Cybersecurity Analyst

Didier Stevens Portfolio

Contributes to the SANS Internet Storm Center while maintaining a suite of widely-used Python forensic tools (oledump.py, pdf-parser.py, base64dump.py) built for analyzing malicious documents and encoded payloads.

Malware AnalysisDigital ForensicsSANS ISCOpen Source Tools

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

A named tool for nearly every specific file format attackers abuse

Separate, purpose-built tools for OLE documents, PDFs, ZIP files, and base64-encoded payloads mean each one does one analysis job well, rather than one tool trying to handle every malicious file type.

2

Continuous small updates logged publicly

Monthly overviews documenting minor tool updates, not just major releases, show ongoing maintenance and real-world use, which matters more in forensic tooling than a tool built once and abandoned.

3

Contribution to a recognized third-party institution (SANS ISC)

Publishing diary entries through the SANS Internet Storm Center in addition to the personal blog adds an independent, peer-reviewed publication channel alongside self-published material.

What Cybersecurity Analysts can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • Build small, single-format tools rather than one do-everything analyzer — a tool that does one job well is easier for others to trust and adopt.

  • Log even minor updates to your tools publicly and regularly — a visible maintenance history is itself evidence the tools are still relevant and used.

  • Publish through an established, independent outlet in your field in addition to your own site — third-party publication adds credibility self-publishing alone can't.

Ready to build your portfolio?

Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.

Cybersecurity Analyst Roadmap