CYBERSECURITY · INFRASTRUCTURE · AUTOMATION

I'm learning cybersecurity by building things that have to actually work.

I'm Scott. I'm building a home Cyber Operations Center from the ground up and documenting the decisions, mistakes, troubleshooting and lessons that come with it.

ABOUT

More than a list of tools.

I wanted an engineering journal and project portfolio that showed more than certifications and screenshots. Most of what you'll find here came from problems I ran into while building and securing my own environment.

I'm working toward cybersecurity and SOC-focused roles, with hands-on work across SIEM, endpoint security, networking, Linux, containers, automation and cloud. I don't pretend my homelab is an enterprise environment. Part of the point is learning where the differences are, and what I would do differently at scale.

FEATURED WORK

The lab is the portfolio.

View my GitHub
IN DEVELOPMENTDetection lab

Project Ares

An adversary-simulation and detection-validation platform designed to generate realistic activity and test whether my defensive controls actually see what I expect them to see.

Proxmox · Detection Validation · Sysmon · SIEM

View the repository
ACTIVE DEVELOPMENT · 2 MODULES COMPLETEAutomation

Project Daedalus

A self-hosted automation and intelligence platform with completed cybersecurity intelligence and certification lifecycle modules.

n8n · PostgreSQL · APIs · Secure Automation

View the repository
IN PROGRESSWorkstation

Project Cerberus

The Linux Mint Cinnamon engineering workstation and primary COC control node, built with secure installation, selective restoration, endpoint monitoring and acceptance testing.

Linux Mint Cinnamon · Git · Containers · Security

View the repository

Code and configuration will be linked here as each project reaches a state that's useful to share. Until then, the journal shows the work without pretending unfinished repos are finished projects.

SKILLS & TECHNOLOGY

What I'm working with.

These are tools and areas I'm using in the lab—not a claim that I've mastered every item.

Security operations

  • Wazuh SIEM
  • Detection engineering
  • Sysmon telemetry
  • Incident investigation

Infrastructure

  • Linux administration
  • Proxmox virtualization
  • Docker containers
  • Networking & DNS

Automation & delivery

  • n8n workflows
  • API integration
  • Git & GitHub
  • Infrastructure as code

Cloud & learning

  • AWS fundamentals
  • Identity & access
  • Security architecture
  • Technical documentation

ENGINEERING JOURNAL

The parts that don't fit in a README.

7 published · more to come

Build decisions, failed assumptions, troubleshooting notes and the lessons worth keeping.

CERTIFICATION · AUGUST 2026

Earning the AWS Certified AI Practitioner

How the official exam blueprint and a rough first practice result turned into a focused study plan—and a pass on the real exam.

Read the entry
PROJECT ATLAS · AUGUST 2026

Finishing the Physical Build of Project Atlas v1

How an older Dell Latitude became the Ubuntu Server backbone for my home COC—and why the final engineering decisions mattered.

Read the entry
DAEDALUS · AUGUST 2026

Building a Certification Lifecycle Manager That Won't Remind Me Twice

How a simple expiry reminder became a tested system for renewal rules, continuing-education progress, authenticated updates and auditable email delivery.

Read the entry
DAEDALUS · AUGUST 2026

Building a Cybersecurity News Pipeline I’ll Actually Use

How I turned eight security feeds into one ranked daily briefing without just moving information overload into my inbox.

Read the entry
COC · 8 MIN READ

Why I'm Building a Home Cyber Operations Center

The project started smaller than this. Here's how it turned into the backbone of my cybersecurity learning.

Read the entry
COC · AUGUST 2026

Building the Cyber Operations Center Engineering Program

What changed when I stopped collecting isolated projects and started treating the lab as one documented system.

Read the entry
ENDPOINT SECURITY · AUGUST 2026

Hardening My Own Endpoints Before Pretending to Defend Everyone Else's

The controls, compromises and validation behind the laptop, workstation, phone and tablet baseline.

Read the entry