What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Build a cybersecurity portfolio by completing small, clearly scoped projects in intentionally vulnerable training environments. For each one, show the authorized lab scope, how you reproduced an issue, what the evidence demonstrates, why it matters, and how a defender could address it. OWASP Juice Shop and PortSwigger Web Security Academy are two practical starting points; neither requires you to test an unapproved real-world system.

Choose a lab that matches your learning goal

Start with one cybersecurity direction rather than trying to demonstrate every specialty at once. NIST’s NICE resources can help connect education and training choices, including cyber ranges and work-based learning, to career development: NIST NICE resources.

Environment Practice format and setup Portfolio artifact
OWASP Juice Shop A deliberately insecure application intended for training, awareness demonstrations, CTFs, and security-tool testing. OWASP describes software-based setup options including Docker, Node.js, and Vagrant. A reproducible assessment of a chosen vulnerability class, with the local setup and scope, evidence, impact, and a proposed fix.
PortSwigger Web Security Academy Free interactive web-security labs with learning material and progress tracking. Exercises cover subjects such as SQL injection, XSS, access control, authentication, and API testing. A lab write-up naming the specific Academy exercise and explaining the vulnerability concept, evidence, and defensive lesson.

Juice Shop gives you more control over a self-managed application and its setup. Academy labs provide a hosted, topic-organized practice route. Both support a credible portfolio project when you make the exercise’s scope explicit. OWASP’s project page describes Juice Shop and its setup options at OWASP Juice Shop; PortSwigger describes its safe, legal training environment at Web Security Academy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a first project in a bounded scope

1. Pick one question to investigate

Choose a single vulnerability class or learning objective, such as access control or injection in Juice Shop, or a specific Web Security Academy lab. A focused exercise is easier to explain and reproduce than a broad claim to have tested an entire application.

#1 Best Overall
Spy Labs: Forensic Investigation Kit | Detective Set
  • Spy Labs Incorporated's activity kits and equipment provide an engaging and interactive way for kids to learn about detective work, including forensic analysis and tracking techniques.
  • Includes a large laboratory setup with materials needed to collect and analyze evidence, such as a UV flashlight, fingerprint powder, pH test strips, and more.
  • The 20-page, full-color manual guides kids through experiments as they assume the role of a forensic scientist, solving make-believe crimes and mysteries presented in the manual.
  • Promotes pretend play as kids ages 8 and up take on the role of detective, setting out to unravel mysteries one tough case at a time.
  • Become a first-class secret agent with Spy Labs, the Detective Gear Experts; your trusted source for all your essential spy tools and gear!

2. State authorization and boundaries first

Name the environment and define what you did and did not test. For Juice Shop, identify your local training instance. For Academy, name the exact lab and keep the report about that exercise. Do not scan or test systems you do not own or have explicit authorization to assess.

3. Follow a repeatable workflow

  1. Set scope: record the lab, application, and permitted boundary.
  2. Map the application: note the relevant pages, features, or inputs in the exercise.
  3. Analyze the attack surface: identify what behavior or security control your question concerns.
  4. Test the vulnerability hypothesis: document the steps you used in the authorized environment and the result you observed.

PortSwigger’s documented testing workflow uses scope, application mapping, attack-surface analysis, and vulnerability testing as stages; its page was last updated October 6, 2026. See PortSwigger’s web security testing methodology. Its getting-started guidance recommends learning through reading, practicing in labs, and tracking progress: Getting started with Web Security Academy.

4. Capture only the evidence needed

Include concise screenshots, sanitized requests and responses, relevant logs, code, or configuration snippets. Label synthetic or lab data clearly. Remove credentials, personal information, tokens, and unrelated system details before sharing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Explain the finding and the defense

Describe the observed behavior in plain language, connect it to the security concept, and explain its impact within the lab. Then propose a proportionate mitigation. Distinguish what the exercise demonstrates from what you have not established about real production systems.

Turn the exercise into a useful portfolio artifact

A project repository or report should let a reviewer understand both your technical reasoning and your care with authorization. Include these elements:

Rank #2
MindWare Science Academy Detective lab - Science Kits for Kids Age 8-12 - Kids Detective Kit Complete with 7 Forensics and Crime-Scene Investigations - Ages 8 and Up
  • Toys that Teach: MindWare Detective Lab teaches basic forensics, data collection and critical thinking with science experiments that are safe, easy and fun! You’ll learn about chromatography, pH, and basic analysis.
  • Scene of the Crime: Delve into the evidence like a real forensic detective! Learn how to lift and compare fingerprints, write secret messages and identify chemicals using the pH scale.
  • User-Friendly Fingerprint Kit: This kids detective game includes a fingerprint kit for kids to learn how to lift and compare fingerprints, adding a realistic touch to their kid detective games
  • Guide Book: The colorful, detailed guide booklet includes step-by-step instructions and safety information, plus a mysterious code to crack!
  • Comprehensive Forensic for Kids Kit: Great as a girls detective kit and boys detective kit alike, this evidence kit for kids includes all necessary supplies for forensics experiments, plus a full-color guide book (Ages 8 and up)
  • Summary: a brief explanation of the objective and outcome for a hiring reader.
  • Scope and authorization: the named training environment and boundary.
  • Reproduction: setup information and clear steps another learner can follow without real secrets or personal data.
  • Evidence: a small set of sanitized artifacts that supports the finding.
  • Analysis: observed behavior, security significance, and impact within the lab.
  • Mitigation: a defensive recommendation linked to the issue you demonstrated.
  • Learning note: what the exercise taught you and a sensible next topic.

Keep claims proportional to the work. A lab write-up demonstrates what you did in that lab; it does not, by itself, establish professional experience or guarantee a hiring outcome.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build a project sequence rather than a pile of unrelated write-ups

PortSwigger Academy offers guided learning paths and progress tracking, so you can connect a series of small lab reports to a coherent topic. Record which exercises you completed, the concept each taught, and what you plan to study next. NICE’s curated training resources can help you choose a direction that relates to cybersecurity work. The official Juice Shop project page also links to its companion guide, which is freely readable online; the latest officially released edition is available free in digital formats.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an initial project, a simple sequence could be: complete one guided lab, write a scoped report, then choose a related exercise that deepens the same concept. For a self-managed project, use Juice Shop to reproduce one issue locally and document the setup alongside the finding. In either case, make each artifact understandable on its own and link it to the broader learning direction.

Keep the work safe and the claims precise

  • Use intentionally vulnerable training software or an explicitly authorized lab.
  • Do not treat a public website, a reachable service, or an employer’s system as permission to test it.
  • Keep proof of concept and screenshots limited to what the learning exercise requires; sanitize before publication.
  • Clearly label lab data and avoid implying that a lab result proves the same condition exists elsewhere.
  • Prefer accurate, narrow descriptions of your contribution over inflated claims such as having assessed real organizations when you have only completed a training lab.

PortSwigger states that the Web Security Academy exists to help people learn web security “in a safe and legal manner.” Its labs are designed for practice; stay within their stated scope. OWASP describes Juice Shop as an insecure application for training and related uses, not as permission to test other systems.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.