Project Hall

Projects

Cybersecurity labs, infrastructure builds, app development, and portfolio work organized in an app-style project dashboard.

Total Projects7
Active Builds6
FocusSecurity / Infrastructure / Dev

Categories

Graduate Research • In Progress

Master’s Thesis — Network Segmentation & Credential-Based Lateral Movement

ResearchActive DirectoryOPNsenseSecurity OnionGRC
Featured Project

This controlled technical study evaluates whether VLAN-based segmentation and least-privilege inter-VLAN firewall rules reduce credential-based lateral movement in a simulated municipal Active Directory environment while maintaining useful monitoring visibility.

Thesis lab architecture comparing flat and segmented network designs

Research Question

To what extent does VLAN-based network segmentation with least-privilege inter-VLAN access control reduce successful credential-based lateral movement compared with a flatter network design in a controlled Active Directory cyber range?

Current Status

  • Research scope and technical direction defined
  • Existing Red, Blue, Victim, and infrastructure lab being documented
  • Security Onion, Zeek, and Suricata visibility being validated
  • Experiment run sheet and evidence structure in development

Study Design

  • Baseline condition: a flatter network with broader reachability between selected systems.
  • Experimental condition: segmented VLANs with explicit least-privilege OPNsense rules.
  • Attack scenario: controlled credential-based lateral movement, including Pass-the-Hash where appropriate.
  • Primary measurements: reachable services, successful and blocked movement attempts, detection outcome, alert timing, and detection latency.
  • Repetition: multiple standardized runs under each condition using restored snapshots and documented procedures.

Technical Environment

  • Proxmox virtualization hosts and isolated virtual machines
  • Windows Server Active Directory and Windows 11 victim endpoints
  • OPNsense routing, VLANs, firewall rules, and trust boundaries
  • Security Onion with Zeek and Suricata monitoring
  • Kali Linux / Red Team system for controlled testing
  • Windows event logs, network telemetry, and packet evidence

Evidence Collected

  • Experiment run records and timestamps
  • Firewall allow/deny evidence
  • Security Onion alerts and Hunt results
  • Zeek connection and protocol logs
  • Suricata detections and metadata
  • Windows authentication and security events
  • Screenshots, diagrams, and configuration excerpts

Supplemental GRC & Security Program

This companion security program uses the same controlled environment and evidence to connect technical testing with governance, risk management, incident response, security operations, resilience, compliance mapping, and assurance.

Foundation & Architecture

  • Project charter, organization profile, scope, assumptions, and boundaries
  • VM and network asset inventory
  • Current-state flat network diagram
  • Target segmented network diagram
  • System categorization and data-classification matrix
  • Business impact analysis for core services

Risk Management

  • Risk-assessment methodology and scoring scales
  • Risk register with treatment and residual-risk fields
  • Risk treatment plan
  • NIST CSF 2.0 current and target profile
  • Risk-acceptance and security-exception forms

Governance Policies & Standards

  • Information Security Policy
  • Network Segmentation Standard
  • Access Control Policy
  • Logging and Monitoring Standard
  • Vulnerability and Patch Management Standard
  • Change Management Procedure and change-ticket template
  • Backup and Recovery Policy

Incident Response

  • Incident Response Plan
  • Incident severity, declaration, roles, escalation, and notification matrix
  • Evidence-handling procedure and chain-of-custody form
  • Credential Theft and Lateral Movement Playbook
  • Containment, eradication, recovery, timeline, and lessons-learned templates

Security Operations

  • Security Onion alert-triage procedure
  • Zeek, Suricata, Windows, and OPNsense investigation guide
  • Alert-severity matrix
  • Detection use-case catalog
  • Daily and weekly monitoring checklists
  • False-positive log and case-management template

Testing & Assurance

  • Security test plan and rules of engagement
  • Test-case matrix, pretest checklist, and evidence log
  • Pilot-trial summary and deviation records
  • Findings register and POA&M/corrective-action tracker
  • Control-effectiveness assessment
  • Retest report and final residual-risk decisions

Business Continuity & Disaster Recovery

  • Combined Business Continuity and Disaster Recovery Plan
  • RTO/RPO worksheet and recovery-priority matrix
  • Backup schedule and restoration checklist
  • Backup-testing procedure and recovery-test report
  • Credential-compromise tabletop exercise and after-action report
  • Incident and continuity communications plan

Compliance & Control Mapping

  • NIST CSF 2.0 profile and gap summary
  • NIST SP 800-53 and CIS Controls crosswalk
  • NIST SP 800-61 incident-response cross-reference
  • NIST SP 800-207 least-privilege design cross-reference
  • CJIS Security Policy considerations memo
  • Control implementation and evidence-status tracking

Final Assessment & Portfolio

  • Main repeated-trial evidence set
  • Executive security assessment report
  • Final risk register and treatment decisions
  • Sanitized findings, diagrams, metrics, and selected evidence
  • Website case study and downloadable portfolio artifacts

Core GRC Documents

Project Charter & ScopePDF • Organization profile, assumptions, boundaries, and objectives Asset InventoryXLSX • Systems, network assets, criticality, and recovery priority Architecture DiagramsPDF • Flat and segmented network designs Classification MatrixXLSX • System categorization and data classification Business Impact AnalysisXLSX • Service impact, dependencies, and recovery priorities Risk MethodologyPDF • Likelihood, impact, scoring, and treatment criteria Risk Register & Treatment PlanXLSX • Inherent risk, controls, treatment, and residual risk NIST CSF 2.0 ProfileXLSX • Current state, target state, gaps, and priorities Information Security PolicyPDF • Top-level security requirements Network Segmentation StandardPDF • Allowed flows, prohibited flows, logging, and exceptions Access Control PolicyPDF • Least privilege, administrative access, and account controls Logging & Monitoring StandardPDF • Data sources, retention, review, and detection requirements Incident Response PlanPDF • Roles, phases, escalation, evidence, and recovery Incident Governance MatrixXLSX • Severity, declaration, roles, escalation, and notification Evidence Handling & Chain of CustodyPDF • Evidence identifiers, preservation, hashes, and custody records Credential Theft & Lateral Movement PlaybookPDF • Detect, validate, contain, eradicate, recover, and review Incident Response Template PackDOCX • Containment, recovery, timeline, and lessons learned Security Onion Triage ProcedurePDF • Alert validation, enrichment, escalation, and closure Investigation GuidePDF • Zeek, Suricata, Windows, and OPNsense workflows Detection Use-Case CatalogXLSX • Logic, data sources, severity, response, and false positives Security Test Plan & Rules of EngagementPDF • Authorized scope, procedures, controls, and boundaries Test & Evidence WorkbookXLSX • Test cases, readiness, runs, and evidence log Pilot Trial SummaryPDF • Repeatability, deviations, visibility, and reset validation Findings & POA&MXLSX • Findings, remediation, owners, due dates, and status Business Continuity & DR PlanPDF • Continuity strategy and technical restoration BC/DR WorkbookXLSX • RTO/RPO, recovery priority, backup schedule, and restoration Control CrosswalkXLSX • NIST SP 800-53 and CIS Controls mapping Control-Effectiveness AssessmentPDF • Baseline versus segmented control results Retest ReportPDF • Corrective-action validation and finding disposition Executive Security AssessmentPDF • Risks, results, limitations, and recommendations

Results & Findings

This section will present validated findings from repeated testing, including reachable-service counts, successful versus blocked attempts, alert coverage, and detection-latency comparisons.

Limitations & Ethical Boundaries

  • All testing occurs in an isolated, controlled cyber range.
  • No production organization, employee, resident, or real municipal network is used as a research subject.
  • Results apply to the defined lab design, tools, configurations, and attack scenarios.
projects-thesis-grc-clean-final.html HTML Library / Thesis / projects-with-masters-thesis.html