
From Zero to Cybersecurity
A public, structured learning log documenting the journey into cybersecurity — what I study, build, break, misunderstand, and eventually learn to do properly.
▸ Learning Journey
240-day goal reached. New target: 365 days (69%)
Top Topics
Weekly Breakdown
About This Project
The Goal
Solid fundamentals in networking, Linux, web tech, and security. Documented practice, careful reasoning, and steady improvement.
The Approach
Foundations first, hands-on labs, rigorous documentation, understanding flows over memorizing definitions.
What You'll Find
Daily logs, labs, structured reports, diagrams & notes, and detailed project material.
Feedback Welcome
Bad assumptions? Weak mental models? Corrections are welcome — better early than confidently wrong later.
October 2026
Moving a Date-Gated Publisher to an Authenticated Ubuntu Timer
I prepared and activated a systemd-based Ubuntu release timer that catches up missed publishing runs, requires owner-authenticated GitHub CLI access, and verifies the real service instead of trusting its unit file.
What Completing Five Google Cybersecurity Courses Actually Gives Me
I completed five Google Cybersecurity Certificate courses and reflected on the practical foundation they gave me: risk, assets, networks, Linux, SQL, and incident response.
Incident Response Plans Are Tools, Not Shelf Documents
I studied what belongs in an incident response plan and why tabletop exercises, clear procedures, diagrams, contacts, and templates are part of security readiness.
Tabletop-Test an Incident Response Plan
Run a small fictional ransomware tabletop using a response plan, asset information, contacts, a timeline, and a post-exercise gap list.
How a CSIRT and SOC Move an Incident Without Losing Context
I studied the responsibilities of security analysts, technical leads, incident coordinators, SOC tiers, and managers, and learned why escalation is a coordination system rather than a status ladder.
Build a CSIRT and SOC Escalation Handoff
Practise moving one simulated alert from L1 triage through deeper investigation, technical leadership, coordination, and management reporting while preserving evidence and uncertainty.
IDS and IPS: The Difference Between Seeing and Stopping
I studied how intrusion detection and intrusion prevention systems differ, and why an alerting control and a blocking control need different evidence and safety expectations.
Reading IPv4 and IPv6 Headers Without Guessing
I studied the structure of IPv4 and IPv6 headers and connected the diagram fields to the decoded packet view in Wireshark.
Verify Message Integrity and Channel Authorization with Synthetic Fixtures
Run a no-send acceptance check for a multi-channel assistant and verify that authorised owner actions pass while forged origins, ambiguous identities, routing errors, and ordering failures are rejected.
Using Wireshark to Turn Packets Into Security Evidence
I opened a supplied sample capture in Wireshark and learned to move from a packet list to defensible observations about Ethernet, IPv4, TCP, and SSH.
Triage a Training Packet Capture with Wireshark
Open a supplied sample.pcap file, isolate a candidate conversation, inspect Ethernet/IP/TCP/SSH fields, and record observations without claiming intent from one packet.
Building a PASTA Threat Model for a Fictional Sneaker Marketplace App
I completed a PASTA threat-modeling exercise for a fictional sneaker marketplace mobile app. The exercise connected business objectives to data flows, trust boundaries, attack paths, and controls.
Threat Model a Sneaker Marketplace with PASTA
The seven PASTA stages applied to a fictional sneaker marketplace app: objectives, data flows and trust boundaries, two threats, attack paths, controls and what to log.
Studying How a SOC Hands Alerts From Tier 1 to Tier 3 and Managers
I studied how a Security Operations Center divides work between Tier 1, Tier 2, Tier 3, leads, and managers. The useful insight was that the tiers form an escalation and decision system, not a ranking of who is “better”…
Writing an Incident Handler Journal Entry for a Ransomware Scenario With the Five W’s
I completed an incident-handler journal entry about a fictional ransomware incident at a small healthcare clinic. The important lesson was not memorizing ransomware terminology. It was learning how to turn an alarming…
Write an Incident Handler Journal Entry
A structured incident record for a training ransomware scenario at a small clinic: who, what, when, where and why, plus the questions that still need evidence.
Building a Work Summary Tool That Says 'Not Proven' When Evidence Is Missing
I worked on a local Resolver that summarizes open Codex and Claude work from historical sources. The security lesson was that a useful summary must preserve uncertainty instead of turning an inventory, a title, or an AI…
Building a Status Importer That Rejects Stale Data and Unproven Completion Claims
A local importer that accepts only the metadata a status brief needs, rejects stale or content-bearing records, and will not claim work is done without an artifact.
September 2026
Testing a Voice Command Path That Starts Coding-Agent Jobs from Telegram
I tested a voice path that can start work in Claude Code or Codex from a Telegram message. The security lesson was that transcription is input, not authorization.
Requiring Confirmation Before a Voice Command Starts an Agent Job
A local confirmation gate that treats a voice transcription as untrusted and starts an agent job only after the owner confirms the exact proposal.
Keeping a Daily Status Digest from Becoming a Transcript Archive
I helped tighten a daily project-status digest that combines current task metadata with historical records. The security problem was not simply how to import data. It was how to keep a short status receipt from becoming…
Building a Status Record That Holds No Message Content and Expires
A strict status record for tasks that stores metadata only, rejects stale or malformed entries, and never counts as proof of completion.
Finding a Setting That Was Correct in the File but Wrong in the Running Service
I investigated a model keep-alive setting that looked correct in a launch configuration but was still wrong in the running service. The value in the file said two hours; the process and server reported twenty-four.
Checking a Config Change Actually Reached the Running Service
Compares the wanted setting with the running process's environment, its log and its status endpoint, showing that a changed file alone proves nothing.
Turning a Message into a Calendar Event Safely: Evidence, Dates, Duplicates
I worked on a local capture path that turns a message containing a future commitment into a calendar event. The security lesson was that extraction is not enough. A write needs evidence, deterministic date handling, an…
Letting Automation Add a Calendar Event Only When the Message Proves It
A fixture-driven pipeline that writes a calendar event only when the source message supports the date, time and action.
Extending an Outgoing-Message Guard to Check the Message It Replies To
I extended an outgoing-message guard after discovering that some failures cannot be detected from the reply alone. Whether a message is safe can depend on the inbound message it answers, the language it used, and…
Reviewing Which Tools a Messaging Agent Can Really Use
I reviewed what capabilities a messaging-facing agent could actually reach. The lesson was simple but important: describing a tool in a prompt does not grant a capability, while attaching a tool schema can make that…
Reviewing an Agent Tool Bundle for Least Privilege
Reviews the tools an inbound messaging agent can actually use and removes the ones that are unnecessary or hold credentials.
Testing a Messaging Bot's Final Message Instead of the Model's First Output
I spent time testing a local messaging persona with tools attached. The most important discovery was about the measuring instrument: scoring the first model completion was not the same as scoring the message that a…
Testing an AI Agent's Final Message, Not Its First Draft
Builds a local test harness that judges what an AI agent would finally send after tool calls, filtering and rewriting, instead of the model's first output.
Writing a Vulnerability Assessment Report for an Internet-Exposed Database (Simulated)
I prepared a simulated vulnerability-assessment report for a scenario involving a business-critical database exposed to the public internet. The valuable lesson was not a magic number in a risk table. It was learning to…
Assessing a Found USB Drive as a Data-Leak and Malware Risk
I completed a removable-media risk exercise built around a found USB drive. The obvious danger is plugging in an unknown device and executing malware. The less obvious lesson was that the files already on the drive can…
Assessing a Found USB Drive Without Plugging It In
Google Cybersecurity Certificate exercise: assessing a found USB drive as a data-leak and malware risk without connecting it.
OSINT: Turning Public Information into Security Intelligence (Google Cybersecurity Certificate)
Closing out this stretch of the Google Cybersecurity Certificate, I studied open-source intelligence (OSINT) — the practice of turning publicly available information into usable security intelligence — and the specific…
Defense in Depth, CVE, CVSS and the OWASP Top 10 (Google Cybersecurity Certificate)
Continuing the vulnerability module, I studied the defense-in-depth model, how the CVE list standardizes vulnerability tracking globally, how CVSS scores severity, and the OWASP Top 10 — the ten most commonly exploited…
Vulnerability Management and CI/CD Pipeline Security (Google Cybersecurity Certificate)
Starting the vulnerability module of the Google Cybersecurity Certificate, I studied the four-step vulnerability management cycle and zero-days, then went deep on CI/CD pipeline security specifically — the automated…
Access Control: AAA, IAM, and a Contractor Account Left Active for Four Years
Studying the authentication, authorization, and accounting (AAA) framework alongside identity and access management (IAM), I worked through SSO, MFA, authorization mechanisms, and the MAC/DAC/RBAC models — then grounded…
Reviewing a Payroll Change Through Access-Control Evidence
Google Cybersecurity Certificate worksheet: analysing a simulated payroll change, what the logs prove about who made it, and which access controls failed.
Hash Functions and Why They Are Not Encryption (Google Cybersecurity Certificate)
Studying hash functions in the Google Cybersecurity Certificate clarified something I'd been fuzzy on: hashing isn't a weaker form of encryption, it's a fundamentally different tool — one-way, irreversible, and built…
Proving Two Identical-Looking Files Are Not the Same File
Google Cybersecurity Certificate activity: using sha256sum and cmp to show that two files which look identical are different.
How PKI Combines Symmetric and Asymmetric Encryption (Google Cybersecurity Certificate)
Starting the encryption module of the Google Cybersecurity Certificate, I studied how public key infrastructure combines symmetric and asymmetric encryption with digital certificates to make online communication both…
Decrypting a Caesar Cipher and an AES-256 File in Linux
Google Cybersecurity Certificate activity: finding and decrypting a Caesar-cipher file, then using OpenSSL to decrypt an AES-256 file.
SQL JOINs for Combining Security Logs (Google Cybersecurity Certificate)
Finishing the SQL module of the Google Cybersecurity Certificate, I studied JOINs — INNER, LEFT, RIGHT, and FULL OUTER — not as four separate syntax rules to memorize, but as one underlying idea: security telemetry is…
Completing a SQL Join for a Security Incident Investigation
Google Cybersecurity Certificate activity: INNER, LEFT and RIGHT joins across machines, employees and login attempts to investigate an incident.
Data Privacy: Lifecycle, Ownership and Handoffs (Google Cybersecurity Certificate)
In the next Google Cybersecurity Certificate material, I studied how data protection depends on more than encryption or a login prompt. Privacy and security have to follow information through its full lifecycle, with…
Asset Security: From Inventory to Classification (Google Cybersecurity Certificate)
Continuing the Google Cybersecurity Certificate, I studied asset security and the step after inventory that is easy to overlook: classification.
SQL for Security Triage: Filtering Logins by Date, Time and Number
In the Google Cybersecurity Certificate material I studied how SQL comparison operators and time ranges turn a large login table into a focused investigation. The important shift was not SQL syntax on its own; it was…
SQL Time-Window Filtering for Authentication Triage
Turning an authentication or patching question into SQL filters on dates, times and IDs, based on Google Cybersecurity Certificate material.
Basing Website Security Claims on What a Real Browser Shows
While automating website trust checks, I learned that a security claim should be based on what a real browser can verify, not on a thin technical signal that sounds equivalent. A redirect, certificate check, or fetch…