Didier Stevens Portfolio
Contributes to the SANS Internet Storm Center while maintaining a suite of widely-used Python forensic tools (oledump.py, pdf-parser.py, base64dump.py) built for analyzing malicious documents and encoded payloads.
What makes it work
A breakdown of the choices that make this portfolio stand out.
A named tool for nearly every specific file format attackers abuse
Separate, purpose-built tools for OLE documents, PDFs, ZIP files, and base64-encoded payloads mean each one does one analysis job well, rather than one tool trying to handle every malicious file type.
Continuous small updates logged publicly
Monthly overviews documenting minor tool updates, not just major releases, show ongoing maintenance and real-world use, which matters more in forensic tooling than a tool built once and abandoned.
Contribution to a recognized third-party institution (SANS ISC)
Publishing diary entries through the SANS Internet Storm Center in addition to the personal blog adds an independent, peer-reviewed publication channel alongside self-published material.
What Cybersecurity Analysts can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
Build small, single-format tools rather than one do-everything analyzer — a tool that does one job well is easier for others to trust and adopt.
Log even minor updates to your tools publicly and regularly — a visible maintenance history is itself evidence the tools are still relevant and used.
Publish through an established, independent outlet in your field in addition to your own site — third-party publication adds credibility self-publishing alone can't.
More Cybersecurity Analyst portfolios
Ready to build your portfolio?
Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.