Yugal Koju

yugal@network:~$ whoami

Yugal Koju

Network Engineer  ·  Cybersecurity  ·  IT Support

I bridge networking, cybersecurity, and IT support — building reliable infrastructure, strengthening security, and turning threats into actionable solutions through monitoring, detection, vulnerability management, and incident response.

CCNA® is a trademark of Cisco. Security+® is a trademark of CompTIA.

~$ about

About

I'm an IT professional with 2+ years of enterprise IT support experience, now focused on cybersecurity and security operations. I enjoy understanding how systems work, finding what went wrong, and turning problems into practical solutions — from SIEM/XDR monitoring and threat detection to incident response and network security. With CCNA and CompTIA Security+, I bring strong networking fundamentals and a practical mindset focused on solving problems, reducing risk, and preventing them from happening again.

  • 2+years hands-on IT
  • 50+users supported
  • 10–15incidents / week

~$ show projects

Projects

Security-first network design, plus hands-on SOC and monitoring work.

Enterprise Network Security Design

Home lab  ·  Cisco Packet Tracer
github.com/ug-koju/Enterprise-WAN-Design ↗

ProblemConnect three sites securely without a flat network or an unmanaged trust boundary between them.

  • 500+ endpoints centralized across 3 sites
  • 10+ VLANs segmented with inter-VLAN routing
  • ASA firewalls — ACLs, NAT, DMZ, 802.1X

ResultCentralized DHCP, DNS, WLC, AAA, and Syslog cut configuration overhead and gave one place to see what's happening across every site.

How I built it
  1. Connected 3 sites with GRE-over-IPsec tunnels and OSPF for resilient routing.
  2. Deployed Cisco ASA firewalls with ACLs, NAT, DMZ segmentation, and 802.1X (RADIUS/TACACS+).
  3. Segmented 10+ VLANs with inter-VLAN routing and NAT overload (PAT) to cut broadcast traffic.

Enterprise LAN Design

Home lab  ·  Cisco Packet Tracer
github.com/ug-koju/Enterprise-LAN-Design ↗

ProblemSupport 1,000+ endpoints on a single flat LAN without gateway failover or a scalable hierarchy.

  • 1,000+ endpoints, Core / Distribution / Access
  • HSRP + LACP for high availability
  • Dual ISPs, SSH-only management

ResultGateway redundancy and bonded uplinks meant a single link or device failure didn't take down access for any department.

How I built it
  1. Built a three-tier hierarchy with OSPF and per-department VLANs.
  2. Added HSRP gateway redundancy and LACP-bonded uplinks.
  3. Added a second ISP and verified failover under simulated link loss.

Wazuh XDR & SIEM Deployment for Endpoint Monitoring

Home lab  ·  VMware
Read the write-up ↗

ProblemEndpoint activity across mixed Windows/Linux systems had no centralized visibility — issues only surfaced after something broke.

  • Wazuh XDR/SIEM deployed on a dedicated VM
  • Suricata IDS integrated for network-level detection
  • Agents on Windows & Kali Linux endpoints

ResultCentralized log aggregation and continuous endpoint telemetry, with alert accuracy validated through structured dashboard correlation.

How I built it
  1. Deployed and configured Wazuh XDR/SIEM on a VM, then installed agents on Windows and Kali Linux endpoints.
  2. Installed and configured Suricata IDS on Windows Server 2025, then integrated its logs into Wazuh for network-based threat detection.
  3. Built detection rules and log filtering, ran vulnerability/compliance scans, and validated alerts through dashboard correlation — including a custom Suricata dashboard.

Additional Hands-On Work

Wireshark Packet Capture & Analysis

  • Captured PCAPs from Ping of Death testing between Kali Linux and Windows, analyzing malformed ICMP traffic
  • Identified Nmap scan signatures, TCP flag patterns, and reconnaissance techniques in captured traffic
  • Implemented firewall deny rules to mitigate the ICMP-based DoS vector

Windows Server Deployment

  • Deployed a Windows Server 2025 Domain Controller with AD, DNS, DHCP for 250+ users/endpoints
  • Implemented 10+ GPO security and access policies
  • Managed the full AD user lifecycle — provisioning, modification, deactivation

SOC Analyst Practical Labs

Completed on TryHackMe & Hack The Box

  • Monitored, triaged, and escalated alerts across Splunk, ELK, and Wazuh using structured SOC workflows
  • Investigated incidents through log correlation, PCAP analysis, and endpoint telemetry
  • Threat-hunted with MITRE ATT&CK and Cyber Kill Chain; ran forensics with Volatility and Autopsy

Junior Penetration Tester Practical Labs

Completed on TryHackMe & Hack The Box

  • Enumerated attack paths with Nmap, BloodHound, and Nessus
  • Tested web applications with Burp Suite and exploited findings with Metasploit
  • Practiced privilege escalation and post-exploitation to understand attacker methodology

~$ show skills

Skills

Networking, security operations, and the platforms in between.

Networking

TCP/IP & Subnetting VLANs & STP/LACP OSPF · EIGRP · RIP DNS · DHCP · NTP NAT/PAT Wireless (WLC)

Security

SIEM/XDR — Splunk · ELK · Wazuh IDS/IPS — Snort · Zeek · FortiGate Threat Hunting — MITRE ATT&CK Forensics — Volatility · Autopsy PCAP Analysis Vulnerability Management ACLs & 802.1X IPSec VPN

Cloud & Infrastructure

Azure VNet & VPN Gateway Hybrid Networking & ExpressRoute Windows Server & AD Group Policy (GPO) VMware Linux

Tools & Platforms

Wireshark & Tshark Nmap · Burp Suite · Metasploit BloodHound Python · Bash · PowerShell Ansible & Git Cisco IOS

IT Support Fundamentals

Windows/Linux Endpoint Support System Hardening & Patching Access Management Asset Inventory & Docs Preventive Maintenance End-User Training

~$ show experience

Experience

  1. Jun 2021 — Aug 2023

    IT Support Technician

    Sahara Rastriya Vidhyalaya · Bhaktapur, Nepal

    • Delivered IT support for 50+ users, resolving 10–15+ incidents weekly while maintaining system availability and security.
    • Installed, configured, and hardened Windows endpoints — patch management and access controls across 30+ endpoints.
    • Managed user accounts and permissions, and delivered cybersecurity awareness training to reduce operational risk.

Additional Sales Associate, Home Depot, North Bay, ON — Apr 2026–Present.

Assistant Manager, Northern Himalayan Cafe, North Bay, ON — Jun 2025–May 2026.

~$ show education

Education

  • Post Graduate Diploma — CybersecurityCanadore College, ON · 2025
  • Post Graduate Diploma — Business ManagementCanadore College, ON · 2024
  • Bachelor of ArtsBMIDU, India · 2017

~$ ping yugal

Let's connect

Hiring for network security, SOC, or network engineering roles? Let's talk.