top of page


My Two October Builds: 31 Days Safer + an Open-Source Detection Skill
What I'm building this October: two anchor projects — the 31 Days Safer challenge and an open-source detection skill that maps alerts to MITRE ATT&CK — plus an "open workbench" where Hacktoberfest's weekly challenges are letting me explore what else I can build within the brand.
4 days ago4 min read


My Hacktoberfest 2026 Plan: An Open-Source Detection Skill (Not a PR Count)
Hacktoberfest changed this year — no more counting pull requests, it's about building with open-source AI. So I'm writing an open-source skills.md that maps a security alert to the MITRE ATT&CK framework: the daily reasoning of a SOC analyst, packaged in public. Here's the plan, out loud so I finish it.
Sep 264 min read


Closing the Gap: How I'm Prepping for the SC-900 Retake
The comeback half of my SC-900 story. After failing by 32 points, I scored 90% on the Microsoft practice assessment four days later. Here's how I'm closing the gap: letting my score report target the right domain, drilling the formats that beat me, and knowing what each practice source can and can't tell me.
Sep 256 min read


SC-900 Debrief: The Honest Version
The honest version of my SC-900 exam experience: I scored 668/700, 32 points short. How the online-proctored setup compared to my CC exam, the true/false and drag-and-drop formats that caught me, what my score report revealed, and exactly how I'm approaching the retake.
Sep 215 min read


The Morning Before the SC-900: Where My Head Is Right Now
Tomorrow I sit the SC-900. This morning, I’m taking stock of where my head is — what feels different from my last certification attempt, what the practice numbers taught me, and the calm that comes from knowing I prepared honestly.
Sep 192 min read


Zero Trust, Defender & Sentinel: Making Sense of Microsoft's Security Stack
Microsoft has a Defender for everything, a SIEM with a sci-fi name, and a Zero Trust philosophy that gets name-dropped into meaninglessness. Here's the SC-900 Security Solutions stack untangled — what each tool does, how Zero Trust, the Defenders, XDR, and Sentinel connect, and where a data mindset already fits.
Sep 185 min read


SC-900 Domains Decoded: What a Data Analyst Already Knows (And What's New)
Nine years in data turned out to be worth more on SC-900 than I expected — but not everywhere. A domain-by-domain walkthrough of all four SC-900 skill areas, mapped honestly to a data-analyst background: what already transfers, what's brand-new, and where my real practice gap still sits.
Sep 146 min read


My First Online-Proctored Exam: Setting Up So Nothing Surprises Me
SC-900 on September 20 is my first online-proctored exam — and after a test-center anomaly ended my first CC attempt, I'm controlling every variable I can. Here's my OnVUE system-test walkthrough, the admission rules that actually matter, and the exam-day checklist I built from them.
Sep 124 min read


SC-900 Explored: My Honest Practice Numbers
The honest middle of cert prep. I scored 62% on a full-length SC-900 practice exam, lost momentum during a busy week, then got it back with targeted drilling. Here are my real numbers, where my misses still cluster (Compliance), the tools I'm using, and my final-week plan.
Sep 114 min read


Why I Added SC-900 to My Plate (While Studying for the CC Retake)
I added SC-900 to an already-full August — mid-CC-retake, deep in camp season. Here's the honest version: the free voucher I refused to waste, why I swapped down from SC-200, the 40% cold baseline that sealed it, and how two exams became one reinforcing study block.
Sep 76 min read


My Cert Stack: SC-900 in September, Security+ in Early 2027 — Here's Why I Won't Book It Yet
I booked SC-900 for September — then deliberately didn't set a Security+ date. Here's why the missing date is the strategy, not a lack of one: what finishing the full SC-900 course taught me about pacing and what an honest, unrushed path to Security+ actually looks like.
Sep 45 min read


The Summer Audit: How Much Progress Did I Actually Make?
I don't trust vibes. I trust data. So instead of saying summer "went well," I pulled the receipts — certs, tools, investigations, posts — and found the most consequential things I built were never on the roadmap.
Aug 315 min read


The Cons I'm Actually Trying To Get To
I haven't been to a hacker con yet — so I built the shortlist. Where I'm trying to be, in what order, and why: local meetups now, BSides and WiCyS in the spring, and DEF CON by 2027.
Aug 294 min read


You're Not Starting Over: Translating Data Experience Into Cybersecurity
You already have the analytical muscle memory cybersecurity hiring managers are looking for — you just describe it in the wrong dialect. Here's how to translate years of SQL, anomaly detection, and log work into the language SOC teams actually hire for, plus a two-question test to audit your own resume: which experience transfers, and which gaps you still need to build.
Aug 286 min read


The 20-minute lab that took me 42
The module said 20 minutes. It took me 42 — and those extra minutes are the whole post. My first run through MISP, the Malware Information Sharing Platform: how threat intel platforms turn one indicator into a resolved IP, a registrant email, and a whole map of an adversary's infrastructure. Plus the search bug I caught in my own technique that a decade with data should have caught sooner.
Aug 215 min read


ISC2 CC Retake Debrief- Round 2: and this time, it let me finish.
My first ISC2 CC exam attempt ended at question 90. On the retake, it ran the full 125 — and I passed. Here's what I did differently, and what's next.
Aug 176 min read


The Day Before: Where My Head Is Going Into Round 2
The first time I sat the ISC2 CC, I was writing into a fog — a first attempt at a machine I hadn't touched yet. This time is different. I've been inside the exam, I know the terrain, and the prep this round was targeted at the specific gaps. Here's where my head is the day before Round 2 — grounded readiness, not anxious anticipation. 💜
Aug 142 min read


Building My GitHub Cybersecurity Portfolio (What I'm Including and Why)
What to put in a cybersecurity portfolio when you're coming from a data background — how to structure it, what each project signals to a recruiter, and how to know which roles are actually your lane. Plus a free bingo board to start today.
Aug 76 min read


The Install That Fought Back: Setting Up Splunk on a Mac
I set out to install Splunk Free and write a tidy walkthrough. Instead I hit four errors, discovered the tutorial was built for a machine that isn't mine, and had to force-restart my laptop — and learned more than a clean install ever would have taught me.
Jul 318 min read


From Storm Signatures to Attack Signatures
I spent years reading atmospheric data for the anomaly that didn't belong. Finishing TryHackMe's Intro to Log Analysis room, I found the same instinct waiting in an Apache access log, just a different kind of storm. Here's what the room taught me about command-line triage, regex, attack signatures, and reading the story a log is telling.
Jul 65 min read
bottom of page