Skip to main content
SSSAM Academy
SSSAM AcademyCyber Security with AI
Applied Capstone Portfolio • Real-World Scenarios

Real-World Cyber Security with AI Capstone Projects

Translate conceptual learning into demonstrable technical capability. Complete scenario-based capstone projects spanning incident response forensics, web vulnerability auditing, Linux bastion hardening, and AI threat summarization.

SOC Incident ForensicsOWASP Web AuditingLinux HardeningAI Log Triage Pipeline
Portfolio Architecture

How Capstone Projects Are Structured

Our projects are modeled after standard workplace security challenges, demanding structured investigation, tool orchestration, and technical reporting.

01

Enterprise Problem Statement

Receive a detailed operational briefing mimicking a corporate incident: anomalous traffic traces, vulnerable services, or unvetted cloud permissions.

02

Independent Tool Execution

Apply toolchains independently: correlate logs in Splunk, decode packet payloads in Wireshark, audit configurations, and script automated triage routines in Python.

03

Defensive Portfolio Artifact

Deliver actionable artifacts: formal Incident Response Reports, hardened server scripts, and detection rules that substantiate your technical capabilities during interviews.

Academic Transparency: These capstone projects are guided educational scenarios conducted in controlled lab environments. They build verifiable practical competence and technical artifacts without promising employment or specific hiring outcomes.
Capstone Scenarios

4 Comprehensive Practical Capstone Projects

Explore the multi-phase educational capstones students execute to demonstrate their command of network defense, web testing, server hardening, and AI SecOps.

#01SOC Defense~25 Hours

Enterprise SOC Incident Response & Packet Forensics

Investigate a simulated multi-stage cyber breach across network packet captures and endpoint event logs, identify the attacker entry vector, and author an executive containment report.

Enterprise Scenario Context:

A simulated e-commerce enterprise observes anomalous outbound data transfers on its database gateway. Students receive a 500MB PCAP file and endpoint event logs to reconstruct the attack timeline.

Technical Toolchain:
WiresharkZeekSplunk / SysmonTcpdumpPython
Project Execution Phases:
1

Network Packet Triage

Analyze network packet streams in Wireshark to isolate anomalous beaconing and decode payload headers.

2

Endpoint Log Correlation

Correlate Windows Event 4688 process creation logs with Sysmon telemetry to trace lateral command execution.

3

Incident Containment & Reporting

Document the complete kill chain according to MITRE ATT&CK guidelines and write remediation steps.

Student Deliverable Artifact:

Executive Incident Investigation Report (PDF) with IoC list, Snort detection rules, and remediation plan.

Demonstrated Practical Competencies:
  • Packet inspection in Wireshark
  • SIEM event log query formulation
  • MITRE ATT&CK kill-chain mapping
  • Technical incident report documentation
#02Ethical Hacking~20 Hours

Web Application Security Audit & Mitigation Guide

Perform an authorized security assessment on an isolated simulated banking portal, audit parameters against OWASP Top 10 vulnerabilities, and provide defensive code mitigations.

Enterprise Scenario Context:

An educational lab web application with deliberate misconfigurations requires an authorized vulnerability review before simulated production release. Students audit authentication and input handlers.

Technical Toolchain:
Burp Suite CommunityOWASP ZAPNmapSQLMap (Safe Mode)Browser DevTools
Project Execution Phases:
1

Reconnaissance & Service Mapping

Map web application endpoints, hidden directories, and API parameters using proxy interception.

2

Vulnerability Testing & Proof-of-Concept

Safely test input fields for SQL injection, Cross-Site Scripting (XSS), and Broken Object-Level Authorization.

3

Remediation Architecture

Formulate defense strategies including input validation, parameterized database queries, and Content Security Policies.

Student Deliverable Artifact:

Comprehensive Vulnerability Assessment Report detailing identified risks, CVSS scores, and exact code mitigations.

Demonstrated Practical Competencies:
  • Burp Suite proxy request tampering
  • OWASP Top 10 vulnerability identification
  • CVSS risk severity rating calculation
  • Defensive security recommendation authoring
#03System Hardening~18 Hours

Linux Bastion Host Hardening & Automated Compliance Audit

Harden a default Linux server into a secure bastion host, configure firewall rules and auditd policies, and author an automated bash verification script.

Enterprise Scenario Context:

A fresh cloud server must be configured as a hardened entry gateway. Students configure least-privilege user access, enforce SSH key authentication, and establish continuous configuration compliance auditing.

Technical Toolchain:
Linux CLI (Ubuntu/Debian)Iptables / UFWOpenSSHAuditdBash Scripting
Project Execution Phases:
1

Baseline Server Hardening

Disable root SSH password access, enforce ed25519 key authentication, and remove unnecessary running services.

2

Firewall & Audit Logging Setup

Configure strict host firewall rules and deploy auditd rules to track modifications to critical system files (/etc/passwd, /etc/shadow).

3

Automated Compliance Script

Author a bash script that automatically audits file permissions, open ports, and SUID binaries against CIS Benchmarks.

Student Deliverable Artifact:

Custom Bash Security Audit Script (.sh) + Hardened Server Configuration Guide + Baseline Audit Log Archive.

Demonstrated Practical Competencies:
  • Linux CLI system administration
  • SSH bastion architecture and key security
  • Host-based firewall access control lists
  • Automated bash shell scripting for security audits
#04AI Threat Defense~22 Hours

AI-Augmented Threat Intelligence & Log Summarization Pipeline

Design an automated workflow utilizing AI prompts and Python parsing scripts to process raw firewall and web proxy logs, correlate threat indicators, and generate prioritized briefings.

Enterprise Scenario Context:

A security team is overwhelmed by 50,000+ daily firewall denial events. Students build an AI-assisted pipeline that groups similar telemetry patterns and correlates external malicious IP lists without hallucination.

Technical Toolchain:
PythonOpenAI / Local LLM APIsRegexSyslogThreat Intelligence Feeds (AbuseIPDB/AlienVault)
Project Execution Phases:
1

Telemetry Pre-Processing

Parse raw log files using Python regex to extract source IPs, requested URLs, and error codes into structured JSON.

2

Prompt Engineering & Correlation

Craft structured zero-shot and few-shot security prompts to summarize incident severity and filter benign anomalies.

3

Prompt Guardrail Verification

Evaluate the pipeline against adversarial prompt injection attempts hidden inside malicious log payloads (e.g., User-Agent strings).

Student Deliverable Artifact:

Functional Python Log Triage Pipeline Script + Sample Automated Threat Briefing + Guardrail Hardening Documentation.

Demonstrated Practical Competencies:
  • Python data parsing for security logs
  • Prompt engineering for SecOps log summarization
  • Threat intelligence IOC enrichment
  • Indirect prompt injection defense techniques
Portfolio Consultation

Build a Demonstrable Cybersecurity Project Portfolio

Employers evaluate hands-on technical problem solving, not passive certificates. Attend a free demo session to see how students build and document real investigation portfolios with active practitioner mentorship.

Learn how capstone scenarios prepare you for entry-level SOC & testing roles
Test our browser cloud sandboxes and Gurugram workstation setups
100% free technical session with zero upfront commitment
Free Technical Demo

Reserve Your Capstone Demo Seat

Select your preferred mode: Live Online across India or Sector 14 Gurugram Classroom.

10 digits
🇮🇳 +91
60+ Guided Labs•No Upfront Fee•Mentor-Led