01
Linux & systems
Services, processes, permissions, packages, storage, logs, SSH, and system health.
FOUNDATION WORK / 003
The less glamorous work that makes the bigger projects believable.
This is where I sharpen the systems knowledge underneath cybersecurity: Linux, networking, cloud operations, troubleshooting, identity, logging, and defensive monitoring.
CURRENT EMPHASIS
LAB TRACKS
The goal is to understand the machine, the network around it, and the evidence it leaves behind.
01
Services, processes, permissions, packages, storage, logs, SSH, and system health.
02
Addressing, DNS, routing basics, packet flow, ARP, connectivity, and structured troubleshooting.
03
Cloud resource management, IAM concepts, least privilege, monitoring, automation, and resilience.
04
Logs, SIEM concepts, endpoint telemetry, event correlation, and useful alerts instead of noise.
05
Reducing attack surface, patching, account controls, firewalling, and configuration review.
06
Hypothesis-driven diagnosis using tools like ping, tracert, nslookup, ARP, netstat, and system logs.
PORTFOLIO EVIDENCE
Every lab should leave proof that another engineer can inspect.
Topology, trust boundaries, interfaces, and service relationships.
What changed, why it changed, and how it was verified.
Examples of expected events, suspicious events, and tuned alerts.
Symptoms, hypotheses, tests, root cause, and the final fix.
NEXT BUILDS
The best next labs are small enough to finish, but deep enough to prove understanding.
Document addressing, VLAN or segmentation choices, DNS/DHCP behavior, and troubleshooting checks.
Send Linux and endpoint events into a central platform, then build a few high-value detections with clear test cases.
Create a repeatable checklist for a fresh Linux host and record before/after exposure and configuration evidence.
WHY THIS PAGE MATTERS
These labs are the bridge between knowing security concepts and being able to diagnose, design, and defend the infrastructure those concepts depend on.