Toronto, ON · Open to work

Ebube Nnaemeka

Junior Systems Administrator · SOC Analyst · IT Administrator

I build and run the infrastructure, then attack it and check that the defences catch it. I work across Active Directory, PowerShell automation, monitoring and Splunk detection, and every project is documented in public on GitHub.

01 About

I'm breaking into IT and cybersecurity in Toronto, aiming for junior systems administrator, IT administrator and SOC analyst roles.

Instead of only studying for certifications, I'm building a homelab that follows the whole job: set up a Windows domain, automate the routine admin, monitor it, then simulate real attacker techniques and tune detections until they fire. Each project has its scripts, configs and write-ups in its own repository.

  • FocusSysadmin → SOC
  • LocationToronto, ON
  • EducationAdv. Diploma, Accounting · Seneca Polytechnic
  • Portfolio8 homelab projects
  • FrameworkMITRE ATT&CK

02 Skills

Systems administration

  • Windows Server 2022
  • Active Directory
  • Group Policy
  • DNS
  • DHCP
  • Windows 10/11
  • Linux

Security operations

  • Splunk / SPL
  • Sysmon
  • Windows Event Logs
  • Security Onion
  • Zeek
  • Suricata
  • MITRE ATT&CK
  • Atomic Red Team

Vulnerability management

  • OpenVAS / GVM
  • Nessus Essentials
  • CVSS
  • Nmap
  • Kali Linux

Automation & monitoring

  • PowerShell
  • Ansible
  • Bash
  • Docker
  • Zabbix
  • Git

03 Projects

Eight connected homelab projects. The Active Directory lab is the base that the monitoring, automation, SIEM and purple team labs build on.

01Sysadmin

Active Directory Enterprise Lab

A two-domain-controller Windows Server 2022 forest with AD-integrated DNS and DHCP, modelled on a mid-size company: departmental OUs with delegated rights, bulk user provisioning from CSV with PowerShell, and Group Policy for password baselines, drive mappings and software restriction.

  • Windows Server 2022
  • AD DS
  • GPO
  • PowerShell
View repository ↗
02SOC

SIEM Detection Engineering Lab

Windows Event Log and Sysmon telemetry forwarded into Splunk, with custom SPL detections for brute force (T1110), PsExec lateral movement (T1021.002) and encoded PowerShell (T1059.001). Each rule has notes on false-positive sources and a triage step.

  • Splunk
  • SPL
  • Sysmon
  • ATT&CK
View repository ↗
03SOC

Purple Team Lab

Runs real attacker techniques against the AD lab with Atomic Red Team: Kerberoasting (T1558.003), LSASS credential dumping (T1003.001) and encoded PowerShell. It then checks whether the Splunk detections fire and adds new rules where there are gaps.

  • Atomic Red Team
  • Kerberoasting
  • Splunk
View repository ↗
04SOC

Security Onion NSM

Network security monitoring with Zeek, Suricata and Kibana, covering what's visible on the wire rather than on the host. Traffic generated in the lab (port scans, beaconing) is triaged and written up in an analyst log.

  • Security Onion
  • Zeek
  • Suricata
View repository ↗
05Sysadmin

IT Automation Scripts

PowerShell tools for patch-compliance reports, audits of disabled accounts that still hold group memberships, and stale computer object cleanup (dry-run by default), plus an Ansible playbook for mixed Windows/Linux patch inventory.

  • PowerShell
  • Ansible
  • AD auditing
View repository ↗
06SOC

Malware Analysis Write-ups

Static and dynamic analysis of public samples in an isolated, snapshotted sandbox VM. Each write-up covers PE inspection, process, registry and network behaviour, extracted IOCs and a MITRE ATT&CK mapping.

  • PEStudio
  • ProcMon
  • Wireshark
  • IOCs
View repository ↗
07SOC

Vulnerability Assessment Lab

The full vulnerability management cycle against intentionally vulnerable targets: OpenVAS scanning, manual verification, and a report with CVSS-scored findings and prioritized remediation, compared across DVWA security levels.

  • OpenVAS
  • Nessus
  • CVSS
  • DVWA
View repository ↗
08Sysadmin

Infrastructure Monitoring Lab

Zabbix deployed in Docker to watch the domain controllers and endpoints, with triggers for AD DS, DNS and DHCP service failure, low disk space, sustained high CPU and unreachable hosts.

  • Zabbix
  • Docker
  • Alerting
View repository ↗

04 Contact

I'm looking for entry-level sysadmin, IT admin and SOC analyst roles in the Greater Toronto Area. Happy to walk through any of these labs.