Blog
-
📅 Day 244 — Writing an Incident Handler Journal Entry for a Ransomware Scenario With the Five W’s
-
📅 Day 243 — Building a Work Summary Tool That Says 'Not Proven' When Evidence Is Missing
-
📅 Day 242 — Testing a Voice Command Path That Starts Coding-Agent Jobs from Telegram
-
📅 Day 241 — Keeping a Daily Status Digest from Becoming a Transcript Archive
-
📅 Day 240 — Finding a Setting That Was Correct in the File but Wrong in the Running Service
-
📅 Day 239 — Turning a Message into a Calendar Event Safely: Evidence, Dates, Duplicates
-
📅 Day 238 — Extending an Outgoing-Message Guard to Check the Message It Replies To
-
📅 Day 237 — Reviewing Which Tools a Messaging Agent Can Really Use
-
📅 Day 236 — Testing a Messaging Bot's Final Message Instead of the Model's First Output
-
📅 Day 235 — Writing a Vulnerability Assessment Report for an Internet-Exposed Database (Simulated)
-
📅 Day 234 — Assessing a Found USB Drive as a Data-Leak and Malware Risk
-
📅 Day 233 — OSINT: Turning Public Information into Security Intelligence (Google Cybersecurity Certificate)
-
📅 Day 232 — Defense in Depth, CVE, CVSS and the OWASP Top 10 (Google Cybersecurity Certificate)
-
📅 Day 231 — Vulnerability Management and CI/CD Pipeline Security (Google Cybersecurity Certificate)
-
📅 Day 230 — Access Control: AAA, IAM, and a Contractor Account Left Active for Four Years
-
📅 Day 229 — Hash Functions and Why They Are Not Encryption (Google Cybersecurity Certificate)
-
📅 Day 228 — How PKI Combines Symmetric and Asymmetric Encryption (Google Cybersecurity Certificate)
-
📅 Day 227 — SQL JOINs for Combining Security Logs (Google Cybersecurity Certificate)
-
📅 Day 226 — Data Privacy: Lifecycle, Ownership and Handoffs (Google Cybersecurity Certificate)
-
📅 Day 225 — Asset Security: From Inventory to Classification (Google Cybersecurity Certificate)
-
📅 Day 224 — SQL for Security Triage: Filtering Logins by Date, Time and Number
-
📅 Day 223 — Basing Website Security Claims on What a Real Browser Shows
-
📅 Day 222 — Moving a Message Safety Filter to the Final Delivery Step
-
📅 Day 221 — Handling a Leaked Bot Token: Removing It from Code Is Not Revoking It
-
📅 Day 220 — Finding That an Empty Tool List Meant 'Inherit Everything', Not 'Deny All'
-
📅 Day 219 — Upgrading a Live Service and Proving Which Commit Is Actually Running
-
📅 Day 218 — Verifying That an Agent Really Ran a Skill Before Accepting Its PDF Report
-
📅 Day 217 — Connecting Home Assistant to a Mac's Wake and Sleep with Minimal Access
-
📅 Day 216 — Building Remote Power Control for a Mac over Telegram, with Two Sender Checks
-
📅 Day 215 — Finding Why a Scheduled Watchdog Never Ran: The Scheduler Rejected a Symlink
-
📅 Day 214 — Building an Encrypted Off-Host Backup and Proving It Restores on Another Machine
-
📅 Day 213 — Unifying Agent Memory into One Source-Attributed Retrieval Path
-
📅 Day 212 — Choosing a Local Coding Model by Measuring Repeated Full Rounds
-
📅 Day 211 — Building a Relay Between ChatGPT and a Local Coding Agent, Guarded Against Stale and Duplicate Messages
-
📅 Day 210 — Fixing an Unattended Job That Kept Picking the Same Files and Starved the Rest
-
📅 Day 209 — Fixing a Watchdog That Mistook a Network Failure for an Expired Credential
-
📅 Day 208 — Adding a Live Trial Because Passing Fixture Tests Did Not Prove a Local Model Was Ready
-
📅 Day 207 — Gating the One Scheduled Message a Bot May Send Without Being Asked
-
📅 Day 206 — Requiring a Recent Incoming Message Before a Bot May Reply, Once
-
📅 Day 205 — Fixing a Bot That Said Good Night at 11:24 in the Morning (Stale Cached Time)
-
📅 Day 204 — Shadow-Testing a New Briefing Feature Before It Reaches Anyone
-
📅 Day 203 — A Config Cap That Deadlocked the Gateway, and a Prefix Match That Nearly Revoked the Wrong User
-
📅 Day 202 — Giving an Agent Write Access to My Calendar Without Giving It Delete
-
📅 Day 201 — Locking Down a New WhatsApp Channel: Too Many Tools, Too Much Trust in the Sender
-
📅 Day 200 — Red-Teaming My Own Chatbot: Building an Adversarial Persona Harness
-
📅 Day 199 — Investigating an Unexplained Mac Shutdown and Restricting Who Can Power It Off
-
📅 Day 198 — Testing My Personal-Data Policy Gate with Phone Location
-
📅 Day 197 — Adding a Secret Scan Before Every Push to a New Repository
-
📅 Day 196 — Four Bugs, One Pattern: Code That Claimed Success Without Proof
-
📅 Day 195 — Fixing a Bug Where Narration Text Was Executed as a Task
-
📅 Day 194 — Stopping the AI Secretary from Writing and Sending Email on Its Own
-
📅 Day 193 — Auditing My Phone-Approval Gate: Wrong Identity Key, Silent Policy Hook, Exposed Webhook
-
📅 Day 192 — SQL Labs: Filtering with WHERE and LIKE, Sorting with ORDER BY
-
📅 Day 191 — Building a Watchdog for Expiring Credentials and Proving the Alarm Fires
-
📅 Day 190 — Closing the Observation Backlog: Two New Skills Born From Real Recurring Bugs
-
📅 Day 189 — Retiring Aider Properly, and Making Agents Land Their Own Work
-
📅 Day 188 — Giving Agent Memory Real Sources, and Routing Trivial Turns to a Small Model
-
📅 Day 187 — Making Email Verification Prove Delivery, Not Just Sending
-
📅 Day 186 — Fixing a Citation Check That Treated a Matching Hash as Trust
-
📅 Day 185 — Turning Two Log-Only Guards into Guards That Block
-
📅 Day 184 — Fixing a Self-Certification Check That a Unicode Lookalike Could Bypass
-
📅 Day 183 — The Fix Had Two More Holes: A Live DNS-Rebinding Bypass Hunt
-
📅 Day 182 — Building an SSRF-Safe Fetcher for an Agent That Reads the Web
-
📅 Day 181 — Using Linux Help Before Making a Change
-
📅 Day 180 — Reviewing a Skill Catalog and Installing Only a Small Allowlist
-
📅 Day 179 — Extracting Useful Text Without Giving an Agent a Browser
-
📅 Day 178 — Testing Whether a Codebase Index Actually Helps Find Evidence
-
📅 Day 177 — Choosing Tools by Evidence, Not by Novelty
-
📅 Day 176 — Execution Depth Presets, a Broken Build, and Unit Tests for the Small Stuff
-
📅 Day 175 — Unattended Delegation: Which Lanes Are Allowed to Work While I Sleep
-
📅 Day 174 — Shadow Trials: Letting the New Router Watch Before It Acts
-
📅 Day 173 — Provenance and Recovery: Knowing Who Changed What, and Undoing It
-
📅 Day 172 — Parallel Agents Without Collisions: Task Graphs and Git Worktrees
-
📅 Day 171 — Five Ways My Automation Faked Success (and the Fail-Closed Fixes)
-
📅 Day 170 — Making Security Work Clear Without Overselling It
-
📅 Day 169 — Why Safe Rollouts Use Feature Flags, Fixtures, and Evidence Gates
-
📅 Day 168 — Secure Artifact Delivery: Narrow Links, Verified Bytes, and No Duplicate Sends
-
📅 Day 167 — Approval-Gated Automation: Making Privileged Agent Work Accountable
-
📅 Day 166 — Resilient Sessions: What a Torn Journal Taught Me About Safe AI State
-
📅 Day 165 — Bounded Context, Better Decisions: Testing AI Agent Memory Without Blind Trust
-
📅 Day 164 — Verifying the Verifier: A False-Positive Streak in My Own Checks
-
📅 Day 163 — Model Fleet Ops: Migrating the Coding Lane to Gemma and Budgeting Tokens Like a Resource
-
📅 Day 162 — An AI Secretary With a Kill Switch: Calendars, Sender Policy, and Emergency Control
-
📅 Day 161 — Hardening the iOS Companion: Untrusted Links, Redacted Errors, and the 'Full Power' Question
-
📅 Day 160 — Tailscale Broke My Stack: Node Identity, Hostnames, and Private Services
-
📅 Day 159 — Widening an Agent's Write Scope on Purpose (and Making Its Findings Earn Evidence)
-
📅 Day 158 — Gated Autonomy: A Phone Approval Loop Before Any Agent Sends Anything
-
📅 Day 157 — WebCheckup: Turning the Mini-Audit Into a Real Multilingual Service
-
📅 Day 156 — Too Many Projects: Auditing My Own Tool Sprawl Like an Asset Inventory
-
📅 Day 155 — Linux User and Group Management as Access Control Practice
-
📅 Day 154 — Building a Cybersecurity Glossary Without Breaking My Notes
-
📅 Day 153 — Testing Hermes Agent: Strong First Builds, Weak Self-Verification
-
📅 Day 152 — Building an AI Inference Orchestrator With Routing, Retries, and Cost Awareness
-
📅 Day 151 — Benchmarking My Local LLM Stack Instead of Trusting Vibes
-
📅 Day 150 — Remote Agent Hub and the Discipline of Honest Feature Labels
-
📅 Day 149 — Turning My iPhone Into a Command Center for Local Agents
-
📅 Day 148 — Building Least-Privilege Tool Profiles for My AI Agents (and Finding My Own Risk Scorer Was Inverted)
-
📅 Day 147 — 'Build Succeeded' Isn't Proof: Writing a Real UI Test for the Auth Flow
-
📅 Day 146 — Giving My Local Agent Daemon Real Auth (And Almost Leaking the Token in the 401 Page)
-
📅 Day 145 — Productizing a Website Security Mini-Audit, and Finding an Access Gap in My Own Funnel
-
📅 Day 144 — A 348-Term Glossary and the False Positives That Came With It
-
📅 Day 143 — Building a Local MITRE ATT&CK Technique Library from My Own Notes
-
📅 Day 142 — Benchmarking an Autonomous Agent: Strong One-Shot Builds, Unreliable Self-Debugging
-
📅 Day 141 — A Human Memory Layer: The RAG Vault My Agents Write and I Read Anywhere
-
📅 Day 140 — AI-OS: Governance, Routing, and a Verification Gateway for My Local Agents
-
📅 Day 139 — Benchmarking a Local LLM Coding Stack: Harness, Routing, and Review Findings
-
📅 Day 138 — An iOS Companion for My Local Agent, Private by Design
-
📅 Day 137 — Running DS4: A Serious Local Model on a Laptop With Limits
-
📅 Day 136 — Linux Permissions and Authorization: A Google Cybersecurity Certificate Portfolio Activity
-
📅 Day 135 — Auditing My Own Website, Then Fixing What the Report Found
-
📅 Day 134 — Building a Website Trust & Security Mini-Audit Service
-
📅 Day 133 — When the Learning Log Breaks: Fixing My Blog's Own Publishing Pipeline
-
📅 Day 132 — Giving a Local LLM Hands: LM Studio, Function Calling, and MCP Servers
-
📅 Day 131 — Project Retrospective: Turning a Real Website Build Into Portfolio Evidence
-
📅 Day 130 — Public Website Security Review for a Static Business Site
-
📅 Day 129 — Testing, Linting, Type Checking, and Build Validation
-
📅 Day 128 — Privacy, Analytics, and Consent-Aware Configuration
-
📅 Day 127 — Custom Domain, DNS, and Website Availability
-
📅 Day 126 — GitHub Pages Deployment and CI/CD Trust Boundaries
-
📅 Day 125 — Image Optimization and Performance as Operational Security
-
📅 Day 124 — SEO, Metadata, and Structured Data Without Forgetting Security
-
📅 Day 123 — Contact Forms, Validation, and Anti-Spam Thinking
-
📅 Day 122 — Mobile-First UX and Customer-Facing Reliability
-
📅 Day 121 — Routing, Pages, and Public Attack Surface
-
📅 Day 120 — Repository Structure and Operational Hygiene
-
📅 Day 119 — React, TypeScript, Vite, and Tailwind as a Production Stack
-
📅 Day 118 — Real Client Website Scope and Business Requirements
-
📅 Day 117 — macOS Persistence, LaunchDaemons, and Endpoint Triage
-
📅 Day 116 — Frontend Architecture, Website Optimization, and GitHub Workflows
-
📅 Day 115 — Local AI Models, Coding Agents, and Operational Automation
-
📅 Day 114 — OS, Network, and Cloud Hardening
-
📅 Day 113 — Sniffing, Spoofing, and Interception Tactics
-
📅 Day 112 — DoS, DDoS, SYN Floods, Smurf, and Amplification
-
📅 Day 111 — Reading tcpdump-Style Logs and DNS/ICMP Failures
-
📅 Day 110 — Enterprise Network Flow and Attack Surface Mapping
-
📅 Day 109 — Firewalls, VPNs, Proxies, Security Zones, and CIDR
-
📅 Day 108 — Network Protocols, Ports, DNS, HTTP, and Remote Access
-
📅 Day 107 — Network Architecture, Cloud Networks, and the TCP/IP Model
-
📅 Day 106 — From Risk Management to Portfolio Evidence
-
📅 Day 105 — Incident Response Playbooks and Escalation Discipline
-
📅 Day 104 — SIEM Logs, Dashboards, and Alert Triage
-
📅 Day 103 — Security Frameworks, Controls, NIST CSF, OWASP, and Audits
-
📅 Day 102 — Threats, Risks, Vulnerabilities, and the NIST RMF
-
📅 Day 101 — Frameworks, Controls, Ethics, and Analyst Tooling
-
📅 Day 100 — Attack History, Business Impact, and Security Domains
-
📅 Day 99 — Cybersecurity Analyst Mindset and Phishing Triage
-
📅 Day 98 — Cookie Banners, Technical Cookies, and Website Privacy Checks
-
📅 Day 97 — Privacy-First Website Analytics
-
📅 Day 96 — IP Spoofing, Sniffing, and Attack Technique Classification
-
📅 Day 95 — DoS, DDoS, Smurf Attacks, and Amplification
-
📅 Day 94 — DNS and ICMP Traffic Incident Analysis
-
📅 Day 93 — Turning Network Concepts into Incident Reports
-
📅 Day 92 — Cybersecurity Roles Across the Attack Surface
-
📅 Day 91 — Enterprise Attack Surface and Exploitation Points
-
📅 Day 90 — Mapping an Enterprise Network End to End
-
📅 Day 89 — From Protocol Memorization to SOC Thinking
-
📅 Day 88 — Security Design Principles and OAuth
-
📅 Day 87 — Network Protocols, Ports, and SOC Visibility
-
📅 Day 86 — Investigating Botnets and IoT Malware
-
📅 Day 85 — Understanding Cryptomining Malware
-
📅 Day 84 — Lateral Movement Techniques in Enterprise Networks
-
📅 Day 83 — The Colonial Pipeline Ransomware Incident
-
📅 Day 82 — The NotPetya Cyberweapon and Destructive Malware
-
📅 Day 81 — The WannaCry Global Ransomware Outbreak
-
📅 Day 80 — Understanding Ransomware Attacks
-
📅 Day 79 — Squiblydoo and Rundll32 Script Execution
-
📅 Day 78 — Metasploit and Exploitation Frameworks
-
📅 Day 77 — PowerShell Empire and Fileless Malware Techniques
-
📅 Day 76 — Understanding Cobalt Strike and Post-Exploitation Frameworks
-
📅 Day 75 — Understanding Fail2Ban and Automated Defense
-
📅 Day 74 — Turning Raw Logs into Patterns and Evidence
-
📅 Day 73 — Detecting SSH Brute Force Attacks Using auth.log
-
📅 Day 72 — From Commands to Systems Thinking in Cybersecurity
-
📅 Day 71 — Verifying Services and Understanding Why Connections Fail
-
📅 Day 70 — Mapping IP Addresses to Devices Using ARP
-
📅 Day 69 — Understanding NAT vs Bridged Networking in a Lab Environment
-
📅 Day 68 — Testing Network Connectivity and Verifying Open Ports
-
📅 Day 67 — Investigating SSH Connection Failures and Security Warnings
-
📅 Day 66 — Debugging DNS Resolution and Understanding Hosting Mismatch
-
📅 Day 65 — Understanding GitHub Authentication, Cloning, and Local Repositories
-
📅 Day 64 — AI Agents, Model Context Protocol (MCP), and Security Implications
-
📅 Day 63 — Understanding Local LLM Infrastructure and Model Quantization
-
📅 Day 62 — Understanding Phishing Attacks and Email Security Controls
-
📅 Day 61 — Investigating the Dark Web Safely and Understanding Tor
-
📅 Day 60 — Understanding Local AI, Model Hosting, and the Cloud vs Local Debate
-
📅 Day 59 — Studying Malware Families: TrickBot, WannaMine and Cryptomining Threats
-
📅 Day 58 — DLL Files, Code Signing, and Malware Trust Verification
-
📅 Day 57 — LOLBins Deep Dive: Squiblydoo (rundll32 and mshtml Abuse)
-
📅 Day 56 — Offensive Security Frameworks and LOLBins
-
📅 Day 55 — Typosquatting and Malicious Domain Impersonation
-
📅 Day 54 — Investigating Phishing Through Email Gateway Logs
-
📅 Day 53 — Understanding Phishing Attacks and Email Security Layers
-
📅 Day 52 — First Steps with Python and JavaScript for Security
-
📅 Day 51 — CLI Fundamentals, OS Security, and Understanding How Data is Represented
-
📅 Day 50 — Understanding Advanced Persistent Threat (APT) Groups
-
📅 Day 49 — Investigating Phishing Infrastructure and Email Attacks
-
📅 Day 48 — Detecting Authentication Attacks in System Logs
-
📅 Day 47 — Encoded PowerShell and Obfuscated Command Execution
-
📅 Day 46 — Understanding LOLBins and Living-off-the-Land Attacks
-
📅 Day 45 — Pivot Training for Log Investigation
-
📅 Day 44 — Detecting Beaconing and Command-and-Control Traffic
-
📅 Day 43 — Detecting Suspicious Process Chains
-
📅 Day 42 — SOC Thinking: Turning Logs into Evidence
-
📅 Day 41 — Sysmon Telemetry, Lab Automation, and Full Cyber Lab Architecture
-
📅 Day 40 — Building a Reproducible Windows SOC VM and Lab Infrastructure
-
📅 Day 39 — Building a Portable Zsh Environment with GitHub Dotfiles
-
📅 Day 38 — SSH Brute-Force Investigation and Automated Defense
-
📅 Day 37 — Ports, Services, and Investigating Listening Processes
-
📅 Day 36 — Linux Process Investigation and First Log Exploration
-
📅 Day 35 — Linux Process Baselining with ps and top
-
📅 Day 34 — Networking Mental Model Reset (DNS, TCP/UDP, HTTPS/TLS, QUIC)
-
📅 Day 33 — Expanding the SOC Learning Roadmap (Identity, Triage, and Hiring Readiness)
-
📅 Day 32 — OSI Model, Encapsulation, and Core Network Protocols
-
📅 Day 31 — Regex Behavior and Text Processing Foundations
-
📅 Day 30 — Streams, Exit Codes, and Bash Redirection
-
📅 Day 29 — SOC Thinking with Linux Pipelines, Pivots, and Process Chains
-
📅 Day 28 — Understanding Command Resolution & Filesystem Investigation with find
-
📅 Day 27 — Command Resolution, PATH Internals & Shell Environment Investigation
-
📅 Day 26 — Effective Shell Part 2: Pipelines, Readline Search, Job Control
-
📅 Day 25 — Effective Shell Fundamentals: ls, du, man, Heredocs, Updates, and Docker Permissions
-
📅 Day 24 — Tools Lane Setup, Effective Shell, and Shutdown Triage
-
📅 Day 23 — Consolidation, Repetition, and Anki-Driven Recall
-
📅 Day 22 — stdout, stderr, wget, and Output Validation
-
📅 Day 21 — Building My Detection Engineering Repo + Hardening My Blog Setup
-
📅 Day 20 — Auditing a Media Archive and Taking Control of Backups
-
📅 Day 19 — Bare-Metal Dual Boot on Intel Mac (macOS + Ubuntu Server)
-
📅 Day 18 — Intel Mac Dual-Boot Experiments, Architecture Friction, and Lab Prep
-
📅 Day 17 — Cookies, Sessions, and Trust Boundaries
-
📅 Day 16 — Linux Privilege Escalation: SUID, SGID, Sticky Bit (Foundations)
-
📅 Day 15 — Building a Proper Terminal Logging Pipeline
-
📅 Day 14 — Linux Permissions, Identity, Pipes, and Data Processing Fundamentals
-
📅 Day 13 — SSH and Networking Flow Between VMs
-
📅 Day 12 — Linux Files, Permissions, and Safety
-
📅 Day 11 — Linux Fundamentals Part 3 (Finale)
-
📅 Day 10 — Linux Fundamentals Part 2 (SSH, Filesystem, Permissions)
-
📅 Day 9 — Linux Fundamentals Part 1
-
📅 Day 8 — Killing Minima Ghosts & Owning the Stack
-
📅 Day 7 — Workflow Ergonomics & GitHub Pages Stabilization
-
📅 Day 6 — Polishing Website & Fixing Jekyll Environment
-
📅 Day 5 — Blogging with GitHub Pages (Publishing Foundations)
-
📅 Day 4 — Recovery Day Logged Honestly
-
📅 Day 3 — How Websites Work (Big Picture)
-
📅 Day 2 — Networking & Web Fundamentals (Consolidation Day)
-
📅 Day 1 — Environment Setup & Foundations
subscribe via RSS
