Blue Team–focused cybersecurity practitioner building hands-on experience in
security monitoring, detection, investigation and incident response.
I turn theory into evidence through hands-on labs: collecting telemetry, investigating suspicious activity, validating detections and documenting analyst decisions.
Personal Blue Team lab focused on the full security-analysis lifecycle.
Telemetry → Detection → Validation → Investigation → Response
- Deployed Suricata IDS and Wazuh SIEM for centralized security monitoring
- Built and validated detection logic for reconnaissance and authentication attacks
- Implemented automated response with Wazuh Active Response and fail2ban
- Reconstructed reconnaissance, brute-force activity and successful access from an 8,936-packet PCAP
- Documented detection gaps, evidence and lessons learned from each investigation
Current direction: Detection Engineering · Threat Hunting · Incident Investigation · Security Automation
Four-segment capstone: Design → Build → Secure & Monitor → Validate & Recover
- Designed an 8-zone Default-Deny IT/OT architecture with separate Employee/Vendor VPN pools
- Implemented the PoC with KVM/libvirt, pfSense, Windows Server/AD, Windows and Linux DMZ/OT systems
- Centralized network, Windows and Linux telemetry in Splunk Enterprise and integrated Suricata EVE JSON
- Built 3 baseline SPL detections, 2 SOC dashboards and 7 final alerts
- Validated 4 controlled scenarios; a disposable DMZ compromise succeeded while the attempted OT TCP/502 pivot was blocked
- Completed incident preservation → containment → restore → re-test and vulnerability remediation
- Documented troubleshooting, lessons learned, design decisions, evidence and four final technical reports
Foundation work behind Aegis and KRANOTECH.
Network Discovery · Wireshark Traffic Analysis · WPA2 Security Testing · Firewalling · Network Segmentation
| 4 CompTIA Certifications |
3 Aegis Chapters Completed |
8,936 Packets Investigated |
4 Segments KRANOTECH Capstone |
Building Project Aegis into a deeper SOC and Detection Engineering portfolio.
Detection Engineering · Threat Hunting · Incident Investigation · Detection Validation · Security Automation
Target roles: Junior SOC Analyst · Cybersecurity Analyst · Security Operations