Building 70 Projects ranging from beginner to advanced so anyone can — learn from, build upon, use as a reference, or even copy directly. Gamified Cybersecurity learning 👇
Go to file
CarterPerez-dev 8b2d5a4487 fix: use PAT_TOKEN for submodule update workflow 2026-01-25 11:37:10 -05:00
.github fix: use PAT_TOKEN for submodule update workflow 2026-01-25 11:37:10 -05:00
PROJECTS Merge pull request #42 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/encrypted-p2p-chat/frontend/npm-dependencies-47062081b4 2026-01-23 15:45:47 -05:00
SYNOPSES yo yo you should star the repo :) pls 2025-11-12 08:05:27 -05:00
templates chore: update fullstack-template submodule to latest 2025-12-24 07:42:11 -05:00
.gitignore feat: add caesar-cipher project implemenation 2026-01-22 03:30:08 -05:00
.gitmodules add full stack template submodule 2025-12-09 03:25:56 -05:00
.pre-commit-config.yaml yapf 2025-11-12 15:33:54 -05:00
.style.yapf Create .style.yapf 2025-12-31 09:06:04 -05:00
CHANGELOG.rst Update CHANGELOG.rst 2025-12-31 09:49:24 -05:00
CODE_OF_CONDUCT.md Add Contributor Covenant Code of Conduct 2025-12-09 09:33:18 -05:00
CONTRIBUTING.md Update CONTRIBUTING.md 2025-12-31 09:43:26 -05:00
LICENSE update Makefiles to Justfiles, switch to uv, add helpful documentation 2026-01-01 01:32:07 -05:00
README.md Update project links and descriptions in README 2026-01-22 03:38:23 -05:00
SECURITY.md Create SECURITY.md 2025-12-09 09:36:58 -05:00

README.md

Kali-dragon-icon svg

Cybersecurity Projects 🐉

60 Cybersecurity Projects, Certification Roadmaps & Resources

stars forks issues license
projects resources

View Complete Projects:


Table of Contents

Big thanks to the current contributors! ❤️


Projects


Beginner Projects

SOURCE CODE: Simple Port Scanner

Asynchronous TCP port scanner in C++ using boost::asio for concurrent port scanning with configurable ranges and timeouts. Implements service detection through banner grabbing and demonstrates async I/O patterns with TCP socket programming.

SOURCE CODE: Keylogger

Use Python's pynput library to capture keyboard events and log them to a local file with timestamps. Include a toggle key (like F12) to start/stop logging. Important: Add clear disclaimers and only test on systems you own.

SOURCE CODE: Caesar Cipher

Create a CLI tool that shifts characters by a specified number (the "key") to encrypt/decrypt text. Implement both encryption and brute-force decryption (try all 26 possible shifts). Bonus: Add support for preserving spaces and punctuation.

SOURCE CODE: DNS Lookup CLI Tool

Use Python's dnspython library to query different DNS record types (A, AAAA, MX, TXT, NS, CNAME). Display results in a clean table format with color coding using rich and typer libraries. Add reverse DNS lookup functionality and WHOIS.

Simple Vulnerability Scanner

Build a script that checks installed software versions against a CVE database or uses pip-audit for Python packages. Parse system package managers (apt, yum, brew) to list installed software. Flag packages with known vulnerabilities and suggest updates.

SOURCE CODE: Metadata Scrubber Tool

CLI tool that removes privacy sensitive metadata (EXIF, GPS, author info) from images, PDFs, and Office documents using concurrent batch processing. Features read/scrub/verify commands with rich terminal output, supports dry-run previews, and generates detailed comparison reports showing exactly what metadata was removed.

Network Traffic Analyzer

Use scapy to capture packets on local network and display protocol distribution, top talkers, and bandwidth usage. Filter by protocol (HTTP, DNS, TCP, UDP) and visualize data with simple bar charts. Add export to CSV functionality.

Hash Cracker

Build a basic hash cracking tool that attempts to match MD5/SHA1/SHA256 hashes against wordlists. Implement both dictionary and brute-force modes. Add salted hash support and performance metrics (hashes per second).

Steganography Tool

Hide secret messages inside image files using LSB (Least Significant Bit) steganography. Support PNG and BMP formats. Include both encoding and decoding functionality with password protection option.

MAC Address Spoofer

Create a script to change network interface MAC addresses on Linux/Windows. Include validation, backup of original MAC, and automatic restoration. Add vendor lookup to generate realistic MAC addresses.

File Integrity Monitor

Monitor specified directories for file changes using checksums (MD5/SHA256). Log all modifications, additions, and deletions with timestamps. Send alerts when critical system files are modified.

Security News Scraper

Scrape cybersecurity news from sites like Krebs on Security, The Hacker News, and Bleeping Computer. Parse articles, extract CVEs, and store in a database. Create a simple dashboard to view latest threats.

Phishing URL Detector

Analyze URLs for common phishing indicators (suspicious TLDs, typosquatting, URL shorteners). Check against safe browsing APIs (Google Safe Browsing). Display risk score with detailed analysis.

SSH Brute Force Detector

Monitor auth.log or secure log files for failed SSH login attempts. Detect brute force patterns and automatically add offending IPs to firewall rules. Send email alerts when attacks detected.

WiFi Network Scanner

Scan for nearby wireless networks and display SSIDs, signal strength, encryption types, and connected clients. Identify potentially rogue access points and weak encryption (WEP, WPA).

Base64 Encoder/Decoder

Create a tool that encodes/decodes Base64, Base32, and hex. Automatically detect encoding type. Add support for URL encoding and HTML entity encoding.

Firewall Log Parser

Parse firewall logs (iptables, UFW, pfSense) and generate reports on blocked connections. Identify top attacking IPs, most targeted ports, and attack patterns. Visualize with graphs.

ARP Spoofing Detector

Monitor network for ARP spoofing attacks by tracking MAC-to-IP mappings. Alert when duplicate IP addresses or MAC address changes detected. Log all ARP traffic for analysis.

Windows Registry Monitor

Track changes to Windows registry keys and values. Focus on common persistence locations (Run keys, Services, Scheduled Tasks). Alert on suspicious modifications.

Ransomware Simulator

Educational tool that demonstrates file encryption without actual harm. Encrypt test files in isolated directory with strong encryption. Include decryption capability and educational warnings.


Intermediate Projects

Reverse Shell Handler

Create a server that listens for incoming reverse shell connections using Python sockets. Implement command execution, file upload/download, and session management for multiple clients. Use cmd2 or similar library for a clean CLI interface.

SIEM Dashboard

Build a Flask/FastAPI backend that ingests logs via syslog or file parsing, then visualize with a React frontend using Chart.js or Recharts. Store events in SQLite/PostgreSQL and implement basic correlation rules (e.g., "5 failed logins in 1 minute"). Add filtering by severity, source IP, and time range.

Threat Intelligence Aggregator

Use APIs from threat feeds (AbuseIPDB, VirusTotal, AlienVault OTX) to collect IOCs (IPs, domains, file hashes). Store in a database with deduplication and enrich with WHOIS/geolocation data. Create a simple UI to search IOCs and view threat scores.

OAuth Token Analyzer

Build a tool that decodes JWT tokens, validates signatures, and checks for common vulnerabilities (weak secrets, algorithm confusion, expired claims). Use PyJWT or similar library and add support for multiple signature algorithms (HS256, RS256). Display token payload in formatted JSON with security warnings.

Web Vulnerability Scanner

Create an async Python scanner using httpx that crawls a target website and tests for XSS (reflected/stored), SQLi (error-based), and CSRF (missing tokens). Implement a plugin architecture so tests are modular and easy to add. Generate HTML reports with vulnerability details and remediation advice.

DDoS Mitigation Tool

Create a network monitor that detects traffic spikes using packet sniffing (Scapy) and implements rate limiting with iptables or similar. Add anomaly detection by establishing baseline traffic patterns. Include alerts via email/webhook when attacks detected.

Container Security Scanner

Scan Docker images by parsing Dockerfiles for insecure practices (running as root, hardcoded secrets) and checking base image versions against vulnerability databases. Use Docker API to inspect running containers for exposed ports and mounted volumes. Output findings in JSON with severity ratings.

SOURCE CODE: Full Stack API Security Scanner

Build an enterprise-grade automated API security scanner that performs deep vulnerability assessment across REST, GraphQL, and SOAP endpoints, detecting OWASP API Top 10 flaws through intelligent fuzzing, authentication bypass testing, broken object level authorization, mass assignment exploitation, and rate limiting analysis with ML-enhanced payload generation and comprehensive reporting dashboards. (FastAPI - React-Typescript - Vite - Nginx - Docker - CSS)

Wireless Deauth Detector

Monitor WiFi networks for deauthentication attacks using packet sniffing. Alert when abnormal deauth frames detected. Track affected clients and potential attacker locations.

Active Directory Enumeration

Enumerate AD users, groups, computers, and permissions using LDAP queries. Identify privileged accounts, stale accounts, and misconfigurations. Generate visual diagrams of AD structure.

Binary Analysis Tool

Disassemble executables and analyze for suspicious patterns. Extract strings, identify imported functions, and detect packing/obfuscation. Support PE, ELF, and Mach-O formats.

Network Intrusion Prevention

Real-time packet inspection using Snort rules or custom signatures. Automatically block malicious traffic using firewall integration. Dashboard for viewing blocked threats and rule management.

Password Policy Auditor

Audit Active Directory or local password policies against security best practices. Test for weak passwords using common patterns. Generate compliance reports and recommendations.

Cloud Asset Inventory

Automatically discover and catalog all resources across AWS, Azure, and GCP. Track changes over time, identify untagged resources, and calculate costs. Export to CSV/JSON.

OSINT Reconnaissance Framework

Aggregate data from public sources (WHOIS, DNS, social media, breached databases). Automate information gathering for penetration testing. Generate comprehensive target profiles.

SSL/TLS Certificate Scanner

Scan domains for SSL/TLS misconfigurations (expired certs, weak ciphers, missing HSTS). Check against best practices (Mozilla SSL Config). Alert on vulnerabilities like Heartbleed.

Mobile App Security Analyzer

Decompile Android APKs and iOS IPAs to analyze security. Detect hardcoded secrets, insecure data storage, and vulnerable libraries. Generate OWASP Mobile Top 10 compliance reports.

Backup Integrity Checker

Verify backup files aren't corrupted using checksums. Test restoration process automatically. Alert if backups fail validation or haven't run recently.

Web Application Firewall

Build a reverse proxy that filters HTTP requests for malicious patterns. Block SQL injection, XSS, and path traversal attempts. Include whitelist/blacklist rules and logging.

Privilege Escalation Finder

Analyze Linux/Windows systems for potential privilege escalation vectors. Check for SUID binaries, weak permissions, and kernel exploits. Generate attack path diagrams.

Network Baseline Monitor

Establish normal network behavior patterns (traffic volume, protocol distribution, top talkers). Alert on deviations that could indicate compromises or attacks.

SOURCE CODE: Docker Security Audit

Go CLI tool that scans Docker containers, images, Dockerfiles, and compose files for security misconfigurations. Checks against CIS Docker Benchmark v1.6.0 controls (privileged mode, dangerous capabilities, sensitive mounts, secrets in images, missing security profiles). Outputs findings with remediation guidance in terminal, JSON, SARIF, or JUnit formats.


Advanced Projects

SOURCE CODE: API Rate Limiter

Build middleware that implements token bucket or sliding window rate limiting for APIs. Support per-user, per-IP, and global limits. Include Redis backend for distributed rate limiting across multiple servers.

SOURCE CODE: Encrypted Chat Application

Build a real time encrypted chat using WebSockets with Signal Protocol encryption (X3DH key exchange + Double Ratchet) for forward secrecy and break-in recovery. Implement passwordless authentication via WebAuthn/Passkeys. Backend uses FastAPI with PostgreSQL, SurrealDB live queries, and Redis. SolidJS TypeScript frontend with nanostores and 8-bit retro design using TailwindCSS.

Exploit Development Framework

Build a modular framework in Python where exploits are plugins (one file per vulnerability). Include payload generators, shellcode encoders, and target validation. Implement a Metasploit-like interface with search, configure, and execute commands.

AI Threat Detection

Train a machine learning model (Random Forest or LSTM) on network traffic data (CICIDS2017 dataset) to classify normal vs. malicious behavior. Use feature engineering on packet metadata (packet size, timing, protocols). Deploy model with FastAPI for real-time inference on live traffic.

SOURCE CODE: Bug Bounty Platform

Create a web app with user roles (researchers, companies), vulnerability submission workflow, and reward management. Implement severity scoring (CVSS), status tracking, and encrypted communications. Use React frontend, FastAPI/Django backend, PostgreSQL database, and S3 for file uploads.

Cloud Security Posture Management

Build a tool using boto3 (AWS), Azure SDK, and Google Cloud SDK to scan for misconfigurations (public S3 buckets, overly permissive IAM roles, unencrypted storage). Implement compliance checks against CIS benchmarks. Generate executive dashboards showing risk scores and remediation priorities.

Malware Analysis Platform

Create a sandbox using Docker or VMs where suspicious files are executed in isolation while monitoring API calls, network traffic, and file system changes. Implement static analysis (strings, PE headers, YARA rules) and dynamic analysis (behavior tracking). Generate detailed reports with IOCs extracted.

Quantum Resistant Encryption

Implement post-quantum algorithms like Kyber (key exchange) or Dilithium (digital signatures) using existing libraries (liboqs-python). Build a file encryption tool that uses hybrid encryption (classical + quantum-resistant). Benchmark performance against traditional RSA/AES and document the security rationale.

Zero Day Vulnerability Scanner

Fuzzing framework that automatically discovers bugs in applications. Implement coverage-guided fuzzing using AFL or LibFuzzer. Triage crashes and generate proof-of-concept exploits.

Distributed Password Cracker

Coordinate password cracking across multiple machines using GPU acceleration. Support distributed workloads with job queuing. Dashboard for monitoring progress and performance.

Kernel Rootkit Detection

Detect kernel-level rootkits by comparing system calls, loaded modules, and memory structures. Use volatility framework for memory analysis. Alert on hidden processes or drivers.

Blockchain Smart Contract Auditor

Static analysis tool for Solidity smart contracts detecting vulnerabilities (reentrancy, integer overflow, access control). Integrate with Mythril and Slither. Generate security reports.

Adversarial ML Attacker

Generate adversarial examples to fool ML-based security systems. Implement attacks like FGSM, DeepFool, and C&W. Test robustness of image classifiers and malware detectors.

Advanced Persistent Threat Simulator

Simulate multi-stage APT attacks with C2 infrastructure, lateral movement, and data exfiltration. Support various persistence mechanisms and evasion techniques. Generate attack reports.

Hardware Security Module Emulator

Software emulation of HSM for cryptographic operations. Implement secure key storage, signing, and encryption. Support PKCS#11 interface for application integration.

Network Covert Channel

Exfiltrate data using DNS queries, ICMP packets, or HTTP headers. Implement encoding schemes to hide data in legitimate traffic. Measure detection rates against common DLP solutions.

Automated Penetration Testing

Orchestrate full penetration tests including reconnaissance, vulnerability scanning, exploitation, and post-exploitation. Generate executive and technical reports. Support multiple target types.

Supply Chain Security Analyzer

Analyze software dependencies for vulnerabilities and malicious packages. Detect typosquatting, dependency confusion, and compromised packages. Monitor for suspicious updates in CI/CD pipelines.


Certification Roadmap by Role

Certification Roadmaps By Role

1. SOC Analyst

Role

Level Certification Organization Link
Entry Security+ CompTIA Website
Core CySA+ CompTIA Website
Intermediate GCIH (Certified Incident Handler) GIAC Website
Intermediate CEH (Certified Ethical Hacker) EC-Council Website
Advanced GCIA (Certified Intrusion Analyst) GIAC Website
Senior/Management CISSP (ISC)² Website

2. Penetration Tester

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
Entry-Level Pentest PenTest+ CompTIA Website
Intermediate CEH (Certified Ethical Hacker) EC-Council Website
Advanced OSCP (Gold Standard) Offensive Security Website
Expert OSEP Offensive Security Website
Expert GXPN (Exploit Researcher) GIAC Website

3. Security Engineer

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
Intermediate CySA+ CompTIA Website
Advanced SecurityX (formerly CASP+) CompTIA Website
Advanced/Expert CISSP (ISC)² Website
Expert (Cloud-focused) CCSP (ISC)² Website

4. Incident Responder

Role

Level Certification Organization Link
Entry Security+ CompTIA Website
Core CySA+ CompTIA Website
Core IR Cert GCIH (Certified Incident Handler) GIAC Website
Forensics/Advanced GCFA (Certified Forensic Analyst) GIAC Website
Malware Analysis/Expert GREM (Reverse Engineering Malware) GIAC Website

5. Security Architect

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
Advanced SecurityX (formerly CASP+) CompTIA Website
Architect/Management CISSP (Required) (ISC)² Website
Cloud Architecture CCSP (ISC)² Website
Security Architecture Framework SABSA SABSA Institute Website
Enterprise Architecture TOGAF The Open Group Website

6. Cloud Security Engineer

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
AWS Cloud Security AWS Security Specialty AWS Website
Azure Cloud Security Azure Security Engineer Microsoft Website
Vendor-Neutral CCSK Cloud Security Alliance Website
Advanced CCSP (ISC)² Website
Advanced Practice SecurityX (formerly CASP+) CompTIA Website
Expert/Management CISSP (ISC)² Website

7. GRC Analyst/Consultant

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
Audit Focused CISA (Certified Information Systems Auditor) ISACA Website
Risk Management CRISC (Risk and Information Systems Control) ISACA Website
Advanced CISSP (ISC)² Website
Compliance-Heavy ISO 27001 Lead Auditor PECB (and others) Website

8. Threat Intelligence Analyst

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
Core CySA+ CompTIA Website
Cyber Threat Intelligence GCTI GIAC Website
Intrusion Analysis GCIA GIAC Website
OSINT (Optional) GOSI GIAC Website
OSINT (Optional) C|OSINT McAfee Institute Website

9. Application Security

Role

Level Certification Organization Link
Foundation Security+ CompTIA Website
Foundation/Core CEH (Certified Ethical Hacker) EC-Council Website
Foundation/Core CySA+ CompTIA Website
Secure Software Lifecycle CSSLP (ISC)² Website
Web App Exploitation OSWE Offensive Security Website
Web App Pentest GWAPT GIAC Website

10. Network Engineer (Security-Focused)

Role

Level Certification Organization Link
Foundation Network+ CompTIA Website
Foundation Security+ CompTIA Website
Associate CCNA (Cisco Certified Network Associate) Cisco Website
Advanced CCNP Security Cisco Website
Architect/Management CISSP (ISC)² Website

Cybersecurity Learning Resources

A collection of tools, courses, frameworks, and educational resources for cybersecurity professionals and learners at all levels.


Table of Contents


Cybersecurity Tools

Reconnaissance & Scanning

Web Application Testing

Network & Wireless

Exploitation & Post-Exploitation

Cryptography & Analysis

Forensics & Malware Analysis

Monitoring & Defense

Code Security

Intelligence & Recon


Study Platforms & Courses

Udemy CompTIA Courses

Udemy Other Security Courses

Free Learning Platforms

Premium Platforms


Certifications & Exam Prep

CompTIA Exam Objectives

Practice Test Resources

Exam Vouchers & Official Resources

Study Guides & Books


YouTube Channels & Videos

Top Cybersecurity Channels

Learning Science & Study Techniques

Practice Exam Videos


Reddit Communities

Main Subreddits

Certification-Specific Communities


Security Frameworks

NIST Framework Suite

ISO/IEC Standards

Industry Frameworks

Compliance & Regulatory

Analysis & Modeling


Industry Resources

Security News & Blogs

Training & Education Organizations

Professional Organizations

Development & Tools


Cloud Certifications

AWS Cloud

Microsoft Azure

Google Cloud

Other Cloud Platforms


CISSP Resources

Official Materials

Practice Tests & Prep

YouTube Courses

Study Resources


LinkedIn Professionals to Follow

Industry Leaders

Organizations


Additional Learning Resources

Specialized Platforms

Cheat Sheets & References


Last Updated: November 2025

Tips for Success:

  • Start with free resources to test your interest
  • Combine video courses with hands-on labs
  • Use practice exams to measure progress
  • Join communities for support and networking
  • Stay current with security news and trends