Wael Shahadeh — Cybersecurity, Marist '27

Security work you can check for yourself.

Malware research, network analysis and secure lab builds, plus tools that let you verify their output rather than take my word for it.

See the work

Featured build

Every post is checked against one signing key.

WaelSocial signs each entry offline with Ed25519, and your browser checks that signature against a public key pinned in the page. Because the key is fixed in the source, a compromised host cannot produce a valid checkmark.

Open the feed
Signed entry Verifying

key id
signed
signature
Ed25519

Practice areas

Console

Every page on this site can be reached by typing. Use one of the buttons below, or run help for the full list of commands.

wael@portfolio:~ Esc clears, ⌘K searches
$ whoami
Wael Shahadeh, cybersecurity senior at Marist University. Malware research and digital investigations. Type `help` for the command list.
$

Read the case studies, or run the tools yourself.

Four projects across research, engineering and community work. Each write-up covers the problem, the approach taken and the result.

Where to go next.

Selected work

How each project started and where it ended up.

Four projects across research, engineering and community work. Expand any one of them for the full account.

A social-style feed in which every authored post is signed offline with Ed25519 and verified in the visitor's browser through Web Crypto. Security news that is relayed automatically is labelled as such and is never marked verified. All of the verification runs client-side, so it can be read in the page source.

Problem

A static host or CDN can serve modified content without the visitor noticing, so trusting the server is not a sufficient security model.

Approach

Posts are signed offline, the public key is pinned in the page, and each entry is verified in the browser. If the served key does not match the pinned one, nothing is shown as verified.

Outcome

The checkmark indicates authorship by one specific key, which an origin or DNS compromise cannot forge.

Ed25519Web CryptoPython toolingThreat modeling

An exploration of machine-learning detection using macOS system logs, aimed at identifying backdoor behavior that signature-based tools do not catch.

Problem

Signature-based antivirus does not detect novel or modified backdoors at all.

Approach

Train models on unified log streams so that detection is based on behavioral patterns rather than known hashes.

Outcome

This is ongoing senior research and the write-up is still in progress.

macOSMachine learningSecurity logs

Diagnosing, repairing and re-imaging donated PCs from start to finish, covering hardware triage, data sanitization and clean operating system deployment.

Problem

Donated hardware arrives in an unknown and frequently broken condition.

Approach

A consistent pipeline of triage, repair, data wipe and imaging, applied one machine at a time.

Outcome

Working machines with clean images were returned to circulation.

ImagingDeploymentSupport

Organizing and hosting residence-hall events that build connection, cultural awareness and student wellbeing, including programming on security literacy.

Problem

Security advice tends not to land when it is abstract or delivered as a lecture.

Approach

Run events that people already want to attend and build the security content into them.

Outcome

Turnout has been consistent, and residents now raise security questions on their own.

EducationSecurityLeadership

Homelab

A lab network built for testing malware safely.

The network is segmented so that anything executed stays where it was executed. Malware runs on an isolated VLAN with no route out, and capture and analysis happen on a separate management segment.

Draft This is a reference topology. The VLAN IDs, subnets and host inventory below are placeholders until the real build sheet is finished.
3Segments
1Choke point
0Routes out of VLAN 66
DenyDefault policy
BothDirections logged

Topology

The segments and how traffic moves between them.

INTERNET Firewall DEFAULT DENY · LOGGED BOTH WAYS NO ROUTE OUT VLAN 10 · MANAGEMENT Analysis workstation Wireshark · notes · git 10.10.10.0/24 VLAN 20 · SERVICES Hypervisor host VirtualBox · file / backup 10.10.20.0/24 VLAN 66 · DETONATION Kali + target VMs Metasploit · snapshot revert 10.10.66.0/24 ONE-WAY TAP Captures leave the detonation VLAN through a tap, and nothing routes back into it.
Edge Perimeter WAN → firewall policy enforced

All traffic between segments passes through here. The rules are written at this point, the default policy is deny, and traffic is logged in both directions.

Firewall / routerDNS sinkholeEgress logging
VLAN 10 Management 10.10.10.0/24 outbound allowed

The segment I work from. It holds the analysis tooling and notes, and it is the only segment that can reach the others.

Analysis workstationWiresharkGit / notes
VLAN 20 Services 10.10.20.0/24 restricted

Long-running services and the hypervisor host. It is reachable from the management segment but not from the lab.

Hypervisor hostFile / backupLocal services
VLAN 66 Detonation 10.10.66.0/24 no default route

Used only for malware and offensive testing. It has no route out and no path to the other segments, and captures leave through a one-way tap.

Kali attacker VMTarget VMsPacket tap

Traffic between segments passes through the firewall only. The detonation VLAN has no default route, so analysis pulls captures from the tap rather than connecting into the VLAN.

Hardware & hosts

Hypervisor hostVirtualBox host running the attacker/target pairs VLAN 20
Analysis workstationCapture review, log parsing, and writeups VLAN 10
Kali attacker VMMetasploit and offensive tooling, reverted to a snapshot after each run VLAN 66
Target VMsDeliberately vulnerable Windows and Linux builds VLAN 66
Firewall / routerSegment enforcement, default deny, bidirectional logging Edge

What I run it for

Malware behavior analysis Running a sample on an isolated target and recording what it changes on disk, in the registry and on the network.
Traffic capture & review Wireshark on lab-only networks, reading protocol behavior against known-bad patterns rather than a signature list.
Offensive drills Kali and Metasploit against targets I own, so that exploitation is practiced rather than only read about.
Detection research Generating labelled log data for the macOS backdoor-detection work, which needs reliable ground truth.

Signed entries, verified in the browser

WaelSocial

Loading feed…

Notes & writeups

Writing

Cryptography · draft Pinning a public key in a static-site feed Why the checkmark indicates authorship by one specific key, rather than whatever key the response happens to contain. In progress
Detection · draft Reading macOS logs for detection, not forensics Notes from training models on unified log streams to identify behavior characteristic of a backdoor. In progress

About

Security involves both the technology and the people using it.

I am a senior at Marist University, studying for a B.S. in Cybersecurity with minors in Computer Science, Information Systems, Information Technology and Criminal Justice. My hands-on work covers malware analysis, network traffic and building secure lab environments.

As a resident assistant and advisor, I turn complex topics into programs people will actually attend. Controls that people do not understand tend not to be followed.

Skills

AnalysisWireshark, Kali Linux and Metasploit
BuildPython, Git, and Web Crypto with Ed25519
LabVirtualBox, isolated networks and OS imaging

Lab setup

VirtualBox, running isolated attacker and target VMs Kali and Metasploit for offensive testing Wireshark captures taken on lab-only networks

See the full topology

Contact

Get in touch.

Privacy

What this site collects.

The short answer is that it collects nothing. The detail below is written against the actual code rather than from a template, so you can read the source and check each claim for yourself.

Cookies

None. The site sets no cookies and reads none, so there is no consent banner.

Browser storage

None. There is no use of localStorage, sessionStorage or IndexedDB. The filter you select on the feed is held in a variable and is discarded when you close the tab.

Analytics & tracking

None. There is no Google Analytics or Plausible, no Meta or LinkedIn pixel, no session recording, no fingerprinting, no A/B testing tooling and no ad network.

Third-party requests

None from the page itself. Fonts were previously loaded from Google, which meant Google received your IP address and User-Agent on every visit. They are now served from this origin. If you open your browser's network tab, every request goes to wael.sh or api.wael.sh.

The feed API

The feed page and the card on the home page make a single GET request to api.wael.sh/api/feed. It carries no cookies, no credentials and no request body. Your browser sends its IP address, User-Agent and Origin header, as it does for any server. The service does not write a per-request log, and its CORS policy permits only this origin.

Forms & accounts

There are none. Nothing on this site accepts input that reaches a server. The terminal on the home page runs entirely in your browser and does not send anything.

Infrastructure

One caveat: I do not control the hosting. This site runs on GitHub Pages, and api.wael.sh is exposed through a Cloudflare tunnel, so GitHub and Cloudflare see request metadata such as IP address, User-Agent and timestamps, under their own policies. This is the same as with any host or CDN. I do not have access to that data and it is not combined with anything else.

Email

If you email me, I will have your email address. I use it to reply and for nothing else. There is no mailing list, newsletter or CRM.

Your rights

There is very little here to act on, because I hold no personal information about visitors to provide, delete or opt out of. I do not sell or share personal information, so there is no "Do Not Sell or Share My Personal Information" link. If you have emailed me and would like that correspondence deleted, let me know and I will delete it.

Known gaps

This page delivers its Content-Security-Policy in a <meta> tag, because GitHub Pages cannot set response headers. Both frame-ancestors and X-Content-Type-Options can only be set as headers, so they are not enforced here. It seems better to note that than to present the policy as complete.

Last reviewed 22 September 2026. Questions: [email protected].