01. AWS_CLOUD_INFRA
Basic Secret Management with Secrets Manager and Lambda
VerifiedA hands-on project retrieving a database secret in a Lambda function using AWS Secrets Manager and the Parameters and Secrets Lambda Extension, with local caching
Website Delivery with Cloudfront
VerifiedHow to use Cloudfront to deliver a Website globally
Building a Virtual Private Cloud in AWS
VerifiedHow to create a Virtual Private Cloud in AWS
Cloud Security with AWS IAM
VerifiedA deep dive into securing AWS resources using Identity and Access Management (IAM) policies and roles.
Encrypt Data with AWS KMS
VerifiedA hands on project that demonstrates how to use encryption and AWS KMS with DynamoDB
02. AZURE_SECURITY_OPS
Zero Trust / Conditional Access Policy Design
VerifiedFive Conditional Access policies and an Intune compliance policy, validated with Entra's What If tool and exported via Microsoft Graph PowerShell
Sentinel Analytics Rule & Automated Response
VerifiedDetection logic converted into a live Sentinel analytics rule with entity mapping and MITRE ATT&CK technique mapping
Sentinel Risk-Tiered Geo Map
VerifiedMicrosoft Sentinel workbook that geolocates and risk-scores Azure control-plane changes by caller IP
Threat Hunt & Incident Report — NPT-WS01
VerifiedFull intrusion investigation in Microsoft Defender Advanced Hunting using KQL, documented as a NIST SP 800-61 incident report with MITRE ATT&CK mapping and containment plan