This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.
|
01 — WEB SECURITY Application Security API Security Authentication Browser Security Security Controls |
02 — NETWORK SECURITY Reconnaissance Protocol Security Enterprise Networks Traffic Analysis Detection |
03 — MALWARE & RE Malware Analysis Reverse Engineering Binary Analysis Behavioural Research Detection |
04 — IoT & EMBEDDED Firmware Wireless Protocols CAN / MQTT / BLE ICS / SCADA Hardware Security |
05 — CLOUD SECURITY AWS / Azure / GCP IAM Containers Kubernetes DevSecOps |
|
|
||||
|
06 — HUMAN SECURITY OSINT Phishing Research Social Engineering Security Awareness Synthetic Media |
07 — CRYPTOGRAPHY Modern Cryptography Post-Quantum Privacy Zero-Knowledge Steganography |
08 — MOBILE SECURITY Android iOS Mobile APIs Telecom Security Application Security |
09 — AI SECURITY Adversarial ML LLM Security Prompt Injection AI Agents Security Automation |
10 — DFIR Disk Forensics Memory Analysis Network Forensics Incident Response Evidence Analysis |
The ten domains are not independent subjects.
They intersect through systems, networks, applications, human behaviour, computation, and evidence.
HIDDEN RESEARCH
│
┌───────────────────────┼───────────────────────┐
│ │ │
SYSTEMS NETWORKS HUMAN
│ │ │
OS · Runtime Protocols Identity
Binary · Memory Traffic Behaviour
│ │ │
└───────────────────────┼───────────────────────┘
│
▼
SECURITY RESEARCH
│
┌───────────────────┼───────────────────┐
│ │ │
OFFENSE ANALYSIS DEFENSE
│ │ │
Assessment Reverse Eng. Detection
Exploitation Forensics Response
Adversarial Behaviour Hardening
│ │ │
└───────────────────┼───────────────────┘
│
▼
AI & AUTOMATION
│
▼
NEW QUESTIONS
│
▼
RESEARCH
01 FOUNDATION
Programming · Linux · Networking · Security Fundamentals
│
▼
02 APPLICATION
Web · Network · System · Cloud · Mobile Security
│
▼
03 SPECIALIZATION
Malware · Reverse Engineering · IoT · Cryptography · DFIR
│
▼
04 EXPERIMENTATION
AI Security · Detection · Automation · Adversarial Research
│
▼
05 RESEARCH
Hypothesis → Experiment → Evidence → Analysis → Findings
│
└──────────────→ New Question
145 PROJECTS · 10 DOMAINS · 3 YEARS
The objective is not to collect techniques.
The objective is to understand the systems those techniques operate against. After nearly three years of research across multiple areas of cybersecurity, involving technical papers, research articles, journals, reviews, and practical experimentation, I have compiled these 140 cybersecurity project ideas with carefully considered development timelines.
I believe this collection is sufficient to build a serious cybersecurity portfolio and, more importantly, to develop the practical depth required to pursue a professional career in cybersecurity. However, I want to make one point absolutely clear: these projects are not designed to make anyone look skilled on paper. They are designed to make you actually skilled.
I personally attempted to work through these projects, and I failed more than 20 times across different projects. Those failures were not wasted time. They forced me to understand why systems behave the way they do, where security assumptions break, how attacks actually work, and how an attacker thinks when there is no convenient tutorial telling you what to do next.
In the current AI era, almost everything can be made to look easy. A model can generate code, explain an exploit, design an architecture, troubleshoot an error, or provide a seemingly complete solution within seconds. That convenience is useful, but it can also destroy the learning process if you depend on it too early.
My strongest recommendation is simple: build these projects without AI assistance until you have genuinely struggled with them.
Read the documentation. Study the papers. Break your own implementations. Debug your own mistakes. Build something that fails. Find out why it failed. Rebuild it. Repeat.
That process is where cybersecurity is actually learned.