About
I defend networks for a living and attack them for fun — and I’ve started to suspect the second part is where I’m headed.
The day job: blue team#
My professional home is on the defensive side. There’s a particular satisfaction in blue team work that doesn’t always get talked about: the quiet win of an alert that fires exactly when it should, the slow craft of tuning detections until the noise falls away and the real signal stands out. I like building the systems that catch things, reading the logs nobody else wants to read, and knowing that on a good day the most interesting thing that happens is nothing at all.
Defense teaches you to think in terms of coverage, assumptions, and the gaps between them — and those gaps are exactly what keep things interesting.
The hobby: red team#
Off the clock, I’m on the other side of the fight. Red team work is where my curiosity really runs — popping boxes in a lab, working through CTFs, chaining small misconfigurations into something that shouldn’t have been possible. It scratches a different itch than defense does: less “hold the line,” more “find the one door someone forgot to lock.”
The two sides feed each other. Every offensive technique I learn makes me a sharper defender, and every defensive blind spot I patch teaches me where to look when the roles reverse.
BreachLab#
Over the past month, I’ve become very heavily involved with Breachlab.org. What began as after-hours practice slowly became the place I was most invested in.
That investment paid off in a way I didn’t expect. My blue team background — knowing how systems are supposed to be defended, where the logging lives, what a misconfiguration actually costs — turned out to be exactly the lens that makes for careful auditing. I was eventually onboarded to the BreachLab team to do just that: auditing, where defensive instincts and offensive curiosity meet in the same job.
It’s the clearest proof yet that the two halves of this aren’t really separate. The defender’s eye for what’s wrong and the attacker’s drive to prove it are the same skill pointed in different directions — and at BreachLab I get to point them both at once.
Where this is going#
Lately the hobby has started to feel less like a hobby. The pull toward offensive security as a career, not just a pastime, keeps getting stronger — and this site is part of figuring that out in the open. Expect notes from both sides of the wire: detections I’m proud of, attacks I’ve pulled apart, and the occasional reflection on what it actually takes to cross from defending to breaking for a living.
If any of that resonates, you’re in the right place.