Gutema Dube

Projects

A selection of real-world and hands-on projects spanning threat hunting, security engineering, platform implementation, governance, and automation. These projects reflect work done in production environments, structured training programs, and independent learning, all built to solve real problems.

Real-World Projects

Log4Shell (CVE-2021-44228) — Full Threat Investigation and Remediation Program

Identified Log4Shell exposure as an active risk requiring immediate investigation. Custom KQL queries were independently built to silently hunt exposure across a live production environment, layered with enough depth and precision to surface not just exposed devices but the full picture, including device status, user context, physical location, folder paths including hidden directories, and environmental details that standard scans would miss. A formal remediation project was designed and coordinated in collaboration with system administrators, tracking progress across all devices and driving every item to verified closure. Outcomes were documented and shared with the broader IT team to strengthen security baselines and runbooks.

NIST CSF Security Governance Framework

Developed and matured a comprehensive security governance program in collaboration with IT leadership, building a structured framework aligned to NIST CSF and NIST 800-53. Work included a technology risk register, vendor risk tracking with risk-based scoring across all major applications, security policy documentation, and supporting compliance documentation. The resulting governance process continues to evolve with each review cycle, providing the organization with measurable, defensible security outcomes.

Vendor Risk Management Program

Recognized third-party risk as a gap requiring a structured response and developed a vendor risk management program in collaboration with IT and leadership to bring visibility and control across the organization. A custom risk-based tracking process was built without relying on third-party GRC tooling, keeping the solution practical and cost-effective. A risk scoring methodology was established to evaluate all major vendors across security, compliance, data handling, and support continuity dimensions, with fully documented workflows, scoring criteria, and escalation procedures supporting HIPAA, FERPA, and NIST CSF requirements.

Conditional Access Hardening — Privileged Account MFA Enforcement

Recognized a critical gap in Microsoft Entra ID Conditional Access policies where MFA was only required for admin accounts outside the on-premises network, leaving privileged accounts vulnerable to identity-based attacks from any location. Working with IT leadership to align on scope and approach, a hardened Conditional Access policy was redesigned and implemented requiring MFA for all administrative accounts regardless of location, network, or device, covering all critical admin roles. Precise exclusion logic was configured for emergency break-glass accounts to maintain operational continuity, and extending the same enforcement to standard user accounts was proposed to further strengthen the organization's identity security posture.

Red Canary MDR and Entra ID Identity Protection Integration

Recognized a gap in identity threat coverage where MDR and identity protection were operating independently without correlation. Conceived and initiated the integration of Red Canary MDR with Microsoft Entra ID Identity Protection, enabling identity-based threat signals to flow directly into MDR detection and response workflows. Configured in close collaboration with the Red Canary security team and internal sysadmins. Following the integration, implemented automated IR playbook automation including token session revocation and additional response actions categorized by incident type and severity, validated across identity-based attack scenarios in the production environment.

KQL Threat Hunting Query Library

Recognized the need for a proactive, silent threat hunting capability that went beyond automated alerts. A custom KQL query library was designed, developed, and maintained within Microsoft Defender XDR and the Microsoft unified security platform to proactively hunt threats and identity risks across the environment. Queries are deliberately run manually rather than automated, enabling silent analyst-driven investigation without alerting potential threat actors. The library covers suspicious and impossible sign-in detection, geographic and behavioral anomaly identification, monitoring of specific IP addresses and malicious domains on a daily basis prior to escalating security concerns, risky user and device identification, accounts without MFA enforcement, inactive but still-enabled accounts, failed authentication pattern analysis, privilege escalation attempts, lateral movement indicators, anomalous admin account activity, and Entra ID sign-in and audit log analysis. All queries are documented and organized as reusable templates. Findings consistently inform targeted remediation efforts coordinated with the broader IT team.

Cloud App Security and App Governance Implementation

Recognized that Microsoft Defender for Cloud Apps and App Governance, both available within the organization's existing licensing, had not yet been fully enabled or configured. A full production deployment was designed and implemented in collaboration with IT, including OAuth app discovery and governance, complete cloud app visibility, and App Governance policy configuration. The initiative gave the organization comprehensive visibility into all cloud applications, OAuth permissions, and third-party app integrations, enabling detection, governance, and control of shadow cloud apps and risky OAuth consents.

Google Workspace DLP and Data Protection Implementation

Recognized a risk around uncontrolled sharing of personally identifiable and sensitive information through Google Workspace collaboration and communication tools. Designed and configured DLP policies using a tiered enforcement approach, ranging from sender warnings that prompt verification to full blocking depending on the sensitivity level of the content. Validated policy effectiveness in the production environment and documented configurations to support ongoing data protection governance.

Active Directory and Entra ID Security Audit and Hardening

Comprehensive Active Directory and Entra ID cloud identity audits were conducted across multiple organizations, surfacing security gaps including passwordless service accounts, improperly configured admin accounts, stale staff accounts, and misconfigured cloud identity settings. Formal password policies aligned with security best practices and NIST guidelines were developed and proposed to leadership. Working directly with sysadmins, findings were remediated by properly managing accounts and admin privileges to strengthen the identity environment and reduce attack surface.

Identity Incident Response Process Design

Developed and formalized a comprehensive identity-focused incident response framework in collaboration with IT leadership, covering account compromise, unauthorized access, privilege escalation, and identity-based attack scenarios. The framework includes detailed IR workflows, escalation paths, and decision trees supported by formal process diagrams and written documentation. The resulting procedures improved response speed and consistency across IT and security teams by establishing clear, repeatable steps for handling identity-related incidents.

Tabletop Exercise Architecture and Facilitation

Tabletop exercises were architected and facilitated in close collaboration with district leadership, using real-world risk scenarios relevant to the organization to drive executive awareness and cross-functional engagement. Teams worked through structured incident response workflows, and outcomes were translated into concrete remediation actions and governance improvements. The exercises elevated cybersecurity awareness across leadership and the broader IT team, reinforcing a shared culture of security accountability.

Shadow IT Discovery and Governance Program

Identified shadow IT as a risk difficult to detect through traditional scanning alone. Designed and executed a structured discovery program in collaboration with IT leadership to surface undocumented technology in active use across the organization. Documented technology usage, authentication methods, MFA status, vendor contacts, and support plans for all findings. Identified several unreviewed tools including one no longer maintained by its vendor. Delivered a formal findings report with prioritized remediation recommendations to leadership.

Least Privilege and Privileged Identity Management Initiative

Recognized that end users held excessive local access rights and that external consultants carried privileges well beyond what their roles required. A comprehensive remediation strategy was proposed and designed in collaboration with IT leadership, implementing Least Privilege Access enforcement, Privileged Identity Management (PIM), and Role-Based Access Control (RBAC) processes. Existing infrastructure was leveraged to deliver the solution without additional tooling costs. Access was restructured to align with least privilege principles, critical ownership was transferred to internal staff, and a proper break-glass emergency account architecture was put in place.

Incident IQ — Full Platform Implementation

Recognized the absence of a formal IT service management platform and delivered a complete Incident IQ implementation through close collaboration with IT colleagues and leadership. The project encompassed system installation, custom ticket categories and workflows, asset management setup and tagging, location and site structure configuration, user roles and permissions, Active Directory and SSO integration, MDM integration, SIS integration, third-party communication platform integration, asset inventory migration, reporting dashboards, and ongoing support. The result was a fully operational, organization-wide ITSM platform built to fit the environment.

Personal Cybersecurity Portfolio Website

Recognized the need for a professional online presence that reflects the depth of work being done. A complete personal cybersecurity portfolio website was independently designed, developed, and published from scratch using web technologies, hosted on GitHub Pages with a custom domain at gutemadube.com. DNS records were configured, HTTPS was enabled, and GitHub repositories were integrated as a live project showcase. The site serves as a professional portfolio, resume delivery platform, and personal brand hub.

Cloud Security Governance Modernization — WGU B.S. Cloud Computing Capstone

A complete enterprise cloud security governance solution designed as the B.S. Cloud Computing capstone at Western Governors University. Spans architecture, compliance, stakeholder analysis, threat modeling, implementation planning, testing, and post-implementation operations. Grounded in the same security thinking applied in production. Available upon request for qualified employers and professional purposes.

Learning and Training Projects

Spear Phishing Simulation — End-to-End Attack Lifecycle | BootCon Capstone

Designed and executed a complete end-to-end spear phishing simulation as the cybersecurity bootcamp capstone, covering OSINT reconnaissance, social engineering, attack chain development, credential harvesting, payload delivery, and post-exploitation access. Executed in a controlled lab environment, validated the full attack lifecycle from target profiling through credential harvest, and documented the complete methodology and defensive recommendations. Presented at BootCon Cybersecurity Capstone, March 2025.

Personal Cybersecurity Home Lab

A personal cybersecurity lab environment is actively maintained with multiple virtual machines configured for realistic attack and defense practice. The lab supports hands-on work across network traffic analysis, SIEM monitoring and threat detection, network reconnaissance, OSINT research, vulnerability scanning, and offensive security concepts. The environment enables continuous practice reinforcing and extending skills applied in professional environments.

Splunk Security Monitoring and Threat Detection

Splunk foundational training was completed and hands-on skills were applied across multiple security projects including log monitoring, search query development, threat detection workflows, and dashboard creation. Independent practice continues through personal home lab use, building strong familiarity with Splunk search processing language, alert configuration, and security event correlation.

Linux Server Security Baseline Script

Recognized the need for a repeatable, documented security baseline process for Linux server deployments. A Bash-based script was developed to perform system inventory collection, OS backup, configuration auditing, access control enforcement, and compliance report generation in a single run. Tested across multiple Linux distributions and designed as a hardening baseline for newly provisioned servers.

Windows System Health and Compliance Audit

Recognized the need for automated compliance visibility across Windows endpoints. A PowerShell-based enterprise compliance audit script was developed to scan endpoints for outdated OS versions, missing updates, and compliance drift. Configurations are checked against customizable security baselines, structured reports are generated, and automated alerts are sent when non-compliant systems are detected. Fully customizable via a single configuration block with no code changes required for most deployments.

Automated AD User Provisioning and Security Validation

Recognized the need for a reliable, auditable automation solution for enterprise user provisioning and client data management. A PowerShell automation script was developed integrating Active Directory user provisioning, SQL database population, structured logging, input validation, privilege verification before execution, domain connectivity validation, and full exception handling with execution reporting. Each run is tracked with a unique identifier for full traceability. Managed via GitLab with documented version control.