System 04 — Security Practice

Capability-oriented security domain map grounded in practical analysis, system controls, and verifiable project evidence.

Security Analysis & Assessment

  • Vulnerability Assessment & Penetration Testing
  • Network Security Architecture & Auditing
  • Access Control & IAM Governance (MBAC / RBAC)
  • Compliance-Aware Systems Design
  • Incident Analysis & Threat Identification
  • Security Controls Verification
  • Secure Software Development Lifecycle (SSDLC)
  • Risk Mitigation & Threat Modeling

Security Engineering & Systems Hardening

  • Secure Application Architecture (Django / React)
  • Authentication & Session Hardening
  • Programmatic State Machine Transition Enforcement
  • Immutable Governance & Transaction Audit Logging
  • Linux Server Administration & Hardening
  • Nginx Reverse Proxy & Firewall Configuration
  • Intune Autopilot & Endpoint Identity Management
  • Public Key Infrastructure (PKI) & TLS Encryption

Verifiable Evidence & Practical Artifacts

Every capability in this domain map is backed by real project implementations, lab exercises, and writeups.

Security Lab Journal

Continuous log of hands-on security labs, threat detection exercises, and vulnerability assessments executed during the CyberShujaa 30 Days to Hire Challenge and independent research.

Vulnerability AssessmentAugust 2026

Network Reconnaissance & Vulnerability Assessment

Objective: Identify open ports, running services, and misconfigurations on a simulated target environment.

NmapWiresharkOpenVASMetasploit
View Lab Findings
Application SecurityJuly 2026

Access Control & State Machine Hardening in Web Applications

Objective: Prevent privilege escalation and illegal state jumps in multi-role governance workflows.

PythonDjangodjango-fsmPostmanBurp Suite
View Lab Findings
Network SecurityMay 2026

Linux Server Hardening & Nginx Reverse Proxy Configuration

Objective: Harden Ubuntu Linux server instance and configure secure Nginx reverse proxy with TLS/SSL encryption.

UFW FirewallNginxCertbotOpenSSH
View Lab Findings

Technical Writeups

Incident Report: PCAP Network Intrusion Analysis

Network Security & Incident ResponseAugust 2026

A technical incident report detailing a multi-stage intrusion involving a malicious ZIP archive, first-stage command-and-control, and Cobalt Strike deployment.

WiresharkNetwork AnalysisSplunk (SIEM)+5
Read Report

Security Hardening & Governance Controls in the SGSS Medical Fund Portal

Application Security & GovernanceAugust 2026

A technical writeup examining the security architecture, governance controls, and hardening measures implemented in a production medical fund management system.

DjangoDjango REST Frameworkdjango-fsm+3
Read Report

Incident Response Report: Windows Server 2016 Compromise & Host Forensics

Incident Response & Host ForensicsAugust 2026

A comprehensive forensic investigation and step-by-step incident response report analyzing a compromised Windows Server 2016 endpoint. Covers web shell delivery, privilege escalation, credential dumping with Mimikatz, persistent registry run keys, backdoor scheduled tasks, Sigma detection logic, and clean vs. rebuild decision analysis.

Windows Event ViewerRegistry EditorTask Scheduler+5
Read Report

Contact Me

or send me a message: