Section / security + systems

Systems that should know where they are.

Infrastructure, protocols, security, and the spaces between connected things. A public map of the systems I build, understand, and am actively developing.

Personal lab / proven ground

A small environment for learning how systems fail.

The work begins with operating systems, networks, and the discipline of making a system explainable. These are the parts I can discuss from direct configuration and use:

  • Proxmox virtualization with Windows and Linux guests
  • TrueNAS, ZFS mirrors, snapshots, and layered backup practices
  • Pi-hole network-wide DNS filtering
  • Tailscale mesh networking with a subnet router
  • Network segmentation for an isolated Kali environment
  • Remote service access, documented dependencies, and architecture decision records

Security / working posture

Calibrated claims. Reproducible systems.

I keep the boundary between implemented experience and developing knowledge visible. Security+ study is in progress; detection engineering, log analysis, and deeper adversarial lab work are being built deliberately rather than presented as finished experience.

That same standard shapes the technical work: document the decision, reduce the attack surface, isolate what is experimental, and keep a recovery path when the system behaves differently than expected.

Practice artifacts

The evidence is being written down.

01 / implemented

Trust boundaries

Proxmox hosts Windows and Linux guests; TrueNAS provides storage and recovery layers; Pi-hole filters DNS; Tailscale provides identity-based remote access; an isolated Kali environment is kept off the LAN by design.

The public version intentionally omits addresses, credentials, and topology details that would make the home network easier to target.

02 / implemented posture

Recovery before confidence

Mirrored storage, snapshots, layered backups, configuration exports, and an offline target turn failure into a recoverable event rather than a story about hoping nothing breaks.

The next public version will document one restore exercise with timing, assumptions, and what was not recoverable.

03 / next build

Detection in the loop

The remaining gap is detection evidence: collect sanitized host and network events, generate a controlled signal, and write the triage from alert to conclusion without presenting planned work as shipped capability.

Wazuh, Windows event logs, and a small ATT&CK-mapped exercise are the intended next lab boundary.

Where this connects

Useful at the boundary between people and systems.

My background combines customer-facing operations, data analytics, web development, documentation, and hands-on infrastructure. I am interested in roles where careful communication and technical curiosity matter as much as the tool list.

Start a conversation