Skip to main content

Writeups

The formal register. Methodology, decisions, and evidence, written for practitioners rather than recruiters. Each piece comes out of a milestone in the lab, with sanitized configs and playbooks published alongside on GitHub.

What’s planned
#

WriteupCovers
Network segmentationVLAN design, inter-segment policy, and what the detonation network is allowed to reach
Asset and software inventoryKnowing what is on the network before trying to defend it
Telemetry pipelineLog sources, collection, retention, and the cost of keeping everything
Detection engineeringRules written against behavior, mapped to MITRE ATT&CK, tuned for signal
Vulnerability assessmentScanning, scoping, and reading output without drowning in it
Vulnerability managementThe harder half: ownership, remediation, and tracking to closure
CIS Controls v8 mappingThe capstone. Controls mapped to implemented evidence

Nothing published yet

The lab has to run before the writeups mean anything. First pieces land as each milestone completes, starting with segmentation.

In the meantime, the Homelab page tracks build status, and the Blog will carry the shorter reasoning behind decisions.

There are no articles to list here yet.