Engineering Dashboard
Current Focus
Major portfolio initiatives I'm actively building and publishing.
Last updated: August 26, 2026
Current Engineering Projects
Cybersecurity Homelab
In ProgressEnterprise Homelab at 70% — role-specific network segmentation advancing with migrated workloads, hardened firewall policy, and expanded Elastic capacity.
View details →
Detection Engineering
PlanningDeveloping Sigma rules, YARA signatures, detection logic, ATT&CK mappings, validation labs, and engineering documentation.
View details →
Threat Hunting
PlanningConducting hypothesis-driven threat hunts, telemetry analysis, purple team exercises, and publishing hunt reports.
View details →
Current Learning
HTB CDSA
Certified Defensive Security Analyst preparation and practical defensive security labs.
Detection Engineering
Advanced detection query development, tuning, and validation workflows.
Malware Analysis
Sandbox analysis, IOC extraction, and behavioral classification techniques.
Windows Internals
Deep-dive into process, memory, and registry mechanics for hunt and forensic work.
MITRE ATT&CK
Mapping detections and hunt outcomes to adversary techniques and sub-techniques.
Publishing Queue
ELK Deployment Guide
In ProgressStep-by-step homelab Elastic Stack deployment and hardening.
Fleet Server
In ProgressElastic Agent Fleet server configuration and endpoint enrollment.
Sysmon Configuration
In ProgressBaseline Sysmon config for detection engineering and threat hunting.
Velociraptor Deployment
PlannedDFIR artifact collection and hunt automation with Velociraptor.
Threat Hunt #1
DraftFirst published threat hunt case study from lab telemetry.
Sigma Rule Collection
PlannedCurated detection rules with validation notes and MITRE mapping.
Lab Roadmap
Current Milestone
Telemetry Platform
DCP-005 is in progress: role-specific network segmentation advanced with migrated security, analysis, development, lab, and identity workloads. Internal name resolution and firewall policy were updated, and Elastic storage capacity was expanded. Storage configuration completion, broader agent coverage, and detection validation remain open.
- Active Directory organizational foundations in place
- Windows, Kali, and dedicated HTB/DFIR analysis workloads deployed
- REMnux malware-analysis capacity online
- Elastic Stack + Fleet with validated Observability and Security views
- Threat-intelligence enrichment and monitoring hygiene in place
- Additional Elastic storage capacity added
- Role-specific network segmentation advanced — finish storage config and detections (next)
Next Milestone
Detection Engineering Loop
Validate detections end-to-end against live lab telemetry.
- First detection validation against Sysmon telemetry
- Detection-as-code workflow
- Published engineering evidence
Future Milestone
Detection, Hunting & Publishing
Run detection and hunt loops, then publish engineering evidence.
- Detection validation and hunt case studies
- Architecture documentation series
- Screenshot and diagram evidence gallery
Current Technology Stack
Proxmox
Windows Server
Elastic
Fleet
Velociraptor
Sysmon
PowerShell
Python
Sigma
MITRE ATT&CK
Microsoft Defender
Active Directory