After over 15 years practicing law — most recently as a litigation attorney, law firm partner, and Thomson Reuters/Practical Law senior legal editor — I transitioned into cybersecurity through the SANS Technology Institute, where I'm pursuing a B.S. in Applied Cybersecurity (Dean's List, 4.0 GPA). I'm currently a Cybersecurity Intern at Helmerich & Payne, focused on security operations, incident response, network traffic analysis, and cyber risk management.

This website documents the projects I've completed while building practical experience in Blue Team operations. Most of the work is performed in my own Proxmox-based home lab, where I build security tooling from the ground up and validate each stage of the telemetry pipeline through hands-on testing and investigation.

My long-term interests include network security monitoring, detection engineering, malware analysis, threat hunting, and digital forensics.


Featured Project

Building a Network Security Monitoring Lab with Proxmox, Arkime, Suricata, Zeek, and SiLK

Following completion of the SANS GCIA certification, I designed and built a Network Security Monitoring (NSM) platform to better understand how packet capture, intrusion detection, protocol analysis, and network flow analytics work together during real-world investigations.

Rather than deploying an all-in-one appliance, I assembled the monitoring pipeline myself using Proxmox, Open vSwitch, Arkime, Suricata, Zeek, SiLK, and YAF. The project documents the complete telemetry pipeline—from mirrored traffic and full packet capture through IDS alerting, protocol metadata, and searchable flow records—along with the troubleshooting required to validate each stage.

My lab now serves as the foundation for future malware analysis, threat hunting, detection engineering, and incident response projects.

Read the Full Project →


Additional Projects

Blue Team Investigation of a Simulated Metasploit PsExec Attack

Simulated a Metasploit PsExec compromise against a Windows 10 virtual machine and performed an end-to-end incident response investigation using Sysmon and PowerShell. The project documents malicious service creation, process execution chains, credential dumping, command-and-control activity, and Netcat persistence.

Read More →



National Cyber League Spring 2025 Team Game

National Cyber League Spring 2025 Team Game

Competed with six SANS Technology Institute classmates in the National Cyber League Spring 2025 Team Game, placing 63rd out of 4,798 teams nationwide (top 1.3%). Challenges included network traffic analysis, digital forensics, reconnaissance, password cracking, and web exploitation.

Read More →