top of page

The Summer Audit: How Much Progress Did I Actually Make?

Aug 31
5 min read

I don't trust vibes. I trust data.


So instead of telling you summer "went well," I pulled the receipts — certs, commits, posts, tools, the labs that shipped versus the plans I made in June. This is my Week 15 self-assessment, done the only way I know how: honestly, with the evidence on the table.


Here's the thing the evidence told me, though, and I didn't expect it: the plan wasn't learn cybersecurity → follow roadmap → check the boxes. Some of the most consequential things I did this summer weren't boxes at all. Let me show you what I mean.


The scoreboard


Certifications. I passed the ISC2 CC on August 15 — officially September 1. But the arc is the real story. My first attempt on June 20 ended at 90 questions, and I didn't pass. Instead of walking away, I used the domain performance breakdown to find my weak spots, started structured daily study on July 24, and pushed my practice scores up (86% on a mock, 90% on a full 100-question exam) before sitting it again. The retake ran the full CAT to 125 questions. Passed. Then I turned the whole experience — first attempt included, fail-safe vs. fail-secure frustration included — into content instead of hiding it. SC-900 is booked for September 20, with Security+ (SY0-701) lined up for next year.


The road to ISC2 CC — from an interrupted exam to officially certified.


Microsoft security — the surprise August deep-dive. This grew into a bigger chunk than I planned. Entra ID (users, groups, external and workload identities), Conditional Access (learning to read it as an if → then decision engine on signals like user risk, device, and network), all four Purview modules, and the Sentinel learning path — badge earned. The concepts that stuck: Collect → Detect → Investigate → Respond, ML-based alert correlation, MITRE ATT&CK mapping, and turning a successful hunting query into a detection. I even poked at Security Copilot — natural-language incident summaries, plain-English → KQL, AI-assisted triage.


Hands-on work.


  • Splunk — real analysis, not "watched a video." Buttercup Games dataset, 109,864 events, ~86% 200 OKs, and I traced the loudest IP (87.194.216.51, 1,036 requests). The whole exercise was one data-analyst question: what looks different?


  • Mirai botnet investigation (GitHub) — 1.32M Zeek records in SQLite, C2 beaconing at a ~755-second cadence, a propagation scanner throwing 338K+ external connection attempts, and an SSH intrusion I traced back to recon that preceded it by ~28 hours. Ten SQL query files, findings summary, full incident timeline.


  • Network anomaly detection pipeline (GitHub) — 2.8M CIC-IDS-2017 flows through IsolationForest, tuned to 48.4% precision / 36.9% recall.


  • MISP — first lab, blog post published, and I documented the things that confused me (stored vs. displayed value, pivoting from a domain to registrant info) instead of pretending it went clean.


  • TryHackMe — Linux Fundamentals, Intro to Log Analysis, Offensive and Defensive Security Intros, Search Skills. Linux → logs → offense → defense → investigation.


Writing. Eight-plus substantial posts across July and August: the Bingo Board piece, the ISC2 CC exam investigation, the "skill that follows you from dashboard to SOC," scenario-based study, the retake debrief, the MISP lab, "Behind the Screens: Building DataSec Chronicles," and this audit. All on the cadence I set in June.


Reach — mostly unplanned. @DataSecChron climbed from ~50 to nearly 400 followers. My CC pass post hit ~10K views. A completely ordinary job-hunting reply somehow exploded to ~28K views. People started DMing for advice, asking about CC resources, asking how I was managing all of it — and those questions literally reshaped my editorial roadmap.


What surprised me


Two things.


The first was the ISC2 CC glitch. I expected to study hard. I did not expect the hardest part to be investigating my own exam — pulling apart what happened at question 90 and turning it into one of my most-read posts of the summer. The anomaly-detection instinct I built in atmospheric science doesn't switch off when the subject is my own testing session.


The second was that the community started steering the content. I wasn't planning to build an audience. The same question kept landing in my DMs — how are you doing all of this? — and it became "Behind the Screens," which led straight into this retrospective. The audience I didn't plan for wrote part of my roadmap for me.


What I changed course on — on purpose


Here's the part I want to be honest about, because it's the most useful lesson of the fifteen weeks.


I had a Wireshark home-networking deep-dive slotted for a Monday. I looked at my actual capacity that week and said: I cannot realistically do this justice right now. So I moved it. Not "learned Wireshark ✓" — deliberately deferred deeper networking work rather than forcing a half-baked project because the calendar said so.


That's not failing to follow the plan. That's using the roadmap as a decision tool instead of a prison. The summer wasn't make roadmap → follow roadmap → done. It was roadmap → learn → discover → adjust → build → reassess → repeat. Every time I hit a wall or a better idea, I let the plan bend.


The boxes that were never on the roadmap


This is where the audit gets interesting, because the two biggest things I built this summer were nowhere in the original plan.


Planned vs. actual — the best moves weren't on the plan.


DataSec Labs. DataSec Chronicles was always the content side. Then I built the hands-on side from scratch — interactive labs, quizzes, scenarios, study tools, a dedicated site, and the GitHub Pages infrastructure under it. None of that was in June's plan.


Case File 01: The Silent Intercept. One attacker. Seven indicators. One chain. Instead of explaining an attack chain in another ordinary post, I turned it into a playable mystery — a case narrative, seven daily clues, a crossword-style investigation grid, UNSOLVED/SOLVED states, a countdown, a time-locked verdict, Field Notes, a two-page PDF, and a full week of launch and daily-clue content. It ran August 25–31, and the verdict drops tonight at 8 PM ET — the same night this audit publishes. The lesson is baked into the game itself: initial access → escalation → spread → reach → objective → detection. The order matters.


I also built a ~40-page Foundations Workbook (Quick Start Guide, Bingo Board, checklist) and launched it into the ecosystem. On the original roadmap? Not one of these.


The through-line


Every single one of these — the Zeek beaconing cadence, the IsolationForest tuning, the exam-glitch investigation, even the puzzle mechanics of Case File 01 — is the same move I've been making since grad school: find the thing that doesn't belong.


I found an old 2014 letter I'd written to Ebony, just after finishing my atmospheric science master's at Howard, talking about STEM and representation. Reading it now, the pattern was already there. I was always chasing signals in complex systems. Atmospheric anomalies → data anomalies → security anomalies. The tool changes, the question doesn't. 💜


So — how much progress did I actually make?


If I score it against June's roadmap, I didn't check every box. I moved one, skipped a couple of sandboxed tutorials I'd now trade for messier real data, and let SC-900 slide into September.


That's the wrong scoreboard.


The right answer is that I started with a cybersecurity roadmap, and fifteen weeks later I looked at the evidence to see whether it was actually working. It was — just not in the shape I drew in June. The most consequential things I built weren't on the plan at all. The instinct underneath all of it turned out to be completely portable, with the receipts to prove it.


That's the audit result. Not the commit count. The through-line.



This was my Week 15 self-assessment. If you're mid-transition too, do the audit — real evidence, not vibes. You'll be surprised by what you undersold, and by which of your best moves were never in the plan.


the tool changes · the question doesn't

Comments


Let's learn this together. Have a question, a better query, or just want to say hi? Drop a line below.

© 2026 by DataSec Chronicles. Data-Inspired, Instinct-Driven.    Privacy Policy    Terms & Conditions

bottom of page