What's brewing?

Coming up: TalonSocLab Link to heading

Over the next few months I’m standing up a personal home SOC, TalonSocLab, in four phases. The goal is simple: one working thing that shows I can run a small SOC end to end.

  • Phase A, Foundation. Wazuh, Sysmon, and Suricata with tuned dashboards on real endpoints.
  • Phase B, Detection Engineering. A Sigma rule pack tested against Atomic Red Team and mapped to MITRE ATT&CK.
  • Phase C, AD Attack and Defense. A vulnerable Active Directory lab, the common attacks, and a detection for each.
  • Phase D, Honeynet and Threat Intel. An internet-facing honeypot feeding an IOC pipeline.

Each phase gets a short post here. Follow along by RSS.

What I’m after Link to heading

Begin my second career path by breaking into the cybersecurity industry with a full time position.