THE CIPHERNEST
Blue Team. Detection Engineering. SOC Automation. Threat Hunting. AI Security.
Practical security engineering for teams that value observable systems, defensible decisions, and capability that improves with every investigation.
Collect
Reliable telemetry
Detect
Tested analytics
Decide
Evidence-led response
Every security claim is tied to a data source, a test, and a response decision.
5
active engineering projects
9
practical security articles
4
defensive disciplines
Projects are treated as durable engineering artifacts: designed around data, validated with realistic behavior, and documented for the next person who needs to operate them.
SOC Engineering
A detection-first SOC operations workspace that brings telemetry health, triage context, and response playbooks into one deliberate workflow.
Home Lab
A repeatable Windows and Linux monitoring lab for testing telemetry, adversary behavior, and detections before production use.
Detection Engineering
A practical rule-development workflow that connects hypotheses, sample telemetry, test cases, and release decisions.
The work combines systems thinking with hands-on validation. The objective is not more alerts; it is better evidence, clearer decisions, and repeatable improvements.
Behavior-led analytics built with test evidence, owners, and a clear tuning path.
Useful workflow improvements that preserve analyst judgment and operational context.
Falsifiable questions, high-quality pivots, and outcomes that strengthen the program.
Evidence-aware evaluation for AI-assisted defensive workflows and human review boundaries.
Operating principles
Cybersecurity is strongest when its controls can be explained, tested, and improved by the people responsible for operating them.
About the practice01
Telemetry before tooling
02
Detections tested like software
03
Human decisions supported by evidence
04
Learning shared in the open
Focused writing on telemetry, detection design, investigations, and the habits that make security work more reliable.
A practical blueprint for a home lab that validates telemetry and detections instead of becoming an unused collection of virtual machines.
A plain-language explanation of collection, normalization, detection, investigation, and why a SIEM is only as good as its data contracts.
Treat detections as maintainable software: begin with behavior, declare telemetry requirements, test against reality, and plan the tuning loop.
Occasional field notes on building resilient defensive capability, lab-tested detections, and what is worth learning next.