Personal Project
A deliberately vulnerable LLM-enabled Flask application, built to demonstrate a real cross-user data leakage vulnerability class and then measure three progressively stronger defenses against it: identity trust, context isolation, input risk inspection, output redaction, and structured security logging. The vulnerable baseline is preserved unmodified so the 'before' stays real and reproducible; the defended modes are implemented alongside it, not in place of it, so the same attack set can be replayed against all three and compared directly.
Outcome: Unauthorized cross-user disclosure measured at 25% under the original vulnerable baseline, dropping to 0% once context isolation is added (Partial Defense) -- the full Defense-in-Depth mode adds pre-model risk-based blocking, output redaction, and resolves identity from a server-side session token rather than a client-declared field, which is what stops a separate identity-spoofing (IDOR) vector the first two modes both leave open.
- Unauthorized disclosure rate -- Vulnerable Baseline:
- 25% (3/12 adversarial cases)
- Unauthorized disclosure rate -- Partial Defense (context isolation only):
- 0% (0/12 adversarial cases)
- Unauthorized disclosure rate -- Defense in Depth:
- 0% (0/12 adversarial cases)
- Identity-spoofing (IDOR) case blocked:
- Only Defense in Depth (1/1); Baseline and Partial Defense both allow it
- Adversarial requests blocked before reaching the model -- Defense in Depth:
- 33% (4/12)
View repository →Academic Project
A threat intelligence project classifying malware samples by their associated Advanced Persistent Threat (APT) groups using opcode-based analysis. Workflow: Dataset Creation (extracted and cleaned opcode text from malware samples, mapped each to its corresponding APT group, building a structured dataset of file hashes, APT labels, and opcode text features); Feature Engineering (converted opcode sequences into numerical features using unigram and bigram representations); Model Training (trained and compared multiple classifiers -- Support Vector Machine, K-Nearest Neighbours, and Decision Tree); Evaluation (assessed performance using accuracy, precision, recall, F1-score, and confusion matrices); and a Threat Intelligence Focus exploring how malware behaviour patterns can support attribution and help analysts connect samples to known adversary groups.
Outcome: Reinforced the applied value of machine learning in cyber threat intelligence -- malware triage, pattern recognition, and early-stage attribution support.
Academic Lab
A hands-on lab series covering exploit development, reconnaissance, vulnerability assessment, exploitation, post-exploitation, authentication attacks, man-in-the-middle simulation, and web application security testing in a controlled VM lab. Exploit Development Basics: used GDB to inspect vulnerable programs, analyze memory behavior, and understand buffer overflow/logic-bypass outcomes. Reconnaissance and Enumeration: Maltego, Nmap, and Wireshark for DNS enumeration, host discovery, OS detection, and packet capture analysis. Vulnerability Assessment: OpenVAS/GVM and Nessus scans against Windows targets, with before/after comparison across system and firewall changes. Exploitation and Post-Exploitation: privilege escalation, process migration, persistence testing, hash dumping, and event log analysis in Windows lab environments. Authentication Attacks: Metasploit/Meterpreter, Kiwi, Cain & Abel, John the Ripper, Hashcat, and Hydra. Network Attack Simulation: Ettercap for ARP poisoning, DNS spoofing, and traffic redirection. Web Application Security Testing: SQL injection, authentication bypass, UNION-based extraction, XSS, CSRF, and IDOR-style access-control weaknesses against vulnerable web applications.
Academic Lab
Lighthouse Labs Cybersecurity Program — Applied Projects
Applied projects from a Cyber Security diploma program: role-played incident-response scenarios; a digital forensics project using EnCase and Autopsy; a security architecture project for a simulated mid-sized e-commerce company intending to accept card payments (PCI DSS compliance scope); an application security project using DAST, IAST, SAST, and SCA; and work with cryptanalysis tools (Crypto SMT, ARX Toolkit, ISEA). Final program project: investigating a simulated ransomware attack at a fictional company ('Premium Lighthouse') and producing prevention recommendations.
Personal Project
My Developer Portfolio (Feb–Dec 2025, personal project): the previous version of this portfolio site (github.com/Azubikeamala/My-Portfolio) -- a React + Tailwind CSS site with animated backgrounds and smooth scrolling, deployed via Vercel.
Osita.pro – Wonder World for Kids (Jul–Dec 2025, personal project): an interactive children's learning/play site (React + Tailwind CSS, hosted on Vercel) with categories including Math Missions, Craft Lab, Story Time, and Brain Boosters.
Car Tracker App (Apr 2025, Conestoga group project): a Framework7 + Firebase web app for tracking car purchase plans in real time, with Email/Password and Google OAuth 2.0 authentication and Firebase Realtime Database sync. Live demo: car-tracker-3aeb5.web.app.
Healthy Eating App (Jan–Apr 2025, Conestoga group project): a full-stack meal-planning app (React/Tailwind frontend, Django/PostgreSQL backend) with categorized recipes, downloadable CSV meal plans/shopping lists, and an AI-powered support chatbot. Hosted at healthyeating.help.
Password Hashing and Secure Credential Storage Demonstration (Jan–Apr 2026, University of Guelph coursework): a presentation and demo covering password hashing, hash function properties, login verification, and data-breach protection in real-world authentication systems.
Commercial Product
QuickHalo
Commercial SaaS product for service businesses, focused on automating customer retention and recurring-service engagement: automated service reminders, customer follow-up, appointment/booking flows, recurring-customer engagement, and AI-assisted customer interactions.