My Two October Builds: 31 Days Safer + an Open-Source Detection Skill
Every October is Cybersecurity Awareness Month, and this year I'm not just talking about security — I'm building in the open, all month. Two anchor projects are carrying the month. One is for everyone. One is for me. Both come from the same instinct.
There's a third thing happening around the edges that I didn't fully plan: Hacktoberfest's weekly challenges are turning into a space to explore — to try building things within my brand and see what sticks. More on that at the end.
Here's what I'm making, and why the two anchors are really the same project wearing two outfits.
Build one: 31 Days Safer
The public-facing one. 31 Days Safer is a month-long challenge — one small, doable security habit a day, across the blog and my socials, with a free tracker to follow along. Passwords, MFA, your home router, your phone, your daily habits. Under ten minutes a day, no experience required.
But — and if you've read this blog, you saw this coming — it's not another "enable 2FA" listicle. Every habit comes with the threat it defends against, because once you see what a practice is actually protecting you from, it stops being a chore and starts being a move you understand. That's the detection lens: don't just do the thing, know what doesn't belong and why. (The challenge kicked off this week — you can still jump in on any day.)
Build two: an open-source detection skill
The one that's really for me — my Hacktoberfest project.
Hacktoberfest changed this year: no more counting pull requests; it's about building with open-source AI. So I'm writing an open-source skills.md — a small, reusable, public artifact that does one specific job: take a security alert and map it to the MITRE ATT&CK framework. That's the daily reasoning a SOC analyst runs on every alert — what technique is this, where does it sit in the attacker's playbook, what's next? — packaged so anyone can reuse it.
I'll have more to say about it later this month once it's further along (and yes, I'll show you the actual file — this blog runs on show, not tell). For now: it's on the workbench, and building it in public is how I make sure I finish it.
Why these are the same build
Here's the part that made me smile when it clicked.
31 Days Safer teaches everyday people to look at their own digital life and ask, "does this belong here?" — is this login normal, is this email really from who it says, is this app doing something it shouldn't. The detection skill teaches a machine to ask the exact same question about a security alert.
Spotting a phishing email in your inbox and mapping an anomalous login to an attack technique are the same instinct at different scales: finding what doesn't belong, and naming what it is. That's the whole storm-to-SOC throughline — the anomaly-detection reflex I built chasing weather data, pointed in two directions at once this month. One at your digital life, one at a SOC console.
Same question. Different scale. That's October.
The open workbench
Those two anchors are the plan. But Hacktoberfest changed its format this year — it's now a series of weekly build challenges — and I've been treating them as something I didn't expect to enjoy this much: an open workbench. A low-stakes space to ask: what can I actually build within this brand? and just try.
The first experiment already happened. Over one weekend I built a small AI-powered phishing checker — paste in a suspicious email, and an open-weight model walks you through the red flags in plain language. It's the exact detection lens from 31 Days Safer, turned into a working tool. (Its own write-up is coming — I want to do it justice.)
Will I do every weekly challenge? No — only the ones whose theme genuinely fits my lane, and only when I've got the room. This isn't a commitment to five projects; it's permission to experiment when a prompt sparks something. But I'll be honest: finding out I like building these — that the storm-to-SOC instinct translates into actual tools, not just posts — has been the best surprise of the month. So more may come. We'll see what the themes bring.
How I'd explain this in a SOC interview
Ask me what I do outside of a day job to grow into this field, and here's the answer: I build in public — one artifact people can use, and one that proves a specific skill. This month that's a public security-awareness challenge and an open-source alert-to-ATT&CK mapping skill, and I commit to them out loud precisely because a public commitment is what gets them finished. That's the same discipline that makes a good analyst: you don't just learn a concept, you produce something real with it and put your name on it. The difference between a skill you can name and one you can show is the whole game — and October is me showing up to the workbench, anchors first, to show rather than tell.
Follow along with 31 Days Safer if you want a safer digital life, watch this space for the detection skill, and keep an eye on the workbench. Two anchors, one instinct, and an open invitation to build — all in one month.
Storm to SOC — read the map, then move. 💜



Comments