Project ideas

50 Cybersecurity Project Ideas for Beginners (2026)

Discover 50 hands-on Cybersecurity project ideas perfect for learners. From beginner to advanced, build your portfolio with practical projects in 2026.

Topic: Cybersecurity

Want to break into cybersecurity? Build things. Break things. Then explain how you did it.

These 50 hands-on projects cover network security, appsec, cloud, incident response, compliance, and cryptography. Each project produces tangible artifacts, writeups, tools, reports, that prove your skills to employers in 2026.

Start with beginner projects to build fundamentals, then progress to advanced and expert levels. Document every step, publish your work on GitHub or a blog, and tailor projects to your target role.

Beginner Projects (1-2 hours each)

Build core skills with guided labs and simple tools. Perfect for those new to cybersecurity.

  1. Wireshark Traffic Analysis of a Home Network

    beginner · 1-2 hours

    Capture and analyze your home network traffic to identify protocols, devices, and potential anomalies.

    Skills: Wireshark, Network Protocols, Traffic Analysis, Documentation

    Why it stands out: medium

  2. Nmap Scan and Report on a Local Lab

    beginner · 1-2 hours

    Set up a virtual lab with vulnerable VMs and perform Nmap scans, then document findings in a professional report.

    Skills: Nmap, Port Scanning, Vulnerability Identification, Reporting

    Why it stands out: medium

  3. OWASP ZAP Baseline Scan of a Vulnerable Web App

    beginner · 1-2 hours

    Run an automated scan against OWASP Juice Shop or DVWA and summarize the top findings.

    Skills: OWASP ZAP, Web App Security, Automated Scanning, Report Writing

    Why it stands out: medium

  4. Password Cracking with Hashcat on a CTF Hash

    beginner · 1-2 hours

    Crack a set of MD5 and SHA1 hashes from a CTF challenge using Hashcat and document the process.

    Skills: Hashcat, Cryptography, Password Security, Linux CLI

    Why it stands out: medium

  5. Build a Personal Firewall with UFW

    beginner · 1-2 hours

    Configure UFW on a Linux VM to allow only specific services, then test with Nmap from another VM.

    Skills: Firewall Configuration, Linux, Network Security, Testing

    Why it stands out: medium

  6. Create a Phishing Email Analysis Report

    beginner · 1-2 hours

    Analyze a sample phishing email, extract indicators of compromise, and write a brief incident report.

    Skills: Email Security, Phishing Analysis, OSINT, Incident Reporting

    Why it stands out: medium

  7. Set Up a SIEM with Splunk Free and Ingest Logs

    beginner · 2-4 hours

    Install Splunk Free, forward logs from a Linux VM, and create a simple dashboard for failed logins.

    Skills: Splunk, SIEM, Log Analysis, Dashboarding

    Why it stands out: high

  8. SQL Injection Lab with DVWA

    beginner · 1-2 hours

    Exploit SQL injection vulnerabilities in DVWA at low security, then document mitigation strategies.

    Skills: SQL Injection, Web Security, Burp Suite, Mitigation

    Why it stands out: medium

  9. Encrypt and Decrypt Files with OpenSSL

    beginner · 1-2 hours

    Use OpenSSL to encrypt files with AES, then decrypt them, and explain the process in a blog post.

    Skills: OpenSSL, Cryptography, File Encryption, Technical Writing

    Why it stands out: medium

  10. Conduct a Basic OSINT Investigation

    beginner · 1-2 hours

    Perform OSINT on a fictional target using tools like theHarvester and Maltego, then present findings.

    Skills: OSINT, theHarvester, Maltego, Reconnaissance

    Why it stands out: medium

  11. Write a GDPR Compliance Checklist for a Small Business

    beginner · 2-3 hours

    Research GDPR requirements and create a practical checklist for a small business to assess compliance.

    Skills: Compliance, GDPR, Risk Assessment, Documentation

    Why it stands out: high

  12. Analyze a PCAP for Malicious Traffic

    beginner · 2-3 hours

    Given a PCAP with malware traffic, use Wireshark to identify the infection chain and write a report.

    Skills: Wireshark, Malware Analysis, Network Forensics, Reporting

    Why it stands out: high

  13. Create a Security Awareness Poster

    beginner · 1-2 hours

    Design an engaging poster on password hygiene or phishing, and explain the psychology behind it.

    Skills: Security Awareness, Design, Communication, Social Engineering

    Why it stands out: medium

Intermediate Projects (4-8 hours each)

Apply tools in realistic scenarios, build small tools, and deepen your understanding of core domains.

  1. Build a Home SOC Lab with Security Onion

    intermediate · 6-8 hours

    Deploy Security Onion in a VM, ingest logs from a Windows VM, and simulate a detection using Suricata rules.

    Skills: Security Onion, SIEM, Intrusion Detection, Log Analysis

    Why it stands out: excellent

  2. Exploit a Vulnerable Web App with Burp Suite

    intermediate · 4-6 hours

    Use Burp Suite to find and exploit XSS, CSRF, and IDOR in OWASP Juice Shop, then write a detailed writeup.

    Skills: Burp Suite, Web Exploitation, XSS, CSRF

    Why it stands out: high

  3. Metasploit Penetration Test on Metasploitable 2

    intermediate · 6-8 hours

    Perform a full penetration test on Metasploitable 2 using Metasploit, document vulnerabilities and remediation.

    Skills: Metasploit, Penetration Testing, Vulnerability Assessment, Reporting

    Why it stands out: excellent

  4. Cloud Security Audit of an AWS S3 Bucket

    intermediate · 4-5 hours

    Set up an intentionally misconfigured S3 bucket, then audit it using ScoutSuite and remediate issues.

    Skills: AWS, Cloud Security, ScoutSuite, IAM

    Why it stands out: high

  5. Incident Response Playbook for Ransomware

    intermediate · 5-7 hours

    Create a detailed incident response playbook for a ransomware attack, including detection, containment, and recovery.

    Skills: Incident Response, Ransomware, Playbook Development, NIST

    Why it stands out: excellent

  6. Cryptography Challenge: Break Weak RSA

    intermediate · 4-6 hours

    Given a weak RSA implementation, factor the modulus and decrypt the message, then explain the flaw.

    Skills: Cryptography, RSA, Python, Mathematical Analysis

    Why it stands out: high

  7. Build a Network Scanner in Python

    intermediate · 5-7 hours

    Write a Python script that scans a network for open ports and services, using sockets and threading.

    Skills: Python, Network Scanning, Sockets, Automation

    Why it stands out: high

  8. SIEM Correlation Rule Development in Splunk

    intermediate · 6-8 hours

    Create correlation rules in Splunk to detect brute force, port scanning, and data exfiltration.

    Skills: Splunk, SIEM, Correlation Rules, Detection Engineering

    Why it stands out: excellent

  9. PCI DSS Compliance Assessment for a Mock E-commerce Site

    intermediate · 6-8 hours

    Assess a mock e-commerce environment against PCI DSS requirements and produce a gap analysis report.

    Skills: PCI DSS, Compliance, Risk Assessment, Auditing

    Why it stands out: excellent

  10. Memory Forensics with Volatility

    intermediate · 5-7 hours

    Analyze a memory dump from a compromised VM using Volatility to find malware and persistence mechanisms.

    Skills: Volatility, Memory Forensics, Malware Analysis, Incident Response

    Why it stands out: excellent

  11. API Security Testing with Postman and Burp

    intermediate · 4-6 hours

    Test a REST API for common vulnerabilities like broken authentication and excessive data exposure.

    Skills: API Security, Burp Suite, Postman, OWASP API Top 10

    Why it stands out: high

  12. Create a Threat Model for a Web Application

    intermediate · 4-5 hours

    Use STRIDE or PASTA to threat model a web app, identify threats, and propose mitigations.

    Skills: Threat Modeling, STRIDE, Risk Analysis, Secure Design

    Why it stands out: high

  13. Wireless Security Assessment with Aircrack-ng

    intermediate · 4-6 hours

    Set up a wireless lab, capture WPA2 handshake, and crack it with Aircrack-ng, then document findings.

    Skills: Wireless Security, Aircrack-ng, WPA2, Penetration Testing

    Why it stands out: high

  14. Build a Honeypot with Cowrie

    intermediate · 6-8 hours

    Deploy Cowrie honeypot, collect attack logs, and analyze attacker behavior over a week.

    Skills: Honeypots, Cowrie, Log Analysis, Threat Intelligence

    Why it stands out: excellent

Advanced Projects (10-20 hours each)

Tackle complex, multi-step projects that simulate real-world security engineering and consulting.

  1. Full Penetration Test Report for a Simulated Enterprise

    advanced · 15-20 hours

    Conduct an end-to-end penetration test on a multi-VM lab, from reconnaissance to reporting, following PTES.

    Skills: Penetration Testing, PTES, Reporting, Risk Rating

    Why it stands out: excellent

  2. Build a Cloud Security Posture Management (CSPM) Tool

    advanced · 15-20 hours

    Develop a Python tool that scans AWS for misconfigurations and outputs a report, using boto3.

    Skills: AWS, Python, CSPM, Cloud Security

    Why it stands out: excellent

  3. Design and Implement a Zero Trust Architecture

    advanced · 12-15 hours

    Create a zero trust network design for a small business, including identity, device, and network controls.

    Skills: Zero Trust, Network Security, Identity Management, Architecture

    Why it stands out: excellent

  4. Malware Analysis of a Real Ransomware Sample

    advanced · 15-20 hours

    Perform static and dynamic analysis of a ransomware sample in a sandbox, and write a detailed report.

    Skills: Malware Analysis, Reverse Engineering, Sandboxing, Reporting

    Why it stands out: excellent

  5. Build a SIEM from Scratch with ELK Stack

    advanced · 15-20 hours

    Deploy Elasticsearch, Logstash, and Kibana, ingest logs, and create detection rules and dashboards.

    Skills: ELK Stack, SIEM, Log Management, Detection Engineering

    Why it stands out: excellent

  6. Conduct a Red Team Exercise Against a Corporate Network

    advanced · 20+ hours

    Simulate an APT attack against a lab network, using Cobalt Strike or Sliver, and document the kill chain.

    Skills: Red Teaming, C2, Post-Exploitation, OPSEC

    Why it stands out: excellent

  7. Develop a Secure Software Development Lifecycle (SSDLC) Policy

    advanced · 10-12 hours

    Create a comprehensive SSDLC policy for a fictional company, including threat modeling and secure coding.

    Skills: SSDLC, Policy Development, Secure Coding, Compliance

    Why it stands out: high

  8. Build a Custom Exploit for a Known CVE

    advanced · 20+ hours

    Choose a CVE, develop a working exploit, and write a detailed analysis of the vulnerability and exploit.

    Skills: Exploit Development, Reverse Engineering, CVE Analysis, Python

    Why it stands out: excellent

  9. Implement a PKI Infrastructure with OpenSSL

    advanced · 10-12 hours

    Set up a root CA, intermediate CA, and issue certificates for a web server and client authentication.

    Skills: PKI, OpenSSL, Certificate Management, Cryptography

    Why it stands out: high

  10. Conduct a Cloud Incident Response Simulation

    advanced · 12-15 hours

    Simulate a compromised AWS account, investigate using CloudTrail and GuardDuty, and write an IR report.

    Skills: Cloud Incident Response, AWS, CloudTrail, GuardDuty

    Why it stands out: excellent

  11. Build a Threat Intelligence Platform

    advanced · 15-20 hours

    Aggregate threat feeds, enrich with VirusTotal, and create a dashboard for IOCs using MISP.

    Skills: Threat Intelligence, MISP, API Integration, Data Enrichment

    Why it stands out: excellent

  12. Perform a Compliance Audit for ISO 27001

    advanced · 12-15 hours

    Conduct a mock ISO 27001 audit for a small company, including gap analysis and remediation plan.

    Skills: ISO 27001, Compliance, Auditing, Risk Management

    Why it stands out: excellent

Expert Projects (20+ hours each)

Push boundaries with original research, tool development, or complex simulations that showcase mastery.

  1. Develop a Novel Detection Technique for Fileless Malware

    advanced · 30+ hours

    Research fileless malware, develop a detection method using ETW or Sysmon, and publish a paper.

    Skills: Detection Engineering, Windows Internals, Sysmon, Research

    Why it stands out: excellent

  2. Build an Automated Penetration Testing Framework

    advanced · 40+ hours

    Create a modular framework that automates reconnaissance, exploitation, and reporting using Python and Metasploit.

    Skills: Automation, Python, Metasploit, Framework Development

    Why it stands out: excellent

  3. Conduct a Full-Scope Red Team Engagement Simulation

    advanced · 40+ hours

    Plan and execute a red team operation against a simulated enterprise, including social engineering and physical.

    Skills: Red Teaming, Social Engineering, Physical Security, Reporting

    Why it stands out: excellent

  4. Design a Secure Multi-Cloud Architecture

    advanced · 30+ hours

    Architect a secure multi-cloud environment (AWS, Azure) with zero trust, encryption, and monitoring.

    Skills: Multi-Cloud, Security Architecture, Zero Trust, Compliance

    Why it stands out: excellent

  5. Create a Cryptography Library in Rust

    advanced · 40+ hours

    Implement common cryptographic primitives (AES, RSA, SHA) in Rust with tests and documentation.

    Skills: Cryptography, Rust, Library Development, Testing

    Why it stands out: excellent

  6. Build a Threat Hunting Platform with Jupyter and Elastic

    advanced · 35+ hours

    Develop a platform for proactive threat hunting, integrating Jupyter notebooks with Elasticsearch.

    Skills: Threat Hunting, Jupyter, Elasticsearch, Data Science

    Why it stands out: excellent

  7. Perform a Full Incident Response for a Simulated APT

    advanced · 30+ hours

    Simulate an APT attack, then lead the incident response from detection to recovery, documenting everything.

    Skills: Incident Response, APT, Forensics, Crisis Management

    Why it stands out: excellent

  8. Develop a Secure Coding Standard and Training Program

    advanced · 25+ hours

    Create a secure coding standard for an organization and develop training materials for developers.

    Skills: Secure Coding, Training Development, OWASP, Policy

    Why it stands out: high

  9. Build a Custom SIEM with Machine Learning Anomaly Detection

    advanced · 40+ hours

    Implement a SIEM that uses ML to detect anomalies in network traffic, using Python and scikit-learn.

    Skills: Machine Learning, SIEM, Python, Anomaly Detection

    Why it stands out: excellent

  10. Conduct a Comprehensive Compliance Program for a Startup

    advanced · 30+ hours

    Build a full compliance program (GDPR, SOC2, ISO 27001) for a startup, including policies and controls.

    Skills: Compliance, GDPR, SOC2, ISO 27001

    Why it stands out: excellent

Build a Portfolio That Gets You Hired

  • Create a personal website or GitHub Pages to showcase your projects and writeups.
  • Tailor your portfolio to the job you want: highlight relevant projects for each application.
  • Include metrics and outcomes (e.g., 'reduced false positives by 30%') to demonstrate impact.
  • Add video demonstrations or screencasts for complex projects to make them accessible.
  • Network on LinkedIn and Twitter by sharing your projects and engaging with the community.

Tips that make the difference

  • Document everything: write detailed READMEs, blog posts, or video walkthroughs for each project.
  • Use version control (Git) and host your code on GitHub to showcase your work.
  • Focus on quality over quantity: a few deep projects are better than many shallow ones.
  • Always include a 'lessons learned' section to demonstrate reflection and growth.
  • Collaborate with others or join CTFs to simulate team environments.
  • Keep your portfolio updated with the latest tools and techniques relevant to 2026.

Ready to Build Your Cybersecurity Portfolio?

Start your first project today on Edirae and join a community of learners. Your future employer is waiting to see what you can do.

Start learning free