I Built a Home SOC on My Own Server.
I installed Splunk on my own production server to build real SOC skills. Here’s what I found already probing my server, and how I locked myself out with my own detection stack.
I installed Splunk on my own production server to build real SOC skills. Here’s what I found already probing my server, and how I locked myself out with my own detection stack.
Some support tickets look routine but might be early signs of account compromise, phishing, or malware. Here are 7 ticket types worth a second look, plus what to document and when to escalate.
Three platforms. Three different types of security professional. LetsDefend builds SOC analysts. TryHackMe builds ethical hackers. Hack The Box builds red teamers.
Here is how to pick the right one for where you want to go, and why the best practitioners use more than one.
A practical, header-by-header walkthrough of how security analysts actually read phishing emails. SPF, DKIM, DMARC, sender spoofing, link analysis, and attachment checks explained.
After I documented my Linode server taking 4,000+ failed login attempts in 24 hours, the next obvious question was: what
A complete walkthrough of how I built and deployed a portfolio website on AWS S3 static hosting, CloudFront CDN, Route 53 custom domain, a serverless visitor counter with Lambda and DynamoDB, and automated CI/CD with GitHub Actions. No console clicking required.
A full SOC analyst walkthrough of LetsDefend alert SOC146 phishing email delivering Excel 4.0 XLM macros, DLL loading via regsvr32, and confirmed C2 beaconing. MITRE ATT&CK mapped, verdict explained.
The 7 best AI-powered cybersecurity tools for small businesses in 2026. Honest picks from a cloud security engineer. No enterprise jargon, no fear-mongering, just tools that actually work on a real budget.
An honest NordVPN vs Surfshark comparison for IT professionals and cloud engineers; security audits, speed, Meshnet, jurisdiction, and which actually holds up for remote work in 2026.
I hadn’t published a single post yet. The server was brand new. Nobody had the link. And yet, less than 24 hours after going live, my Nginx error logs were full of automated bots hunting for exposed credentials. Here’s exactly what they were after and how I stopped them.