steel Mountain walkthrough covering Windows service enumeration, Rejetto HFS remote command execution through Metasploit and a standalone Python exploit, and SYSTEM privilege escalation through an insecure unquoted service path.
- Nmap
- Rejetto HFS
- CVE-2014-6287
- Metasploit
Technical progression
Earlier coursework remains part of the record
The archive keeps practical notes from Linux administration, Windows memory-safety labs, scripting coursework, and early embedded and parallel programming.
