Section / IT systems + security

Infrastructure, security, and recovery.

Security monitoring and recovery work I can show.

Personal lab / proven ground

A small environment for running, breaking, and recovering systems.

I work from systems I have configured and used:

  • Proxmox virtualization with Windows and Linux guests
  • TrueNAS, ZFS mirrors, snapshots, and layered backup practices
  • Pi-hole network-wide DNS filtering
  • Tailscale mesh networking with a subnet router
  • Network segmentation for an isolated Kali security-learning VM
  • Wazuh 4.14.7 deployment, Linux agent enrollment, FIM live-fire testing, and vulnerability triage
  • Remote service access, documented dependencies, and architecture decision records

02 / public-safe trust boundary

Conceptual home lab trust boundaryA public-safe conceptual path from a remote device through identity-based access into a private boundary, with services and storage as destinations and DNS filtering plus isolated testing shown as controlled branches.HOME BOUNDARYREMOTE DEVICEMESH ACCESSSUBNET ROUTERSERVICESSTORAGEISOLATED TESTDNS FILTER
Identity-based access enters the private boundary; services and storage are destinations, while DNS filtering and isolated testing remain controlled branches. The animated checkpoint is a conceptual audit sequence, not a literal packet trace.

Security / working posture

Calibrated claims. Reproducible systems.

Wazuh is implemented within a narrow scope: deployment, one enrolled Linux agent, alert triage, FIM, vulnerability remediation, and custom detection-rule testing. The custom rule maps narrowly to ATT&CK T1110.001.

Windows AD and deeper adversarial lab work are still in progress. I document what is implemented and label the rest as next work.

Wazuh / evidence roadmap

From implementation to proof.

01 / current

Implemented scope

Wazuh deployment, one enrolled Linux agent, FIM live-fire testing, vulnerability triage, and one custom SSH rule mapped narrowly to ATT&CK T1110.001.

02 / next capture

Make the work inspectable

Publish redacted alert output, the rule ID and logtest result, a vulnerability finding and remediation record, timestamps, dashboard evidence, and retention or autostart notes.

03 / boundary

Keep the scope honest

Windows telemetry, AD integration, Sysmon, broad ATT&CK coverage, threat hunting, and Atomic Red Team remain separate work.

Home lab / operating theory

Use leaves a trail.

A home lab becomes useful through real use, failure, recovery, and revision.

01 → 02 / shared recovery interface

Systems improve through use and provenanceTwo circular systems loops touch at one shared recovery node. The left loop describes operational use. The right loop describes provenance.SYSTEMS IMPROVETHROUGH USESYSTEMS IMPROVETHROUGH PROVENANCECONFIGUREOPERATEOBSERVEREVISEDECISIONCHANGEEVIDENCECONTEXTRECOVERR / SHAREDSystems improve through use and provenanceA mobile composition of two tangent systems loops sharing one recovery node.SYSTEMS IMPROVETHROUGH USESYSTEMS IMPROVETHROUGH PROVENANCECONFIGUREOPERATEOBSERVEREVISEDECISIONCHANGEEVIDENCECONTEXTRECOVERR / SHARED
Use teaches the system. Provenance explains the change.

Exports, decisions, restore notes, and test results keep both loops legible.

Practice artifacts

The evidence is being written down.

01 / implemented

Trust boundaries

Proxmox hosts Windows and Linux guests; TrueNAS provides storage and recovery layers; Pi-hole filters DNS; Tailscale provides identity-based remote access; an isolated Kali environment is kept off the LAN by design.

The public version intentionally omits addresses, credentials, and topology details that would make the home network easier to target.

02 / implemented posture

Recovery before confidence

Mirrored storage, snapshots, layered backups, configuration exports, and an offline target turn failure into a recoverable event rather than a story about hoping nothing breaks.

Restore timing and limits are the next evidence to publish.

03 / next build

Detection in the loop

The remaining gap is Windows detection and adversarial validation. AD DS, domain clients, Windows telemetry, and controlled attack emulation remain next steps.

They are separate from the Wazuh work already implemented.

04 / in progress

Windows domain-controller candidate

Windows Server 2022 is installed and booted in a separate Proxmox VM. It is a candidate environment for future AD DS and Windows telemetry work, not a completed domain controller.

AD DS, domain clients, GPOs, Windows Wazuh integration, and Sysmon remain open.

Where this connects

Useful at the boundary between people and systems.

My background combines customer-facing operations, data analytics, web development, documentation, and hands-on infrastructure. I am interested in roles where careful communication and technical curiosity matter as much as the tool list.

Start a conversation