Featured

20 God-Tier Cybersecurity Projects That Will Get You Hired

Thanks! Share it with your friends!

You disliked this video. Thanks for the feedback!

Added by McDan
8 Views
Get started learning cybersecurity with an emphasis on cloud: https://madhat.io

Join the Mad Hat discord: https://discord.com/invite/BUzZY2sR4J

Stop building generic cybersecurity projects that recruiters ignore. Learn how to create technical projects that prove your skills.

1. Home SIEM + writeup
Full SOC build (Wazuh + Suricata + pfSense + Sysmon, PDF guide): https://github.com/marxgoo/Wazuh-SOC-Lab
Beginner OVA walkthrough w/ screenshots: https://github.com/UsmanPrime/Wazuh-Setup
Official docs: https://documentation.wazuh.com

2. Contribute a detection rule to SigmaHQ
The repo + CONTRIBUTING guide: https://github.com/SigmaHQ/sigma
Contributing checklist: https://sigmahq.io/docs/digging-deeper/contributing.html
Rule Creation Guide: https://github.com/SigmaHQ/sigma/wiki/Rule-Creation-Guide

3. Honeypot + dashboard
Cowrie + Wazuh integration: https://medium.com/@maryamliaqat4583/building-a-cowrie-ssh-honeypot-with-wazuh-integration-a-hands-on-soc-lab-guide-d89b2430076d
T-Pot all-in-one platform guide: https://github.com/telekom-security/tpotce
Cowrie official: https://github.com/cowrie/cowrie

4. Portfolio site
Github…
Build your own…
I made a silly video on it: https://youtu.be/81NguENBjws

5. Reverse-engineer malware → YARA/Sigma rule
Ghidra (official, NSA): https://github.com/NationalSecurityAgency/ghidra
YARA docs: yara.readthedocs.io

6. Phishing email analysis lab
TryHackMe Phishing rooms (part of SOC L1 path)
[Standard project — point to any current "analyze phishing headers" walkthrough; low risk]

7. Detection-as-Code (rules in Git + CI/CD)
Quick Guide: https://blog.runreveal.com/runreveal-detection-cicd-guide/

8. LLM prompt-injection / red-team ✅ strongest resource set
Official tool: https://github.com/NVIDIA/garak
Beginner repo: https://github.com/chinmayajoshi/LLM-Red-Teaming-with-Garak
Tool comparison (Promptfoo/PyRIT/Garak): https://bestaiweb.ai
OWASP LLM Top 10: https://genai.owasp.org

9. STIX/TAXII threat-intel automation
My old video on it: https://youtu.be/f7k1FWMC8g4
MISP (official): https://github.com/MISP/MISP
OpenCTI (official): https://github.com/OpenCTI-Platform/opencti

10. From-scratch security tool

11. Cloud misconfiguration hunt (CSPM)
Prowler (open-source CSPM, AWS/Azure/GCP): github.com/prowler-cloud/prowler
ScoutSuite: github.com/nccgroup/ScoutSuite

12. Least-privilege IAM design
Mad Hat Labs...idk I'll find some more.

13. GRC gap assessment
NIST CSF 2.0 (official): nist.gov/cyberframework

14. Active Directory attack-and-defend
GOAD (Game of Active Directory, open-source vulnerable lab): https://github.com/Orange-Cyberdefense/GOAD
HackTheBox or TryHackMe AD paths

15. OAuth consent-phishing in Entra ID ⚠️ your wheelhouse — hardest to find a clean guide

16. Network traffic / C2 in PCAP
Malware-Traffic-Analysis.net (real PCAP exercises): https://malware-traffic-analysis.net
Wireshark official: https://wireshark.org

17. IR playbook + tabletop
CISA tabletop exercise packages (official, free): https://cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
Incident response playbook templates: https://github.com/counteractive/incident-response-plan-template

18. Build your own vuln scanner
Check out my previous video for inspiration: https://youtu.be/I9rvl-x0RQI

19. SOAR automation playbook
Tines (free Community edition, has templates): https://tines.com
Shuffle (open-source SOAR): https://github.com/Shuffle/Shuffle

20. Responsible disclosure
HackerOne / Bugcrowd disclosure guidelines:
https://www.hackerone.com/terms/disclosure-guidelines
https://docs.bugcrowd.com/researchers/disclosure/disclosure/
Disclose IO (responsible disclosure framework + templates): https://disclose.io


Most tutorials lead to cookie-cutter portfolios that offer zero competitive advantage. This video breaks down how to select cybersecurity projects that actually demonstrate practical, high-value skills. We focus on technical depth to help you stand out during hiring processes.We assess specific project types including LLM prompt injection and network analysis to determine their real-world hireability. You will learn how to evaluate if a project is worth your time or just busy work. We also cover the practical application of SigmaHQ rules and malware analysis to ensure your work aligns with industry standards.By filtering out low-effort tutorials, you can focus on building a cybersecurity portfolio that highlights your problem-solving abilities. Use this guide to prioritize projects that provide tangible evidence of your technical expertise to potential employers.Subscribe for cybersecurity career advise and breakdowns and comment which project topic you might want to see a full tutorial on.
Category
Cybersecurity
Tags
joma tech, programmer, tech lead

Post your comment

Comments

Be the first to comment