Welcome
Defensive-security homelab and writeups by Gage Neumaier — detection engineering, network segmentation, and incident response, designed from a threat model and proven in a live lab.
A defensive-security homelab, documented end to end. I build detection, segmentation, and incident-response capability the way a blue team does — from a threat model down to the alert that fires — and write up the reasoning at every step. The goal here is to show judgment and process, not just that a tool got installed.
Start here
New to the site? Begin with the Posts — This is where all of my docuementation
What I work on
- Detection Engineering — building a Graylog SIEM pipeline end to end: raw log, parsing rule, structured fields, tuned alert.
- Network Security — segmentation and firewall design driven by trust zones, plus an IDS sensor feeding the SIEM.
- Platform Security — host hardening and endpoint telemetry (Sysmon, auditd) with the rationale attached.
Incident Response — MITRE ATT&CK-mapped exercises, documented from first alert through containment and lessons learned.
LATEST WRITEUPS — uncomment this block once you have at least one published post, otherwise it renders an empty section under a heading.
Latest writeups
Building a Centralized Logging Pipeline with Graylog on Debian
September 30, 2026
A complete guide to installing a Graylog server natively on Debian using the apt package manager, secured behind an Nginx reverse proxy using Certbot and Cloudflare DNS.
Let’s connect
I’m building toward a defensive-security role and happy to talk detection, segmentation, or homelab design. Start with the about page, grab the resume, or reach me on LinkedIn.