top of page


Week 1 Deep Dive: Locking Down Your Digital Identity
Week 1 of 31 Days Safer, one layer deeper. The daily tips gave you the moves; this post gives you the why — how credential stuffing, SIM-swapping, and social-media recon actually work, and why your accounts are a chain attackers pull at the weakest link. Non-technical, but technically accurate.
2 days ago6 min read


My Two October Builds: 31 Days Safer + an Open-Source Detection Skill
What I'm building this October: two anchor projects — the 31 Days Safer challenge and an open-source detection skill that maps alerts to MITRE ATT&CK — plus an "open workbench" where Hacktoberfest's weekly challenges are letting me explore what else I can build within the brand.
4 days ago4 min read


The Detection Mindset: Why This Isn't Your Average Hygiene Challenge
There are a hundred cybersecurity challenges this October, and most are the same checklist. This one's different: it teaches the reason behind every habit, not just the rule — the "does this belong here?" detection lens a SOC analyst uses on every alert, aimed at your own digital life.
5 days ago5 min read


31 Days Safer: A Digital Hygiene Challenge for Cybersecurity Awareness Month
Everyone knows not to click the link — but nobody explains why. 31 Days Safer is a month-long digital hygiene challenge that gives you one small security habit a day, plus the threat behind each one. Free tracker included. Small steps for a safer digital life, from DataSec Chronicles.
Sep 284 min read


My Hacktoberfest 2026 Plan: An Open-Source Detection Skill (Not a PR Count)
Hacktoberfest changed this year — no more counting pull requests, it's about building with open-source AI. So I'm writing an open-source skills.md that maps a security alert to the MITRE ATT&CK framework: the daily reasoning of a SOC analyst, packaged in public. Here's the plan, out loud so I finish it.
Sep 264 min read


Closing the Gap: How I'm Prepping for the SC-900 Retake
The comeback half of my SC-900 story. After failing by 32 points, I scored 90% on the Microsoft practice assessment four days later. Here's how I'm closing the gap: letting my score report target the right domain, drilling the formats that beat me, and knowing what each practice source can and can't tell me.
Sep 256 min read


SC-900 Debrief: The Honest Version
The honest version of my SC-900 exam experience: I scored 668/700, 32 points short. How the online-proctored setup compared to my CC exam, the true/false and drag-and-drop formats that caught me, what my score report revealed, and exactly how I'm approaching the retake.
Sep 215 min read


Zero Trust, Defender & Sentinel: Making Sense of Microsoft's Security Stack
Microsoft has a Defender for everything, a SIEM with a sci-fi name, and a Zero Trust philosophy that gets name-dropped into meaninglessness. Here's the SC-900 Security Solutions stack untangled — what each tool does, how Zero Trust, the Defenders, XDR, and Sentinel connect, and where a data mindset already fits.
Sep 185 min read


You're Not Starting Over: Translating Data Experience Into Cybersecurity
You already have the analytical muscle memory cybersecurity hiring managers are looking for — you just describe it in the wrong dialect. Here's how to translate years of SQL, anomaly detection, and log work into the language SOC teams actually hire for, plus a two-question test to audit your own resume: which experience transfers, and which gaps you still need to build.
Aug 286 min read


Building My GitHub Cybersecurity Portfolio (What I'm Including and Why)
What to put in a cybersecurity portfolio when you're coming from a data background — how to structure it, what each project signals to a recruiter, and how to know which roles are actually your lane. Plus a free bingo board to start today.
Aug 76 min read


My First 3 Splunk Queries: Finding the Loudest IP on the Network
I loaded 109,864 events into Splunk and went hunting for the noisiest host on the network. My first query found a suspect. My next two proved it innocent — and somewhere in the middle I realized I'd been writing this query language for ten years without knowing its name.
Aug 37 min read


Saturday Flex: I Was Already Thinking Like a Security Professional — I Just Didn't Know It Yet
When people hear I'm moving from data analytics into cybersecurity, they picture a hard reset. Then I started paying attention to what I'd already been doing — building sandboxes, hunting anomalies, testing before trusting. This is the story of the security instincts I had long before I had the language for them.
Jul 115 min read


Going Deeper — Beacons, a Second Host, and What the Data Confessed
Part 2 of the Zeek threat hunt: using SQL to detect C2 beaconing on a fixed cadence, internal reconnaissance across 771 hosts, and a confirmed SSH intrusion — plus the timeline that showed the network was compromised before the attacker I could see ever logged in.
Jul 1010 min read
bottom of page