Cybersecurity Analyst

David J. Bianco Portfolio

Creator of the "Pyramid of Pain" threat-detection model and SANS network forensics instructor, publishing data-driven threat-hunting research such as an analysis of over 11 million VirusTotal malware samples testing whether hash-based detection actually works.

Threat HuntingPyramid of PainDetection ResearchSANS

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

A named, widely-adopted conceptual model

The Pyramid of Pain gives threat hunters and SOC teams a shared vocabulary for ranking indicators by how much pain they cause an attacker to change — a durable mental model has more lasting influence than any single incident writeup.

2

Hypothesis-driven research format

Posts are structured as an actual research process — hypothesis, dataset, analysis, conclusion — rather than opinion pieces, which is what makes an 11-million-sample VirusTotal analysis read as investigation rather than commentary.

3

Quantified findings instead of qualitative claims

Reporting an exact figure (91.81% of files submitted by a single submitter) to support a conclusion about hash-based detection is concrete and falsifiable in a way "hash detection often fails" is not.

What Cybersecurity Analysts can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • If you have a recurring insight in your field, try naming it as a model or framework — a named concept spreads and gets cited in ways a buried blog post doesn't.

  • Structure technical posts like actual research — state the hypothesis, show the dataset, then the conclusion — rather than presenting a bare opinion.

  • Back claims with an actual measured number wherever you can, even an approximate one; a specific figure is more credible and more memorable than a qualitative claim.

Ready to build your portfolio?

Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.

Cybersecurity Analyst Roadmap