Hazvinei Nomatter Masiya

Enterprise IT Professional β†’ Cybersecurity Β· Security Operations Β· Detection & Automation
Enterprise IT Professional | CompTIA Security+ | Google Cybersecurity
πŸ“ Harare, Zimbabwe πŸ“§ Contact via LinkedIn πŸ“ž +263 77 521 6823 / +263 71 866 2162

Enterprise IT professional with 12+ years of enterprise IT infrastructure experience, deliberately transitioning into cybersecurity. Hands-on cybersecurity capability is demonstrated through independent, authorized labs in Wazuh SIEM, detection engineering, incident investigation, DFIR, Windows/Sysmon telemetry, network security, cloud security, and automation. The portfolio clearly separates professional IT experience from independent security work.

12+ years supporting Windows/Linux environments, infrastructure, Active Directory, endpoint security, system hardening and business-critical IT operations β€” now applying that foundation to detection engineering, incident response, threat hunting, digital forensics and security automation.

Evidence Hubs

Focused entry points for recruiters and technical reviewers. Each hub links directly to source evidence in the repository and preserves the portfolio's evidence-scope standard.

Technical Projects & Artifacts

PCAP Traffic & Triage Automation

Synthetic Lab
⚑ Automated PCAP Traffic Analysis

Captured packet traffic using tshark to analyze automated web scans, SQL injection payloads, and command execution attempts. Engineered custom Python scripts for automated triage.

ARTIFACT // PCAP_PARSER.PY
MITRE T1190
$ python3 pcap_triage.py --file capture.pcap [+] Extracting HTTP POST payloads... [!] ALERT: SQLi Payload Detected: ' OR 1=1 -- [!] Source IP: 192.168.1.105 -> Targeted Port: 8080
Wireshark/Tshark Python Network Forensics

Linux Incident Response & DFIR

Observed Evidence
🎯 Reconstructed Attack Timeline from Linux System Logs

Executed deep forensic triage on compromised Linux system logs. Verified SHA-256 evidence hashes, mapped actor techniques to MITRE ATT&CK, and produced post-incident timelines.

ARTIFACT // AUTH.LOG_ANALYSIS
MITRE T1078
# sha256sum /var/log/auth.log e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 [+] Root session established via SSH key from 10.0.4.12
Linux DFIR Syslog Audit MITRE ATT&CK

Wazuh SIEM Rules & FIM Lab

Synthetic Lab
πŸ›‘οΈ Custom Wazuh Rules Validated Against Test Events

Deployed Wazuh agents across lab nodes. Authored custom XML detection rules to flag privilege escalation and established File Integrity Monitoring (FIM) for system directories.

ARTIFACT // WAZUH_LOCAL_RULES.XML
MITRE T1548
<rule id="100002" level="10"> <if_sid>5715</if_sid> <match>sudo: privilege escalation</match> <description>Possible privilege escalation alert</description> </rule>
Wazuh SIEM XML Rules FIM

Splunk SOC Lab Track

Synthetic Lab
πŸ“Š Six Connected SOC Labs Β· SPL Detection & Investigation

Completed a six-lab Splunk SOC track covering SSH authentication hunting, Windows/Sysmon process investigation, web-attack investigation, SPL detection engineering, SOC monitoring/dashboarding, and end-to-end incident investigation using controlled synthetic telemetry.

Splunk SPL SOC Investigation Detection Engineering

AD Security Event Automation

Observed Evidence
πŸ” Automated Parsing of Event 4728 & 4625 XML Security Logs

Automated parsing of Windows Security XML event logs (4624, 4625, 4728) using Python to highlight lateral movement, brute force attempts, and unauthorized group escalation.

ARTIFACT // AD_PARSER.PY
MITRE T1098
$ python3 ad_triage.py --event 4728 [!] PRIVILEGE ESCALATION DETECTED User 'jdoe' added target 'Domain Admins' Caller User: 'bad_actor_admin'
Active Directory Python Automation Windows Security

GCP Secure Landing Zone

IaC / DESIGN
πŸ”’ Org-Wide External-IP Deny + Deny-All-Ingress VPC β€” IaC

Real Terraform for a GCP organization landing zone: org-level policy guardrails (no external IPs, no SA key files, domain-restricted IAM), an environment folder structure, a Shared VPC host project with deny-all-ingress firewall rules and Cloud NAT, and a centralized org-wide logging sink. Formatting-checked with terraform fmt; full validate/apply pending a real org (this build environment can't reach the Terraform registry).

Org Policy Shared VPC Org Logging
GCP Terraform Landing Zone

Attack Simulation & Detection Engineering Lab

Live Lab Evidence
🎯 6 of 6 Technique/Platform Combinations β€” Live Validation on Self-Owned Lab Targets

3 real MITRE ATT&CK techniques (Execution T1059, Persistence T1053/T1547, Credential Access T1003), each written to run against 2 real, self-owned targets: the home-lab Linux host and the Azure Windows Server DC documented elsewhere in this portfolio. All 6 technique/platform combinations have preserved live-alert evidence from authorized tests against self-owned Linux and Windows lab targets. The evidence is lab validation, not client or production infrastructure.

MITRE ATT&CK Wazuh Detection Engineering

Azure Windows Server Security Lab

Observed Evidence
πŸ”’ RDP Locked to a Single Admin IP β€” No Open Ingress

Terraform-provisioned Windows Server 2022 VM in Azure with a default-deny NSG, no committed secrets, and daily auto-shutdown for cost control. Deployed, promoted to an AD Domain Controller (lab.local), hardened, and validated end-to-end: 409 real Security events exported and analyzed for 392 findings, plus a live Wazuh Agent connection generating real MITRE-mapped alerts.

Admin IP NSG (3389) Win Server DC
Terraform Azure Active Directory PowerShell

Linux Host Hardening Audit

Observed Evidence
🐧 0 Findings β€” All 26 SUID Binaries Individually Verified

CIS-benchmark-style Python audit engine (SSH config, sudoers NOPASSWD scope, SUID binaries, world-writable files, legacy services, firewall state), validated first against synthetic fixtures, then run for real against a live personal Linux host via a purpose-built collector script.

Real Host CIS Checks 0
Linux Hardening CIS Benchmark Python

Container Configuration Security Audit

Observed Evidence
🐳 14 Findings Across 8 Real Running Containers

CIS Docker Benchmark / MITRE ATT&CK for Containers-style Python audit engine (root user, unpinned tags, hardcoded secrets, privileged mode, docker.sock mounts, host network mode), validated first against synthetic fixtures, then run for real against a home-lab Docker host via a docker inspect-based collector that redacts every env value before it touches disk.

8 Containers CIS Checks 14
Docker Security CIS Benchmark MITRE ATT&CK

Nmap Network Reconnaissance

Observed Evidence
πŸ”Ž 13 Open Ports Found on a Full 65535-Port Scan

Full TCP port range scan (-sV -sC -p-) against the analyst's own home-lab host, with raw output preserved in all three Nmap formats. An unrecognized service fingerprint on port 9443 was independently verified with curl/ss rather than assumed, revealing Portainer exposed on every network interface instead of scoped like the stack's other services.

65535 Ports -sV -sC 13
Nmap Network Recon T1046

Wireshark Packet Analysis

Observed Evidence
πŸ•΅οΈ Real SQLi Test Captured and Correctly Flagged

Real tcpdump capture (52 packets) of the analyst's own Juice Shop container, including a genuine test of its known SQL-injection-vulnerable search endpoint. Analyzed with this portfolio's existing pcap_soc_analyzer.py, previously validated only against synthetic data - it correctly flagged the real SQLi request (HIGH) while correctly declining to flag a weaker scanner-UA signal alone.

52 Packets SOC Analyzer 1
Wireshark/TShark Packet Analysis SOC Triage

Static Application Security Testing

Observed Evidence
πŸ” Real Scan, Real Fix, Honest Triage

Real bandit static analysis scan of this portfolio's own 1,278-line Python codebase - not a fictional target. Found and fixed one genuine High-severity issue (unnecessary shell=True command execution). Remaining findings triaged honestly: one confirmed scanner false positive, one documented defense-in-depth recommendation, and low-risk findings reviewed and accepted rather than blindly cleared.

Bandit SAST Secure Code Review

Windows Sysmon Telemetry Engineering

Observed Evidence
πŸ‘οΈ Real Sysmon Telemetry: 16 Events, 5 Findings

Installed Sysmon (SwiftOnSecurity config) on a live, deployed Azure Domain Controller and captured real process-create (Event ID 1) and network-connect (Event ID 3) telemetry, validated against the same detection logic used on synthetic data.

ARTIFACT // SYSMON_CONFIG.XML
MITRE T1055
<ProcessAccess onmatch="include"> <TargetImage condition="is">C:\Windows\System32\lsass.exe</TargetImage> </ProcessAccess>
Sysmon Threat Hunting Endpoint Defense

Virtual Job Simulations

Practical cybersecurity simulations completed through Forage. These are virtual work experiences, not employment, and are presented as evidence of applied learning and professional skills.

Forage β€’ Virtual Experience 1–2 hours

Mastercard β€” Cybersecurity

Security Awareness-focused simulation completed as a Security Analyst scenario, including phishing simulation design and interpretation of phishing-simulation results.

CybersecurityPhishingSecurity AwarenessData AnalysisSecurity TrainingProblem Solving
Forage β€’ Virtual Experience 3–4 hours

Datacom β€” Cyber Security Operations

Cybersecurity operations simulation covering cyberattack impact analysis and cybersecurity risk assessment, with emphasis on threat research, risk prioritization and actionable recommendations.

Risk AssessmentRisk ManagementThreat AnalysisOSINTInformation SecurityResearch
Portfolio evidence

Certificates and original work products can be linked here once published. Only completed work and verifiable evidence should be presented.

Public GitHub Projects

Loading synchronized GitHub projects…

Core Competencies

SIEM & Detection

  • Wazuh & Splunk/SPL Detection
  • Sysmon XML Rules
  • Log Triage Automation
  • File Integrity Monitoring
  • Custom Alert Pipelines

DFIR & Hunting

  • Linux Auth/Syslog Forensics
  • PCAP Packet Triage
  • Hash & Integrity Audits
  • MITRE Framework Mapping

Infrastructure

  • Active Directory & GPO
  • Dell Versa SD-WAN
  • Sophos XG & Endpoint
  • Windows Server Admin

Engineering

  • Python IOC Parsers
  • Terraform (GCP & Azure) IaC
  • Bash & PowerShell Scripts
  • Cloud VPC Isolation

Certifications & Education

SY0-701

CompTIA Security+

Core Security Standards

Google Professional

Google Cybersecurity

SOC & Defensive Tools

Google Professional

Google IT Support

Systems & Networking

Unicaf University

BSc Computer Science (In Progress)

Undergraduate Degree

Get In Touch

Targeting SOC Analyst, Security Operations Analyst, Cybersecurity Analyst, Detection Engineering, Threat Hunting, and Security Engineering opportunities.