top of page


The 20-minute lab that took me 42
The module said 20 minutes. It took me 42 — and those extra minutes are the whole post. My first run through MISP, the Malware Information Sharing Platform: how threat intel platforms turn one indicator into a resolved IP, a registrant email, and a whole map of an adversary's infrastructure. Plus the search bug I caught in my own technique that a decade with data should have caught sooner.
3 days ago5 min read


ISC2 CC Retake Debrief- Round 2: and this time, it let me finish.
My first ISC2 CC exam attempt ended at question 90. On the retake, it ran the full 125 — and I passed. Here's what I did differently, and what's next.
7 days ago6 min read


The Day Before: Where My Head Is Going Into Round 2
The first time I sat the ISC2 CC, I was writing into a fog — a first attempt at a machine I hadn't touched yet. This time is different. I've been inside the exam, I know the terrain, and the prep this round was targeted at the specific gaps. Here's where my head is the day before Round 2 — grounded readiness, not anxious anticipation. 💜
Aug 142 min read


How I'm Studying Scenario-Based Questions Differently for the ISC2 CC
On the ISC2 CC, the scenario questions are a different animal from the knowledge questions — and they're where a lot of people freeze. "What should you do FIRST?" isn't testing what you know; it's testing how you choose. Here's how I'm studying them differently: ISC2's Least/Most/Best framework, reading the call word before the options, and budgeting judgment practice separately from recall. 💜
Aug 105 min read


The Skill That Follows You From Dashboard to SOC
Every cyber-career video says "it's the soft skills." Almost none of them show you what that actually looks like. So here's mine: I caught data-integrity failures in a vendor's returned results, took the finding to three different rooms, and watched them change their process. That's the one skill that quietly carries a data analyst into a SOC — and you already have more of it than you think.
Aug 86 min read


Building My GitHub Cybersecurity Portfolio (What I'm Including and Why)
What to put in a cybersecurity portfolio when you're coming from a data background — how to structure it, what each project signals to a recruiter, and how to know which roles are actually your lane. Plus a free bingo board to start today.
Aug 76 min read


My First 3 Splunk Queries: Finding the Loudest IP on the Network
I loaded 109,864 events into Splunk and went hunting for the noisiest host on the network. My first query found a suspect. My next two proved it innocent — and somewhere in the middle I realized I'd been writing this query language for ten years without knowing its name.
Aug 37 min read
bottom of page