Hands-On Practice
Lab Archive
Browse the practical exercises, experiments, and technical write-ups from the lab work.
October 2026
Verify Message Integrity and Channel Authorization with Synthetic Fixtures
Run a no-send acceptance check for a multi-channel assistant and verify that authorised owner actions pass while forged origins, ambiguous identities, routing errors, and ordering failures are rejected.
Tabletop-Test an Incident Response Plan
Run a small fictional ransomware tabletop using a response plan, asset information, contacts, a timeline, and a post-exercise gap list.
Build a CSIRT and SOC Escalation Handoff
Practise moving one simulated alert from L1 triage through deeper investigation, technical leadership, coordination, and management reporting while preserving evidence and uncertainty.
Triage a Training Packet Capture with Wireshark
Open a supplied sample.pcap file, isolate a candidate conversation, inspect Ethernet/IP/TCP/SSH fields, and record observations without claiming intent from one packet.
Threat Model a Sneaker Marketplace with PASTA
The seven PASTA stages applied to a fictional sneaker marketplace app: objectives, data flows and trust boundaries, two threats, attack paths, controls and what to log.
Write an Incident Handler Journal Entry
A structured incident record for a training ransomware scenario at a small clinic: who, what, when, where and why, plus the questions that still need evidence.
Building a Status Importer That Rejects Stale Data and Unproven Completion Claims
A local importer that accepts only the metadata a status brief needs, rejects stale or content-bearing records, and will not claim work is done without an artifact.
September 2026
Requiring Confirmation Before a Voice Command Starts an Agent Job
A local confirmation gate that treats a voice transcription as untrusted and starts an agent job only after the owner confirms the exact proposal.
Building a Status Record That Holds No Message Content and Expires
A strict status record for tasks that stores metadata only, rejects stale or malformed entries, and never counts as proof of completion.
Checking a Config Change Actually Reached the Running Service
Compares the wanted setting with the running process's environment, its log and its status endpoint, showing that a changed file alone proves nothing.
Letting Automation Add a Calendar Event Only When the Message Proves It
A fixture-driven pipeline that writes a calendar event only when the source message supports the date, time and action.
Reviewing an Agent Tool Bundle for Least Privilege
Reviews the tools an inbound messaging agent can actually use and removes the ones that are unnecessary or hold credentials.
Testing an AI Agent's Final Message, Not Its First Draft
Builds a local test harness that judges what an AI agent would finally send after tool calls, filtering and rewriting, instead of the model's first output.
Assessing a Found USB Drive Without Plugging It In
Google Cybersecurity Certificate exercise: assessing a found USB drive as a data-leak and malware risk without connecting it.
Reviewing a Payroll Change Through Access-Control Evidence
Google Cybersecurity Certificate worksheet: analysing a simulated payroll change, what the logs prove about who made it, and which access controls failed.
Proving Two Identical-Looking Files Are Not the Same File
Google Cybersecurity Certificate activity: using sha256sum and cmp to show that two files which look identical are different.
Decrypting a Caesar Cipher and an AES-256 File in Linux
Google Cybersecurity Certificate activity: finding and decrypting a Caesar-cipher file, then using OpenSSL to decrypt an AES-256 file.
Completing a SQL Join for a Security Incident Investigation
Google Cybersecurity Certificate activity: INNER, LEFT and RIGHT joins across machines, employees and login attempts to investigate an incident.
SQL Time-Window Filtering for Authentication Triage
Turning an authentication or patching question into SQL filters on dates, times and IDs, based on Google Cybersecurity Certificate material.
Verifying a Local-Only HTTP Service Cannot Be Reached or Misused
Builds a toy HTTP service meant to be reachable only from the same machine and to run one fixed action, then attacks those assumptions.
Verifying an Encrypted Backup Restore Safely
Checks that an encrypted backup really restores: restore to an isolated location, inspect it, and avoid starting a second live copy.
August 2026
Testing an Agent Relay That Refuses Stale or Replayed Messages
Tests the integrity checks in a local relay between agents, using fixtures only, so old or repeated messages are refused.
Allowing Exactly One Reply per Incoming Message
A small authorization pattern for automation that messages people: each incoming message permits one short-lived reply to one destination.
Building a Minimal Adversarial Test Harness for a Chat Persona
A script that sends the same adversarial prompt to a chatbot many times, measures how often the answer changes, and scores what it reveals about itself.
SELECT, FROM, and ORDER BY for Login-Activity Review
Google Cybersecurity Certificate activity: basic SELECT and FROM queries, with ORDER BY to put login events in time order.
Filtering SQL Queries with WHERE and LIKE
Google Cybersecurity Certificate activity: narrowing SQL results with WHERE and LIKE to the records a security task needs.
Building and Breaking an SSRF-Safe Fetch Guard
Builds a small guard that stops a program fetching internal addresses, then attacks it the way two real bypasses were found.
July 2026
Finding Linux Commands with Built-in Help
Using Linux's built-in help to find out what a command and its options do before making a system change.
Extracting Text from a Local HTML File Safely
Pulls readable text out of a local HTML file while keeping the operation narrow and easy to inspect.
Assessing a Candidate Tool Before Adoption
A security-first review of a third-party command-line tool before installing it: its source, permissions, what it keeps, and how to remove it.
Isolating Parallel Agents with Git Worktrees
Uses git worktrees so several automated agents can work on one repository at once without touching each other's files.
Testing Safe File Delivery: Expiring Links and Hash Checks
Tests the checks behind handing over a task's output file safely: single-purpose expiring links, hash verification and revocation.
Auditing What an AI Agent Is Given to Read Before It Acts
Treats the text handed to an AI agent as security-relevant input: checks where each piece came from and that the total stays within set limits.
Investigating a False-Positive Alert in a Verification Script
Handling a noisy alert from my own tooling: reproduce it, find why it fires, narrow it, and keep a test so real problems are still caught.
Linux User and Group Management for Access Control
Creating and removing Linux users and groups and assigning ownership, from a security analyst's point of view.
February 2026
Endpoint Process Chain Triage with Pipe-Delimited Logs and awk
SOC-style triage of a synthetic process-creation log, using Linux pipelines and awk to trace which process started which.
HTTP in Practice (Pentester POV)
How a browser proves who it is and what the server trusts: sessions, cookies and headers, studied on real requests rather than exploited.
Real SUID Behavior: Scripts vs Binaries
Tests how the SUID bit really behaves on a modern Linux system, and why it works on binaries but not on scripts.
Linux Permissions & Ownership Hands-On Practice
Hands-on practice changing file permissions and ownership on Linux, and reading who can access what.