SOC Analyst Level 3 | Investigations | Offensive security | Engineering
Ciaran Byrne
Security operations backed by offensive, forensic, and engineering experience
I work in enterprise security operations, investigating incidents, hunting for threats, and helping move complex cases towards containment and response. I am interested in security as a complete system rather than a set of separate disciplines: how an attacker moves, what the defender can see, and how infrastructure, software, and identity change the options available to both. This site documents the projects, investigations, and research behind that work.
Areas of work
Security operations, offensive research, forensics, and engineering
Security operations
Enterprise incident investigation, threat hunting, endpoint analysis, containment, escalation, and response handover.
Offensive security
Authorised testing, exploit research, adversary simulation, and understanding how attacks work in practice.
Forensics and analysis
Malware analysis, network forensics, event correlation, reverse engineering, and evidence-led technical reporting.
Engineering
Cyber ranges, segmented infrastructure, backend services, automation, and the systems needed to make security work repeatable.
Selected projects
Systems I designed, built, or evaluated
King of the Forest: Competitive Cyber Security Range
Honours project combining a Proxmox-based competitive cyber range with isolated team networks, intentionally vulnerable Linux and Active Directory hosts, and a custom scoring service.
- Proxmox VE
- OPNsense
- TrueNAS
- VXLAN
Authorised Payload Research Lab
CMP320 / Advanced Ethical Hacking research into Python-driven Windows payload packaging, C++ template generation, self-injection and process-injection models, and the difference between static and runtime detection.
- Python
- C++
- Windows API
- AES
Internal Network Security Evaluation
Third-year assessment of an undocumented multi-subnet lab network, covering route-led discovery, controlled pivoting, host and service weaknesses, firewall review, and prioritised remediation.
- Kali Linux
- Nmap
- SSH
- NFS
Research and investigation
Investigations, malware analysis, and secure code review
Reviewing an Integer Overflow in MIT Kerberos
Secure-software engineering case study tracing CVE-2018-5709 through the MIT Kerberos 1.16 database-dump parser, reviewing the integer boundary, mitigation, testing strategy, and development controls that would prevent the same class of defect.
- C
- MIT Kerberos
- Secure Code Review
- CWE-190
Network Forensics Investigation
Individual forensic investigation of three packet captures using evidence hashing, interface-level preprocessing, Zeek correlation, file reconstruction, decoding, steganography analysis, and timeline-driven reporting.
- Wireshark
- Zeek
- CyberChef
- Linux
WannaCry Malware Analysis
Controlled analysis of a supplied WannaCry sample using static inspection, decompilation, isolated execution, memory forensics, process monitoring, and network-traffic review.
- Ghidra
- Volatility
- Wireshark
- FTK Imager
CTF walkthroughs
Hands-on attack paths and technical walkthroughs
Flatline Creator's Walkthrough
Beginner-focused creator walkthrough for my Flatline TryHackMe Windows room, covering FreeSWITCH enumeration, Python socket analysis, initial access and privilege escalation through insecure Windows service permissions.
- Nmap
- Python
- TCP Sockets
- FreeSWITCH
Alfred TryHackMe Walkthrough
Beginner-focused walkthrough of the Alfred TryHackMe Windows room, covering Jenkins default credentials, command execution through build steps, PowerShell reverse shells, Windows token privileges, Meterpreter, and SYSTEM escalation with Incognito.
- Nmap
- Jenkins
- Jetty
- PowerShell
Steel Mountain TryHackMe Walkthrough
Beginner-focused Steel Mountain walkthrough covering Windows service enumeration, Rejetto HFS remote command execution through Metasploit and a standalone Python exploit, and SYSTEM privilege escalation through an insecure unquoted service path.
- Nmap
- Rejetto HFS
- CVE-2014-6287
- Metasploit
Archive
Earlier technical work and coursework
The archive contains earlier work from systems administration, scripting, memory safety, embedded development, networking, and foundational security. It remains available as part of the progression towards the more complete work published across the rest of the site.
