What's brewing?
Coming up: TalonSocLab Link to heading
Over the next few months I’m standing up a personal home SOC, TalonSocLab, in four phases. The goal is simple: one working thing that shows I can run a small SOC end to end.
- Phase A, Foundation. Wazuh, Sysmon, and Suricata with tuned dashboards on real endpoints.
- Phase B, Detection Engineering. A Sigma rule pack tested against Atomic Red Team and mapped to MITRE ATT&CK.
- Phase C, AD Attack and Defense. A vulnerable Active Directory lab, the common attacks, and a detection for each.
- Phase D, Honeynet and Threat Intel. An internet-facing honeypot feeding an IOC pipeline.
Each phase gets a short post here. Follow along by RSS.
What I’m after Link to heading
Begin my second career path by breaking into the cybersecurity industry with a full time position.