I'm a IT student who enjoys learning by building things and investigating how attacks show up in real telemetry. Most of my work here focuses on blue-team security: homelabs, detection engineering, digital forensics, network analysis, and the occasional automation script. I'm still learning, and I use GitHub to document that process and turn what I study into practical projects. Feedback or Invitations are always welcome.
| Project | Description |
|---|---|
| PentaSOC | Raspberry Pi-based blue-team homelab for SIEM, network monitoring, detection validation, and incident-response practice. |
| DetectionFoundry | Behaviour-driven Sigma, YARA, KQL, SPL, and network detections with ATT&CK mapping, testing, and tuning. |
| IncidentDossier | Evidence-led DFIR case studies featuring timelines, technical findings, IOCs, and response recommendations. |
| infosec-wiki | Obsidian-compatible cybersecurity knowledge base covering SOC operations, DFIR, detection, and network security. |
| Area | Practical evidence |
|---|---|
| SIEM implementation and log analysis | PentaSOC · infosec-wiki |
| Detection engineering and rule development | DetectionFoundry |
| Network traffic monitoring and attack detection | PentaSOC · DetectionFoundry |
| Incident investigation and timeline reconstruction | IncidentDossier |
| Digital forensics and malware triage | IncidentDossier · infosec-wiki |
| Security scripting and automation | PentaSOC · DetectionFoundry |
- Developing and documenting the PentaSOC homelab
- Building and validating behaviour-based detections
- Publishing structured DFIR investigation reports
- Expanding Microsoft Sentinel, Defender XDR, and KQL skills toward SC-200