David J. Bianco Portfolio
Creator of the "Pyramid of Pain" threat-detection model and SANS network forensics instructor, publishing data-driven threat-hunting research such as an analysis of over 11 million VirusTotal malware samples testing whether hash-based detection actually works.
What makes it work
A breakdown of the choices that make this portfolio stand out.
A named, widely-adopted conceptual model
The Pyramid of Pain gives threat hunters and SOC teams a shared vocabulary for ranking indicators by how much pain they cause an attacker to change — a durable mental model has more lasting influence than any single incident writeup.
Hypothesis-driven research format
Posts are structured as an actual research process — hypothesis, dataset, analysis, conclusion — rather than opinion pieces, which is what makes an 11-million-sample VirusTotal analysis read as investigation rather than commentary.
Quantified findings instead of qualitative claims
Reporting an exact figure (91.81% of files submitted by a single submitter) to support a conclusion about hash-based detection is concrete and falsifiable in a way "hash detection often fails" is not.
What Cybersecurity Analysts can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
If you have a recurring insight in your field, try naming it as a model or framework — a named concept spreads and gets cited in ways a buried blog post doesn't.
Structure technical posts like actual research — state the hypothesis, show the dataset, then the conclusion — rather than presenting a bare opinion.
Back claims with an actual measured number wherever you can, even an approximate one; a specific figure is more credible and more memorable than a qualitative claim.
More Cybersecurity Analyst portfolios
Ready to build your portfolio?
Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.