I'm an early-career security professional building real, working detection engineering skills, not just watching tutorials. I run my own Active Directory lab, attack it, defend it, and write up what actually happens.
SIEM & Detection
Endpoint & Adversary Emulation
IR & Frameworks
I'm Joshua, working toward a career in the SOC/detection engineering space. This profile is a record of what I've actually built, not a list of what I've read about.
My approach across every project is the same: log first, attack second, hunt third, then formalize. I don't write a detection until I've run the real attack against my own lab and confirmed what it looks like in the telemetry. If something doesn't work or a technique stays undetected, the README says so. I'd rather show an honest gap than a polished lab that hides one.
Certifications: CompTIA Security+ | ISC2 Certified in Cybersecurity (CC) | working toward CompTIA CySA+
| Project | What it is |
|---|---|
| Cybersecurity-Labs | The full AD attack/defense lab, five phases from visibility foundation to Golden Ticket persistence |
| Detection-Engineering | Sigma rules built from real attacks, compiled to Elastic/KQL, tuned against false positives |
| Purple-Team-Automation | Caldera-driven emulation validating the Sigma rules above, with an ATT&CK coverage heatmap |
| Network-Traffic-Analysis | Network-layer visibility work and the infrastructure issues behind it |
| Incident-Response | IR playbooks and response workflow documentation |
