About

I’m an IT support technician moving into defensive security — detection engineering and SIEM, network and platform security, and incident response. This site documents that work through a hands-on homelab where I start from a threat model, build the controls, and then prove they actually do what I claimed.

Focus

Blue-team work, grounded in a lab I run rather than walkthroughs I followed:

  • Detection engineering / SIEM — building a Graylog pipeline end to end: raw log, parsing rule, structured fields, tuned alert, with the reasoning at each step.
  • Network & platform security — segmentation and firewall design driven by a threat model and trust zones, plus host hardening with the rationale attached.
  • Incident response — running MITRE ATT&CK-mapped exercises and documenting the full cycle: what fired, triage, containment, lessons learned.

The aim across all three is to show judgment and process — why a control or detection exists — not just that a tool got installed.

Foundation

Before and alongside the security work, I support users and systems day to day:

  • Operating systems — troubleshooting and administration across Windows and Linux.
  • Identity & directory services — user and group management in Active Directory.
  • Networking — diagnosing connectivity issues and the fundamentals beneath them.

This isn’t a footnote — it’s why the security work clicks. Defending an environment means knowing what normal looks like: how endpoints and users actually behave, how identity and directory services work, where networks break. A support background is a head start on detection and incident response, not a detour from them.

How I got here

I came into IT through an unconventional means. I started with almost no hands on skills and schooling and leanred most of what I know from home labing and in my current role as an IT Support Specialist. The deeper I got into keeping systems running, the more the defensive side pulled at me — understanding not just that something broke, but whether it was supposed to happen, and how I’d know if it were an attacker.

Certifications & training

  • CompTIA Security+ — March 2025
  • TryHackMe — active learner (profile)

The work

I learn by building and documenting. A sandbox environment helps a lot with knowing how things work and how to configure them, as well as putting my security knowledge to the test. This would be all documented in my (posts)

Let’s connect

I’m building toward a defensive-security role and always glad to talk shop about detection, segmentation, or homelab design.

Prefer the short version? Here’s my resume.