Project ideas

30 Cybersecurity Projects for Your Portfolio (2026)

Discover 30 hands-on Cybersecurity project ideas perfect for learners. From beginner to advanced, build your portfolio with practical projects in 2026.

Topic: Cybersecurity

In 2026, cybersecurity employers won't just read your resume, they'll inspect your GitHub, your lab writeups, and your CTF badges.

These 30 hands-on projects span network defense, application security, cloud hardening, incident response, compliance, and cryptography. Each produces a tangible artifact, a tool, a report, a lab environment, that proves you can operate real security tools like Wireshark, Nmap, Burp Suite, Metasploit, Splunk, and OWASP ZAP under realistic constraints.

Start with the beginner tier to build foundational fluency, then progress to intermediate and advanced projects that mirror real SOC, red team, and cloud security workflows. Document every step, publish sanitized writeups, and link your repositories in your portfolio.

Beginner Projects (1–4 hours each)

Build core tool familiarity and produce your first portfolio artifacts with guided, low-risk labs.

  1. Home Network Vulnerability Scan with Nmap

    beginner · 2-3 hours

    Scan your home network, identify open ports and services, and produce a prioritized remediation report with screenshots and Nmap scripts used.

    Skills: Nmap scripting, Network reconnaissance, Report writing

    Why it stands out: high

  2. Wireshark Traffic Analysis of a Simulated Attack

    beginner · 3-4 hours

    Capture and analyze a PCAP from a public malware-traffic-analysis exercise, identifying C2 beacons, DNS tunneling, and suspicious TLS certificates.

    Skills: Packet analysis, Protocol dissection, Threat hunting

    Why it stands out: high

  3. OWASP ZAP Baseline Scan on a Vulnerable Web App

    beginner · 2-3 hours

    Run an automated baseline scan against OWASP Juice Shop, triage alerts, and write a concise executive summary with false-positive notes.

    Skills: OWASP ZAP, Web vulnerability scanning, Triage

    Why it stands out: high

  4. Password Cracking Lab with Hashcat

    beginner · 2-4 hours

    Crack a set of provided NTLM and SHA-256 hashes using wordlists and rules, then document password policy weaknesses and mitigation strategies.

    Skills: Hashcat, Password policy analysis, Cryptography basics

    Why it stands out: medium

  5. Phishing Email Triage with Splunk

    beginner · 3-4 hours

    Ingest a sample phishing email dataset into Splunk, build a dashboard for sender reputation and URL extraction, and write an incident summary.

    Skills: Splunk SPL, Email header analysis, Incident documentation

    Why it stands out: high

  6. Firewall Rule Audit with pfSense

    beginner · 3-4 hours

    Configure a pfSense VM, create a least-privilege rule set for a small network, and document the audit process with before/after rule tables.

    Skills: Firewall configuration, Network segmentation, Change documentation

    Why it stands out: medium

  7. CTF Writeup: TryHackMe Pre-Security Path

    beginner · 2-3 hours

    Complete a beginner TryHackMe room, capture flags, and publish a step-by-step writeup with screenshots and lessons learned.

    Skills: Linux CLI, Enumeration, Technical writing

    Why it stands out: high

  8. SSL/TLS Configuration Checker with Python

    beginner · 3-4 hours

    Write a Python script that connects to a host, retrieves the certificate, checks expiry and cipher suite, and outputs a JSON report.

    Skills: Python sockets, TLS fundamentals, Automation

    Why it stands out: medium

  9. Security Awareness Poster and Quiz

    beginner · 2-3 hours

    Design a one-page phishing awareness poster and a 10-question quiz, then deploy it via Google Forms and analyze results.

    Skills: Security awareness, Content design, Data analysis

    Why it stands out: medium

  10. Vulnerability Report for a Public CVE

    beginner · 3-4 hours

    Pick a recent CVE, reproduce it in a lab, and write a vulnerability report with CVSS score, impact, and remediation steps.

    Skills: CVE analysis, CVSS scoring, Vulnerability reporting

    Why it stands out: high

Intermediate Projects (5–12 hours each)

Combine multiple tools and frameworks to simulate real security operations, red team, and cloud security tasks.

  1. SIEM Home Lab with Splunk and Sysmon

    intermediate · 8-12 hours

    Build a Splunk instance ingesting Sysmon logs from a Windows VM, create detection rules for common attacks, and document the architecture.

    Skills: Splunk administration, Sysmon, Detection engineering

    Why it stands out: excellent

  2. Metasploit Exploitation Walkthrough on Metasploitable

    intermediate · 6-8 hours

    Exploit three vulnerabilities in Metasploitable 2 using Metasploit, capture screenshots, and write a red team report with mitigation advice.

    Skills: Metasploit, Exploitation, Red team reporting

    Why it stands out: high

  3. Burp Suite Web App Penetration Test

    intermediate · 10-12 hours

    Perform a manual web app pentest against DVWA or Juice Shop using Burp Suite, covering SQLi, XSS, and CSRF, and deliver a full report.

    Skills: Burp Suite, Web app pentesting, Report writing

    Why it stands out: excellent

  4. Incident Response Playbook for Ransomware

    intermediate · 6-8 hours

    Create a ransomware IR playbook aligned with NIST SP 800-61, including detection, containment, eradication, and recovery steps.

    Skills: Incident response, NIST framework, Playbook development

    Why it stands out: high

  5. Cloud Security Posture Review on AWS Free Tier

    intermediate · 8-10 hours

    Deploy a small AWS environment, run Prowler or ScoutSuite, remediate findings, and document the before/after security posture.

    Skills: AWS security, Cloud scanning, Remediation

    Why it stands out: excellent

  6. Network Traffic Anomaly Detection with Zeek

    intermediate · 8-12 hours

    Deploy Zeek on a home network, generate traffic, and write scripts to detect port scans and unusual DNS queries, then visualize with Kibana.

    Skills: Zeek, Network monitoring, Log analysis

    Why it stands out: high

  7. Cryptography Challenge: Implement AES and RSA

    intermediate · 8-10 hours

    Implement AES-256-CBC and RSA-OAEP from scratch in Python, then write tests and a comparison of performance and security trade-offs.

    Skills: Cryptography, Python, Secure coding

    Why it stands out: high

  8. Compliance Gap Assessment for ISO 27001

    intermediate · 6-8 hours

    Perform a mock ISO 27001 gap assessment for a fictional company, produce a findings register, and draft a remediation roadmap.

    Skills: ISO 27001, Compliance auditing, Risk management

    Why it stands out: medium

  9. CTF Writeup: Hack The Box Easy Machine

    intermediate · 5-8 hours

    Root an easy HTB machine, document enumeration, exploitation, and privilege escalation, and publish a polished writeup.

    Skills: Enumeration, Privilege escalation, Writeup skills

    Why it stands out: excellent

  10. API Security Testing with Postman and OWASP ZAP

    intermediate · 8-10 hours

    Test a REST API for broken authentication, rate limiting, and injection flaws using Postman collections and ZAP, then report findings.

    Skills: API security, Postman, OWASP ZAP

    Why it stands out: high

  11. Digital Forensics: Memory Analysis with Volatility

    intermediate · 6-8 hours

    Analyze a provided memory dump using Volatility 3, extract processes, network connections, and malware artifacts, and write a forensic report.

    Skills: Volatility, Memory forensics, Evidence handling

    Why it stands out: high

  12. Zero Trust Architecture Design Document

    intermediate · 6-8 hours

    Design a zero trust architecture for a hybrid workforce, including identity, device, network, and application pillars, with a deployment roadmap.

    Skills: Zero trust, Architecture design, Technical writing

    Why it stands out: medium

Advanced Projects (15–30 hours each)

Tackle complex, multi-component projects that demonstrate deep expertise and end-to-end security engineering.

  1. Build a Mini SOC with Wazuh and TheHive

    advanced · 20-30 hours

    Deploy Wazuh for endpoint detection, TheHive for case management, and integrate them to automate alert creation and response workflows.

    Skills: SOC operations, Wazuh, TheHive, Automation

    Why it stands out: excellent

  2. Red Team vs Blue Team Home Lab

    advanced · 25-30 hours

    Set up an isolated lab with Kali and Windows targets, simulate an APT attack, and document detection and response from the blue team perspective.

    Skills: Red teaming, Blue teaming, Lab design

    Why it stands out: excellent

  3. Cloud Incident Response Simulation on AWS

    advanced · 15-20 hours

    Simulate a compromised AWS account, investigate CloudTrail and GuardDuty findings, and produce an IR report with containment and recovery steps.

    Skills: Cloud IR, AWS CloudTrail, GuardDuty

    Why it stands out: excellent

  4. Custom SIEM Detection Rules for MITRE ATT&CK

    advanced · 20-25 hours

    Map 10 MITRE ATT&CK techniques to Splunk detection rules, test them with Atomic Red Team, and document coverage and false positives.

    Skills: Detection engineering, MITRE ATT&CK, Atomic Red Team

    Why it stands out: excellent

  5. Full Web App Pentest with Custom Exploit Development

    advanced · 25-30 hours

    Conduct a full pentest against a custom vulnerable app, develop a working exploit for a novel vulnerability, and present a professional report.

    Skills: Exploit development, Pentesting, Reporting

    Why it stands out: excellent

  6. Secure Software Development Lifecycle (SSDLC) Implementation

    advanced · 15-20 hours

    Create an SSDLC policy, integrate SAST/DAST into a CI/CD pipeline, and demonstrate a vulnerability being caught and fixed.

    Skills: SSDLC, CI/CD security, SAST/DAST

    Why it stands out: high

  7. Threat Modeling for a Microservices Application

    advanced · 15-18 hours

    Perform STRIDE threat modeling on a microservices architecture, produce a threat model, and propose mitigations with a risk matrix.

    Skills: Threat modeling, STRIDE, Risk assessment

    Why it stands out: high

  8. Cryptographic Protocol Analysis with ProVerif

    advanced · 20-25 hours

    Model and analyze a custom authentication protocol in ProVerif, identify vulnerabilities, and propose a fixed version with formal verification.

    Skills: Formal methods, Cryptography, Protocol analysis

    Why it stands out: excellent

Your Portfolio Is Your Proof of Work

  • Create a dedicated portfolio site with project summaries, links to GitHub, and downloadable reports.
  • For each project, state the problem, your approach, tools used, and measurable outcomes.
  • Include a 'Skills Matrix' mapping projects to job requirements (e.g., SIEM, pentesting, cloud).
  • Showcase at least one end-to-end project that covers detection, response, and remediation.
  • Regularly update your portfolio with new CTF writeups and lab experiments to show continuous learning.

Tips that make the difference

  • Always sanitize and anonymize data before publishing writeups; use lab environments or public datasets.
  • Record short video walkthroughs of your projects to demonstrate tool proficiency and communication skills.
  • Link each project to a specific framework (NIST, MITRE ATT&CK, OWASP) to show industry alignment.
  • Include a 'lessons learned' section in every writeup to highlight critical thinking and growth.
  • Version control everything, scripts, reports, and configs, on GitHub with clear READMEs.
  • Contribute to open-source security tools or CTF platforms to build a public track record.

Ready to Build Your Cybersecurity Portfolio?

Start any of these projects on Edirae, track your progress, and share your work with a community of learners and mentors.

Start learning free