top of page


The Install That Fought Back: Setting Up Splunk on a Mac
I set out to install Splunk Free and write a tidy walkthrough. Instead I hit four errors, discovered the tutorial was built for a machine that isn't mine, and had to force-restart my laptop — and learned more than a clean install ever would have taught me.
Jul 318 min read


The Data Behind My ISC2 CC Exam Experience
On June 20, 2026, my ISC2 CC exam session ended at 90 questions — with time still on the clock and no error message. ISC²'s own CAT documentation puts the minimum at 100 items. I'm a data analyst, so I did what I do when something terminates outside its expected parameters: I went looking for the data. Here's what turned out to be noise, and the one thing that didn't.
Jul 2711 min read


My Cert Stack So Far: ISC² CC + SC-900 and What Each One Actually Taught Me
Two certs on my entry-level path — one I've gone deep on, one I've previewed hands-on. This is the honest version: what the material revealed, and where it exposed gaps I didn't know I had.
Jul 245 min read


I Turned My Cybersecurity Path Into a Bingo Board (Vol. 1: Foundations)
Cybersecurity felt like forty open tabs and no idea where to start. So I turned the whole path into a bingo board — 25 beginner steps, in any order.
Jul 205 min read


Linux Fundamentals: A Data Analyst in the Terminal
The terminal stops being scary the moment you realize it's just asking questions. Ten years of querying data, and my first real Linux command line turned out to be full of familiar instincts — plus a few places where that familiarity ran out.
Jul 186 min read


Uncovering Hidden Threats: My Journey from Data Analytics to Cybersecurity
No cloud account, no labeled attack data — just SQL and Python on 2.8 million network flows. An Isolation Forest flagged suspicious traffic blind, and tuning it surfaced a counterintuitive truth about where attacks actually hide. A data analyst's field notes from the pivot into security.
Jul 176 min read


Mapping the Mirai Botnet to MITRE ATT&CK
Turning raw findings into a threat intelligence report doesn't have to be intimidating. This post walks through mapping a Mirai botnet to MITRE ATT&CK — and explains every tag in plain English, so you can speak the language every SOC team uses.
Jul 137 min read


Saturday Flex: I Was Already Thinking Like a Security Professional — I Just Didn't Know It Yet
When people hear I'm moving from data analytics into cybersecurity, they picture a hard reset. Then I started paying attention to what I'd already been doing — building sandboxes, hunting anomalies, testing before trusting. This is the story of the security instincts I had long before I had the language for them.
Jul 115 min read


Going Deeper — Beacons, a Second Host, and What the Data Confessed
Part 2 of the Zeek threat hunt: using SQL to detect C2 beaconing on a fixed cadence, internal reconnaissance across 771 hosts, and a confirmed SSH intrusion — plus the timeline that showed the network was compromised before the attacker I could see ever logged in.
Jul 1010 min read


From Storm Signatures to Attack Signatures
I spent years reading atmospheric data for the anomaly that didn't belong. Finishing TryHackMe's Intro to Log Analysis room, I found the same instinct waiting in an Apache access log, just a different kind of storm. Here's what the room taught me about command-line triage, regex, attack signatures, and reading the story a log is telling.
Jul 65 min read


Saturday Flex: 4th of July + Cybersecurity Thoughts 🇺🇸💻
Attackers don't log off for fireworks. Holidays don't weaken systems — they change how humans interact with them. And that's usually where risk quietly creeps in.
Jul 42 min read


The End of Obscurity: Why Small Utilities Face Big Cyber Risks in 2026
Small utilities have operated under a comforting assumption for years: 'We're too small for anyone to target.' The data says otherwise. Attackers don't need to know who you are — they just need your IP address to show up in an automated scan.
Jul 33 min read
bottom of page