Daniel Forsyth

Cybersecurity & IT

B.S. Cybersecurity Analytics and Operations, Penn State, December 2026

About

Photo of Daniel Forsyth

I'm a cybersecurity student at Penn State with real-world IT support experience, looking for full-time roles in IT and cybersecurity. I'm open to opportunities across the field: security operations, incident response, digital forensics, or IT and systems roles where I can keep building toward security. I started building PCs as a teenager and haven't stopped taking things apart to see how they work. Since then I've supported more than 150 users on a campus help desk, handled a high-volume remote service desk for an MSP, and investigated a simulated network breach across more than 140 GB of forensic evidence.

I grew up on the Maryland–Pennsylvania border and didn't have a strong network or many resources before college. The decision to pursue this field was my own, inspired by my older sister and by peers who were already chasing careers in tech. Getting here has meant figuring a lot out myself: an IT career program, a branch campus, a transfer to University Park, and working while I studied. That's made me resourceful, and it's why I take every opportunity seriously.

Outside of tech, I've spent five years learning 3D art, modeling, and animation in Blender. It's the same itch as security: figuring out how complex systems fit together, one detail at a time. I'm also into music and live concerts, traveling, and almost anything outdoors, including hiking, kayaking, paddleboarding, and biking.

Experience

Remote Service Desk Analyst

Aug 2026 – Oct 2026

GDC IT Solutions · Internship (IST 495)

GDC IT Solutions is a managed service provider that offers help desk support, managed IT, and cybersecurity services to organizations across many industries. As a Remote Service Desk Analyst, I support two charter school clients at once. I handle 15–40 calls and tickets a day from staff, students, and caretakers. Each school runs its own environment, so I constantly switch between platforms. For one client I use Edio to find accounts and reset passwords, OnBase to look up and verify student and caretaker identities, Autotask for ticketing, and Kaseya VSA to remote into student laptops. For the other, I use One-to-One for account information and ticketing.

Much of my work is credential management: creating and resetting passwords and getting users back into their accounts. Every request starts with verifying who's on the other end of the line. Identity verification is the front line against social engineering, and doing it dozens of times a day has made it second nature. The rest is remote troubleshooting of cameras, microphones, connectivity, batteries, displays, and general laptop problems, usually resolved in 5 to 30 minutes. I also report suspected malware incidents and escalate complex cases to the appropriate support tier. Compared with campus support, MSP work means higher volume, multiple clients, and strict documentation standards and SOPs. And because the work is remote, I have to diagnose problems without the device in front of me, relying on clear questions and careful listening.

Tier 1 Technician

Aug 2023 – May 2024

Penn State Mont Alto, Information Technology Services

At Penn State Mont Alto I was a front-line technician who supported more than 150 students, faculty, and staff. I split my time between the help desk and working around campus. At the desk, I answered calls and walk-ups, logged and routed every incident in ServiceNow, and worked each one through to resolution. Around campus, I serviced network closets, deployed machines to buildings, set up classrooms and events, and handled hands-on hardware work: docks, monitors, desktops, and printers, including troubleshooting and supply replacement.

The most common tickets were Wi-Fi setup, MFA lockouts, classroom AV, printers, and laptop issues. Many of those problems were really security conversations. When someone was locked out of MFA or unsure about a suspicious email, I took the time to explain why MFA matters and how to recognize phishing, so the fix also made them a little safer. Working in a small, close-knit IT department, where faculty and staff knew me by name, taught me that good support is as much about trust and communication as it is about technical skill.

Education

The Pennsylvania State University

Dec 2026

B.S. Cybersecurity Analytics and Operations · Minor in Information Technology Systems · NSA Certificate

I got into cybersecurity the way a lot of people do: building computers as a teenager and wanting to know how far I could push them. Over time, that curiosity turned into wanting to use the same skills to protect people and their data. Older peers who were already working in the field showed me it could be a career. Penn State's Cybersecurity Analytics and Operations program gave me the structure to make it one. It combines hands-on cyber defense with the analytics behind it. I also completed a minor in Information Technology Systems because strong IT fundamentals and good security go hand in hand.

My coursework went from building defenses to taking threats apart. In Cyber-Defense Studio I configured firewalls, deployed host- and network-based intrusion detection, and ran penetration tests with Metasploit. Malware Analytics taught malware detection and defense through reverse engineering and static analysis in lab work. Cybersecurity Analytics Studio used R and Python to find attacks in data, including log analytics, access analytics, and investigating real infections such as ZeroAccess. Computer and Cyber Forensics covered evidence collection and investigation procedures, and Network Security included attack-and-defense team exercises.

On the organizational side, Cyber Incident Handling and Response was writing-intensive. In it I wrote and revised real incident response documentation: an incident management plan, a CSIRT plan, a business continuity plan, and a post-incident recovery plan. Information Security Management and Risk Analysis in a Security Context covered risk assessment, security policy, contingency planning, and security standards and certification. My last class was the Cybersecurity Capstone, where my team analyzed more than 140 GB of incident data using Wireshark, Python, FTK Imager, and Volatility. We mapped suspicious behavior to MITRE ATT&CK and briefed our findings to a C-suite audience (see Projects).

I also earned Penn State's National Security Agency Certificate. The NSA and the Department of Homeland Security award it to students who complete the knowledge units required by Penn State's designation as a National Center of Academic Excellence in Cyber Defense.

Starting at Mont Alto

I began at Penn State Mont Alto, where the IT program is small and close-knit, and I built strong relationships with faculty and staff. I made the most of my time there. I worked for the campus ITS department and served in the Student Government Association as IT Representative (August 2023 – April 2024), handling AV, running Zoom and large meetings, and troubleshooting for staff. That work earned me a certificate for outstanding service and dedication to a student organization, plus a superlative for best attendance. When my degree required it, I transferred to University Park to finish. There I served as IT Director for the Council of Commonwealth Student Governments (August 2024 – April 2025), the student government that represents Penn State's Commonwealth Campuses. In that role I ran the technology for large-scale meetings and supported the central staff.

Honors: Provost Award scholarship, Scholarship for Talented Students, Dean's List (Fall 2022–23) · GPA: 3.3

Franklin County Career & Technology Center

Spring 2021 – Jan 2022

Information Systems Technology Program · Chambersburg, PA

My hands-on IT foundation comes from Franklin County Career & Technology Center's Information Systems Technology program. For two full-time semesters, my school day was IT: about six hours a day in a lab with roughly 25 desktop workstations, server racks, networking equipment, and a practice wall for punchdowns and cabling. The program covered computer repair and upgrades, structured cabling, building and maintaining LANs and client-server networks, configuring and securing end devices, web design, and the foundations of cybersecurity.

I finished with a 4.0 GPA, membership in the National Technical Honor Society, and three TestOut certifications. I also scored Advanced, the highest performance level, on the NOCTI industry assessment for the program, which earns recommended college credit in computer networking and information systems. My instructor sometimes picked me to handle real IT work around the school, like troubleshooting machines and replacing hardware. That was my first experience supporting actual users rather than lab equipment. Seeing peers thrive in cybersecurity, and having an instructor who pushed me toward it, is what pointed me to Penn State's cybersecurity program.

Honors: TestOut Network Pro, IT Fundamentals Pro, and PC Pro; NOCTI Advanced; National Technical Honor Society · GPA: 4.0

Projects

Municipal Network Breach Investigation

CYBER 440 Capstone · Team of 5 · May – Aug 2026

A small town's network was suspected of being compromised. Its IT department, Mayor's Office, Police Department, Tax Office, and shared file server were all potentially involved. Our five-person team acted as the incident response firm. Our job was to work out what happened, when, which systems were involved, and what it meant for the town, then brief leadership. The evidence: 41 packet captures (11,063,688 packets), 9 forensic disk images, 7 memory captures, and mail server and centralized logs (265K+ records), about 140 GB in total.

How we investigated

  • Network: We wrote a Python script that used Wireshark's command-line tools to automatically profile 40 of the 41 packet captures, then reviewed the one it couldn't parse by hand. Together they covered about 18 hours of traffic across four days.
  • Disk: We verified forensic image integrity in FTK Imager with MD5 and SHA-1 hashes before touching anything, then examined accounts, software, email, and documents to establish a baseline of normal activity.
  • Memory: We used Volatility (pslist, dlllist) to find the same executable running on four systems: the IT workstation, the Mayor's workstation, and two Windows servers. We pinned down its start times and the user profiles it ran from.
  • Triage: We hashed recovered executables and checked them on VirusTotal, mapped their behavior to MITRE ATT&CK techniques, and used string analysis to understand their structure.
  • Logs: We reviewed HmailServer and centralized Windows event logs for failed logins and unusual account activity.

What we found

We reconstructed a two-day timeline linking activity across four systems. We also found that the shared drive held sensitive data: tax records containing PII, police reports, and Mayor's Office documents. We did not find evidence of exfiltration, tampering, or ransomware, and we said so plainly. Every conclusion in our report was limited to what the evidence could verify. Where it couldn't, such as the initial attack vector, we called out the gap instead of guessing.

The deliverable

We delivered a full forensic report and an executive briefing written in Bottom Line Up Front (BLUF) style for a C-suite audience. Our recommendations covered patching, centralized logging and retention, EDR, MFA and least-privilege access reviews, security awareness training, and forensic readiness.

AI-Assisted Threat Intelligence Analysis

IST 451 Network Security · Solo project · Spring 2025

Security analysts use cyber threat intelligence (CTI) reports to hunt for attacks in their own logs. Pulling the usable indicators of compromise (IOCs) out of a 40-page report is slow. Large language models can speed it up, but they also hallucinate, and a made-up technique ID or command line in a detection rule is worse than none at all.

My approach

I worked through two real APT reports paragraph by paragraph: Bitdefender's analysis of a Chinese espionage campaign against Southeast Asian governments (Chinoxy, PcShare, and FunnyDream backdoors) and Trend Micro's analysis of Earth Lusca. For each paragraph I wrote targeted prompts to make the LLM extract threat actors, targets, tools, TTPs, and IOCs. Then I verified every claim against the MITRE ATT&CK knowledge base before accepting it, flagging and challenging anything the model inferred beyond the source text. Before that, I used ATT&CK to build a profile of Turla, the Russian FSB-linked espionage group, covering its persistence, defense evasion, discovery, lateral movement, exfiltration, and C2 techniques.

The result

For each report I produced a verified IOC table that classifies command lines, registry keys, and file paths and maps each one to its ATT&CK technique and tactic. Analysts could turn these tables directly into detection rules. A sample:

IOCTypeATT&CK techniqueTactic
schtasks /create ... /ru "SYSTEM" /sc DAILY /tr "c:\users\public\11.bat"Command lineScheduled Task (T1053.005)Persistence
HKCU\Software\Classes\CLSID\{42aedc87-...}\InprocServer32Registry keyCOM Hijacking (T1546.015)Persistence
rundll32 \\<DC>\netlogon\msvcrt.dll,StartCommand lineSMB/Windows Admin Shares (T1021.002)Lateral Movement
c:\users\public\ccf32.exe -PC all ... doc,docx,pdf ...Command lineAutomated Collection (T1119)Collection
reg add "HKCU\Environment" /v UserInitMprLogonScript ...Command lineLogon Script (T1037.001)Persistence
move <malware> ...\spool\prtprocs\x64\spool.dllCommand linePrint Processors (T1547.012)Persistence

The main lesson: AI can speed up threat intelligence work, but only if an analyst verifies every output against an authoritative source before it reaches a detection rule.

Contact

I graduate in December 2026 and I'm looking for roles in IT and cybersecurity. If you think I'd be a good fit for your team, I'd love to hear from you.

Resume