top of page


Week 1 Deep Dive: Locking Down Your Digital Identity
Week 1 of 31 Days Safer, one layer deeper. The daily tips gave you the moves; this post gives you the why — how credential stuffing, SIM-swapping, and social-media recon actually work, and why your accounts are a chain attackers pull at the weakest link. Non-technical, but technically accurate.
2 days ago6 min read


My Two October Builds: 31 Days Safer + an Open-Source Detection Skill
What I'm building this October: two anchor projects — the 31 Days Safer challenge and an open-source detection skill that maps alerts to MITRE ATT&CK — plus an "open workbench" where Hacktoberfest's weekly challenges are letting me explore what else I can build within the brand.
4 days ago4 min read


The Detection Mindset: Why This Isn't Your Average Hygiene Challenge
There are a hundred cybersecurity challenges this October, and most are the same checklist. This one's different: it teaches the reason behind every habit, not just the rule — the "does this belong here?" detection lens a SOC analyst uses on every alert, aimed at your own digital life.
5 days ago5 min read


31 Days Safer: A Digital Hygiene Challenge for Cybersecurity Awareness Month
Everyone knows not to click the link — but nobody explains why. 31 Days Safer is a month-long digital hygiene challenge that gives you one small security habit a day, plus the threat behind each one. Free tracker included. Small steps for a safer digital life, from DataSec Chronicles.
Sep 284 min read


My Hacktoberfest 2026 Plan: An Open-Source Detection Skill (Not a PR Count)
Hacktoberfest changed this year — no more counting pull requests, it's about building with open-source AI. So I'm writing an open-source skills.md that maps a security alert to the MITRE ATT&CK framework: the daily reasoning of a SOC analyst, packaged in public. Here's the plan, out loud so I finish it.
Sep 264 min read


The Summer Audit: How Much Progress Did I Actually Make?
I don't trust vibes. I trust data. So instead of saying summer "went well," I pulled the receipts — certs, tools, investigations, posts — and found the most consequential things I built were never on the roadmap.
Aug 315 min read


The Cons I'm Actually Trying To Get To
I haven't been to a hacker con yet — so I built the shortlist. Where I'm trying to be, in what order, and why: local meetups now, BSides and WiCyS in the spring, and DEF CON by 2027.
Aug 294 min read


You're Not Starting Over: Translating Data Experience Into Cybersecurity
You already have the analytical muscle memory cybersecurity hiring managers are looking for — you just describe it in the wrong dialect. Here's how to translate years of SQL, anomaly detection, and log work into the language SOC teams actually hire for, plus a two-question test to audit your own resume: which experience transfers, and which gaps you still need to build.
Aug 286 min read


Behind the Screens: Building DataSec Chronicles
There's no content team behind DataSec Chronicles. There's just me, a full-time career, a family, and a lot of open tabs. Here's how I actually build all of this — and what I'd tell anyone asking where to start.
Aug 246 min read


The 20-minute lab that took me 42
The module said 20 minutes. It took me 42 — and those extra minutes are the whole post. My first run through MISP, the Malware Information Sharing Platform: how threat intel platforms turn one indicator into a resolved IP, a registrant email, and a whole map of an adversary's infrastructure. Plus the search bug I caught in my own technique that a decade with data should have caught sooner.
Aug 215 min read


The Skill That Follows You From Dashboard to SOC
Every cyber-career video says "it's the soft skills." Almost none of them show you what that actually looks like. So here's mine: I caught data-integrity failures in a vendor's returned results, took the finding to three different rooms, and watched them change their process. That's the one skill that quietly carries a data analyst into a SOC — and you already have more of it than you think.
Aug 86 min read


Building My GitHub Cybersecurity Portfolio (What I'm Including and Why)
What to put in a cybersecurity portfolio when you're coming from a data background — how to structure it, what each project signals to a recruiter, and how to know which roles are actually your lane. Plus a free bingo board to start today.
Aug 76 min read


My First 3 Splunk Queries: Finding the Loudest IP on the Network
I loaded 109,864 events into Splunk and went hunting for the noisiest host on the network. My first query found a suspect. My next two proved it innocent — and somewhere in the middle I realized I'd been writing this query language for ten years without knowing its name.
Aug 37 min read


The Install That Fought Back: Setting Up Splunk on a Mac
I set out to install Splunk Free and write a tidy walkthrough. Instead I hit four errors, discovered the tutorial was built for a machine that isn't mine, and had to force-restart my laptop — and learned more than a clean install ever would have taught me.
Jul 318 min read


I Turned My Cybersecurity Path Into a Bingo Board (Vol. 1: Foundations)
Cybersecurity felt like forty open tabs and no idea where to start. So I turned the whole path into a bingo board — 25 beginner steps, in any order.
Jul 205 min read


Linux Fundamentals: A Data Analyst in the Terminal
The terminal stops being scary the moment you realize it's just asking questions. Ten years of querying data, and my first real Linux command line turned out to be full of familiar instincts — plus a few places where that familiarity ran out.
Jul 186 min read


Uncovering Hidden Threats: My Journey from Data Analytics to Cybersecurity
No cloud account, no labeled attack data — just SQL and Python on 2.8 million network flows. An Isolation Forest flagged suspicious traffic blind, and tuning it surfaced a counterintuitive truth about where attacks actually hide. A data analyst's field notes from the pivot into security.
Jul 176 min read


Saturday Flex: I Was Already Thinking Like a Security Professional — I Just Didn't Know It Yet
When people hear I'm moving from data analytics into cybersecurity, they picture a hard reset. Then I started paying attention to what I'd already been doing — building sandboxes, hunting anomalies, testing before trusting. This is the story of the security instincts I had long before I had the language for them.
Jul 115 min read


Unboxing TryHackMe: A Data Analyst Steps Into the Cybersecurity 101 Path
I finally opened TryHackMe — and Module 1 hit differently than I expected. Three rooms, one mystery chest, and a data analyst moment I didn't see coming. Here's what I found in Offensive Security, Defensive Security, and Search Skills through a data analyst's eyes.
Jun 297 min read


You Don't Have to Be a Hacker: Entry Points into Cybersecurity for Non-Tech People
The cybersecurity field is wider than the movies make it look. GRC, security awareness, data analytics, helpdesk, incident response — these are real doors into a field that needs far more than hackers. Here's a map of the entry points, and why your current background is probably worth more than you think.
Jun 226 min read
bottom of page