Daily Study Log
Blog Archive
Browse the daily notes, progress logs, and reflections from the cybersecurity journey.
October 2026
Moving a Date-Gated Publisher to an Authenticated Ubuntu Timer
I prepared and activated a systemd-based Ubuntu release timer that catches up missed publishing runs, requires owner-authenticated GitHub CLI access, and verifies the real service instead of trusting its unit file.
What Completing Five Google Cybersecurity Courses Actually Gives Me
I completed five Google Cybersecurity Certificate courses and reflected on the practical foundation they gave me: risk, assets, networks, Linux, SQL, and incident response.
Incident Response Plans Are Tools, Not Shelf Documents
I studied what belongs in an incident response plan and why tabletop exercises, clear procedures, diagrams, contacts, and templates are part of security readiness.
How a CSIRT and SOC Move an Incident Without Losing Context
I studied the responsibilities of security analysts, technical leads, incident coordinators, SOC tiers, and managers, and learned why escalation is a coordination system rather than a status ladder.
IDS and IPS: The Difference Between Seeing and Stopping
I studied how intrusion detection and intrusion prevention systems differ, and why an alerting control and a blocking control need different evidence and safety expectations.
Reading IPv4 and IPv6 Headers Without Guessing
I studied the structure of IPv4 and IPv6 headers and connected the diagram fields to the decoded packet view in Wireshark.
Using Wireshark to Turn Packets Into Security Evidence
I opened a supplied sample capture in Wireshark and learned to move from a packet list to defensible observations about Ethernet, IPv4, TCP, and SSH.
Building a PASTA Threat Model for a Fictional Sneaker Marketplace App
I completed a PASTA threat-modeling exercise for a fictional sneaker marketplace mobile app. The exercise connected business objectives to data flows, trust boundaries, attack paths, and controls.
Studying How a SOC Hands Alerts From Tier 1 to Tier 3 and Managers
I studied how a Security Operations Center divides work between Tier 1, Tier 2, Tier 3, leads, and managers. The useful insight was that the tiers form an escalation and decision system, not a ranking of who is “better”…
Writing an Incident Handler Journal Entry for a Ransomware Scenario With the Five W’s
I completed an incident-handler journal entry about a fictional ransomware incident at a small healthcare clinic. The important lesson was not memorizing ransomware terminology. It was learning how to turn an alarming…
Building a Work Summary Tool That Says 'Not Proven' When Evidence Is Missing
I worked on a local Resolver that summarizes open Codex and Claude work from historical sources. The security lesson was that a useful summary must preserve uncertainty instead of turning an inventory, a title, or an AI…
September 2026
Testing a Voice Command Path That Starts Coding-Agent Jobs from Telegram
I tested a voice path that can start work in Claude Code or Codex from a Telegram message. The security lesson was that transcription is input, not authorization.
Keeping a Daily Status Digest from Becoming a Transcript Archive
I helped tighten a daily project-status digest that combines current task metadata with historical records. The security problem was not simply how to import data. It was how to keep a short status receipt from becoming…
Finding a Setting That Was Correct in the File but Wrong in the Running Service
I investigated a model keep-alive setting that looked correct in a launch configuration but was still wrong in the running service. The value in the file said two hours; the process and server reported twenty-four.
Turning a Message into a Calendar Event Safely: Evidence, Dates, Duplicates
I worked on a local capture path that turns a message containing a future commitment into a calendar event. The security lesson was that extraction is not enough. A write needs evidence, deterministic date handling, an…
Extending an Outgoing-Message Guard to Check the Message It Replies To
I extended an outgoing-message guard after discovering that some failures cannot be detected from the reply alone. Whether a message is safe can depend on the inbound message it answers, the language it used, and…
Reviewing Which Tools a Messaging Agent Can Really Use
I reviewed what capabilities a messaging-facing agent could actually reach. The lesson was simple but important: describing a tool in a prompt does not grant a capability, while attaching a tool schema can make that…
Testing a Messaging Bot's Final Message Instead of the Model's First Output
I spent time testing a local messaging persona with tools attached. The most important discovery was about the measuring instrument: scoring the first model completion was not the same as scoring the message that a…
Writing a Vulnerability Assessment Report for an Internet-Exposed Database (Simulated)
I prepared a simulated vulnerability-assessment report for a scenario involving a business-critical database exposed to the public internet. The valuable lesson was not a magic number in a risk table. It was learning to…
Assessing a Found USB Drive as a Data-Leak and Malware Risk
I completed a removable-media risk exercise built around a found USB drive. The obvious danger is plugging in an unknown device and executing malware. The less obvious lesson was that the files already on the drive can…
OSINT: Turning Public Information into Security Intelligence (Google Cybersecurity Certificate)
Closing out this stretch of the Google Cybersecurity Certificate, I studied open-source intelligence (OSINT) — the practice of turning publicly available information into usable security intelligence — and the specific…
Defense in Depth, CVE, CVSS and the OWASP Top 10 (Google Cybersecurity Certificate)
Continuing the vulnerability module, I studied the defense-in-depth model, how the CVE list standardizes vulnerability tracking globally, how CVSS scores severity, and the OWASP Top 10 — the ten most commonly exploited…
Vulnerability Management and CI/CD Pipeline Security (Google Cybersecurity Certificate)
Starting the vulnerability module of the Google Cybersecurity Certificate, I studied the four-step vulnerability management cycle and zero-days, then went deep on CI/CD pipeline security specifically — the automated…
Access Control: AAA, IAM, and a Contractor Account Left Active for Four Years
Studying the authentication, authorization, and accounting (AAA) framework alongside identity and access management (IAM), I worked through SSO, MFA, authorization mechanisms, and the MAC/DAC/RBAC models — then grounded…
Hash Functions and Why They Are Not Encryption (Google Cybersecurity Certificate)
Studying hash functions in the Google Cybersecurity Certificate clarified something I'd been fuzzy on: hashing isn't a weaker form of encryption, it's a fundamentally different tool — one-way, irreversible, and built…
How PKI Combines Symmetric and Asymmetric Encryption (Google Cybersecurity Certificate)
Starting the encryption module of the Google Cybersecurity Certificate, I studied how public key infrastructure combines symmetric and asymmetric encryption with digital certificates to make online communication both…
SQL JOINs for Combining Security Logs (Google Cybersecurity Certificate)
Finishing the SQL module of the Google Cybersecurity Certificate, I studied JOINs — INNER, LEFT, RIGHT, and FULL OUTER — not as four separate syntax rules to memorize, but as one underlying idea: security telemetry is…
Data Privacy: Lifecycle, Ownership and Handoffs (Google Cybersecurity Certificate)
In the next Google Cybersecurity Certificate material, I studied how data protection depends on more than encryption or a login prompt. Privacy and security have to follow information through its full lifecycle, with…
Asset Security: From Inventory to Classification (Google Cybersecurity Certificate)
Continuing the Google Cybersecurity Certificate, I studied asset security and the step after inventory that is easy to overlook: classification.
SQL for Security Triage: Filtering Logins by Date, Time and Number
In the Google Cybersecurity Certificate material I studied how SQL comparison operators and time ranges turn a large login table into a focused investigation. The important shift was not SQL syntax on its own; it was…
Basing Website Security Claims on What a Real Browser Shows
While automating website trust checks, I learned that a security claim should be based on what a real browser can verify, not on a thin technical signal that sounds equivalent. A redirect, certificate check, or fetch…
Moving a Message Safety Filter to the Final Delivery Step
During an in-progress Hermes WhatsApp repair, I found that filtering assistant responses was not enough. Direct handlers and maintenance notices could bypass that path and reach the delivery adapter. The defensive…
Handling a Leaked Bot Token: Removing It from Code Is Not Revoking It
While improving a WebCheckup watchdog, I worked through a credential-exposure lesson that is easy to state and easy to underdo: removing a bot token from a workflow is cleanup, not revocation.
Finding That an Empty Tool List Meant 'Inherit Everything', Not 'Deny All'
While enabling local, source-attributed conversation recall for Hermes, I found an easy-to-misread authorization setting: an empty WhatsApp tool list did not mean “no tools.” In that version of the platform, it…
Upgrading a Live Service and Proving Which Commit Is Actually Running
Upgrading Hermes taught me that a clean test run and a new source checkout are not enough evidence for a security-sensitive service. The important question is more concrete: *what code is the live process actually…
Verifying That an Agent Really Ran a Skill Before Accepting Its PDF Report
Letting Hermes generate real financial-adjacent PDFs — an Amazon purchase register, a shareable spending note — meant building a supervision layer that refuses to let "the runtime found the skill" count as "the skill…
Connecting Home Assistant to a Mac's Wake and Sleep with Minimal Access
Connecting Home Assistant to my M4 Mac's power state started with fixing a broken wake toggle — a fix so narrow it added no new capability at all. Hours later, adding the ability to put the machine to sleep from the…
Building Remote Power Control for a Mac over Telegram, with Two Sender Checks
Building remote power control for a second machine (an M4 Mac) over Telegram meant answering two separate questions at once: who is allowed to send this command, and does the network path even stay reliable enough for…
Finding Why a Scheduled Watchdog Never Ran: The Scheduler Rejected a Symlink
Finding that a scheduled Hermes watchdog was versioned and manually runnable, yet silently blocked in the actual scheduler because the deployed path was a symlink.
Building an Encrypted Off-Host Backup and Proving It Restores on Another Machine
Building encrypted off-host backup for Hermes state, then proving the restore on the disaster machine without interrupting the live messaging bridge.
Unifying Agent Memory into One Source-Attributed Retrieval Path
Unifying local memory retrieval so different agents use a shared, source-attributed path instead of accumulating disconnected notes and hidden context.
August 2026
Choosing a Local Coding Model by Measuring Repeated Full Rounds
Choosing a local coding model by measuring complete repeated rounds, not by model size or a one-off first response.
Building a Relay Between ChatGPT and a Local Coding Agent, Guarded Against Stale and Duplicate Messages
Building a local ChatGPT-to-OpenCode relay that keeps the workflow simple without letting stale replies, duplicate loops, or leaked worker output control the next step.
Fixing an Unattended Job That Kept Picking the Same Files and Starved the Rest
Finding that an unattended document-reconciliation job was repeatedly choosing the same high-priority files and silently starving the rest of its registry.
Fixing a Watchdog That Mistook a Network Failure for an Expired Credential
Fixing an authentication watchdog that could turn a transient network failure into a confident but wrong credential-expiry diagnosis.
Adding a Live Trial Because Passing Fixture Tests Did Not Prove a Local Model Was Ready
Adding an explicit, opt-in live-evidence path because deterministic shadow tests cannot prove how a real local model will behave.
Gating the One Scheduled Message a Bot May Send Without Being Asked
Making the one allowed non-reply WhatsApp action—a scheduled morning greeting—prove that it is exactly that and nothing broader.
Requiring a Recent Incoming Message Before a Bot May Reply, Once
Treating a reply to a real person as a short-lived, one-use authorization—not as something a local process can invent because it can reach an API.
Fixing a Bot That Said Good Night at 11:24 in the Morning (Stale Cached Time)
Two real incidents — "Buonanotte zia!" sent at 11:24 in the morning, and "Buongiorno zia!" sent at 13:41 in the afternoon — traced back to a stale cached fact baked into the persona's config by an hourly cron job. In…
Shadow-Testing a New Briefing Feature Before It Reaches Anyone
Rolling out a new "Phase 4" briefing feature meant reusing a pattern from earlier this month — shadow trials before anything reaches a real user — but this time as deliberate, staged, standard practice:…
A Config Cap That Deadlocked the Gateway, and a Prefix Match That Nearly Revoked the Wrong User
One day carried three separate lessons: a compression-threshold cap meant to fix a real problem instead deadlocked the whole gateway and had to be reverted, an access-revocation for a user I'd asked to stop turned into…
Giving an Agent Write Access to My Calendar Without Giving It Delete
Hermes needed to write calendar events on my behalf. Instead of pointing it at my real calendar with full write access, I scoped the capability down to a dedicated calendar it owns, banned deletion outright, and used a…
Locking Down a New WhatsApp Channel: Too Many Tools, Too Much Trust in the Sender
Rolling WhatsApp out as a real channel for Hermes surfaced two unrelated ways a new surface can end up trusting more than it should: a default toolset that handed a chat-facing persona terminal and code execution, and a…
Red-Teaming My Own Chatbot: Building an Adversarial Persona Harness
Rolling out a WhatsApp-facing persona for Hermes meant I could no longer eyeball a handful of test messages and call it safe. I built an automated adversarial harness to attack the persona itself — and then had to fix…
Investigating an Unexplained Mac Shutdown and Restricting Who Can Power It Off
A WhatsApp message powered my Mac off. Nothing in the agent's own turn could have caused it — no model response had even landed yet, no tool had executed — which meant the real caller was unidentified and unaccountable.…
Testing My Personal-Data Policy Gate with Phone Location
I gave Hermes access to my phone's location so it could use it for real tasks — then treated that as a test case for the deny-first personal-data policy gate built a couple of weeks ago, instead of assuming it would…
Adding a Secret Scan Before Every Push to a New Repository
Standing up a new private remote for Hermes' binaries was the excuse to build the habit I should have had from day one: a pre-push secret scan, plus a one-command Google reauth so recovering from an expired credential…
Four Bugs, One Pattern: Code That Claimed Success Without Proof
Four unrelated bugs this week — an audit ordering flaw, a stale test expectation, a push notification, and a night batch runner — turned out to be the exact same failure shape wearing different clothes: something…
Fixing a Bug Where Narration Text Was Executed as a Task
A deliberate audit of the task supervisor, run while it was intentionally deactivated, found that text meant purely as narration — commentary about what was happening — could get routed into supervised execution as if…
Stopping the AI Secretary from Writing and Sending Email on Its Own
The personal secretary had been asking the Hermes agent to compose email and send it automatically. I stopped both halves of that and replaced them with a three-draft picker over Telegram — real human choice, not a…
Auditing My Phone-Approval Gate: Wrong Identity Key, Silent Policy Hook, Exposed Webhook
A real audit of the phone-approval gate from a few weeks back found several concrete weaknesses: an approval queue keyed on the wrong identity, a policy hook that could be knocked over silently, and a webhook sitting on…
SQL Labs: Filtering with WHERE and LIKE, Sorting with ORDER BY
Two Google Cybersecurity Certificate SQL labs today: filtering with WHERE and LIKE, then plain SELECT/FROM and sorting with ORDER BY. Small syntax, but the framing is the point — every query was tied to a security…
Building a Watchdog for Expiring Credentials and Proving the Alarm Fires
The personal secretary went quiet, and the root cause traced back to Google OAuth credentials expiring with no alert firing. I built an independent watchdog — then made myself prove the alarm actually rings before…
Closing the Observation Backlog: Two New Skills Born From Real Recurring Bugs
Weeks of skill observations — small lessons captured during real tasks — had accumulated into a backlog. Closing it meant a genuine review, not a rubber stamp, and it produced two new skills built from patterns that…
Retiring Aider Properly, and Making Agents Land Their Own Work
Aider stopped being installed a while ago, but the stack was still quietly shelling out to it. Retiring the lane properly, and adding a rule that agents must commit their own work before finishing, closed two different…
Giving Agent Memory Real Sources, and Routing Trivial Turns to a Small Model
Two upgrades to how Hermes thinks day to day: a memory index that tracks real sources and supersession instead of an undifferentiated pile of facts, and a tiering proxy that stops routing trivial turns to an expensive…
Making Email Verification Prove Delivery, Not Just Sending
A "verified Apple Mail delivery" feature was reporting success the moment a send call returned — not when the message actually arrived. Fixing that, and finding secrets leaking into diagnostic evidence along the way,…
Fixing a Citation Check That Treated a Matching Hash as Trust
The memory-fabric's citation verifier had a naming problem masking a real one: content that hash-verified correctly could still be wrongly treated as trustworthy, because hash integrity and promotion eligibility had…
Turning Two Log-Only Guards into Guards That Block
Two separate audit findings shared the same shape: a guard that computed the right answer and then did nothing with it. A personal-data policy that defaulted to allow, and a provider-authority check that only logged…
Fixing a Self-Certification Check That a Unicode Lookalike Could Bypass
A rule I trusted — a worker cannot certify its own attempt — turned out to be enforced by a string comparison that never normalized Unicode. A homoglyph lookalike of a worker's identity could slip past it.
The Fix Had Two More Holes: A Live DNS-Rebinding Bypass Hunt
An independent security review of yesterday's SSRF fix — Chromium IP-pinning meant to close DNS-rebinding — found two further bypasses, both confirmed live against a real browser and a real local server, before either…
Building an SSRF-Safe Fetcher for an Agent That Reads the Web
Giving an agent the ability to fetch and cite real web pages means giving it a network client — which means building it as if it were hostile from day one. I put together the SSRF-hardening layer for the…
July 2026
Using Linux Help Before Making a Change
Using Linux's built-in help resources to identify commands and options before changing a system.
Reviewing a Skill Catalog and Installing Only a Small Allowlist
Curating a small set of defensive skills instead of installing a large catalog into an active workflow.
Extracting Useful Text Without Giving an Agent a Browser
Building a small, bounded way to extract readable content from a local HTML file or a single URL.
Testing Whether a Codebase Index Actually Helps Find Evidence
Testing whether a codebase index improves evidence gathering rather than assuming that faster retrieval is a security win.
Choosing Tools by Evidence, Not by Novelty
Evaluating a third-party tool before it becomes part of a local security workflow.
Execution Depth Presets, a Broken Build, and Unit Tests for the Small Stuff
Two threads that turned out to be the same lesson: giving the Captain agent user-facing execution depth presets, and giving even my smallest helper scripts real unit tests — with a broken build in between to make the…
Unattended Delegation: Which Lanes Are Allowed to Work While I Sleep
Not every automation lane deserves to run unattended. I documented which ones do, wired the Headroom proxy in properly as a managed service, and explicitly banned a lane that looked fine but was not.
Shadow Trials: Letting the New Router Watch Before It Acts
Before trusting changes to the AI-OS routing layer, I ran them in shadow mode: the candidate logic sees every real task and records what it *would* have done, while the proven path keeps doing the actual work.
Provenance and Recovery: Knowing Who Changed What, and Undoing It
A baseline for the whole agent stack: every change attributable to the agent and task that made it, and every change reversible through a documented recovery path.
Parallel Agents Without Collisions: Task Graphs and Git Worktrees
Letting multiple agents work at the same time without trampling each other: a task graph to order the work, and git worktrees so every agent gets its own isolated copy of the repository.
Five Ways My Automation Faked Success (and the Fail-Closed Fixes)
A hardening pass on the task supervisor uncovered something uncomfortable: several code paths where an autonomous task could look successful without being successful. Today was about closing every one of them.
Making Security Work Clear Without Overselling It
Writing clearer summaries of recent labs and engineering work: not a list of buzzwords, but short case studies that connect an outcome, the controls used, the evidence collected, and the limits of the claim.
Why Safe Rollouts Use Feature Flags, Fixtures, and Evidence Gates
Turning several recent automation projects into one rollout principle: build new capability additively, prove it under controlled conditions, and do not confuse successful testing with permission to change production…
Secure Artifact Delivery: Narrow Links, Verified Bytes, and No Duplicate Sends
Extending the supervised-agent workflow with an artifact-delivery design that limits access to one intended file and verifies the content before it reaches a recipient.
Approval-Gated Automation: Making Privileged Agent Work Accountable
Adding an autonomous-supervisor layer that creates a durable task record before sensitive work begins, and gives an operator approval, cancellation, and recovery controls.
Resilient Sessions: What a Torn Journal Taught Me About Safe AI State
Designing resumable agent sessions that preserve critical facts across a restart without treating corrupted state as trustworthy.
Bounded Context, Better Decisions: Testing AI Agent Memory Without Blind Trust
Building a bounded, source-attributed working context for a local AI agent, then measuring it without pretending that a benchmark is the same thing as live intelligence.
Verifying the Verifier: A False-Positive Streak in My Own Checks
My verification tooling cried wolf: hermes-verify produced a streak of false MISMATCH alerts, and today was about fixing the check itself — plus hardening timeouts, regression-testing the guardrails, and automating the…
Model Fleet Ops: Migrating the Coding Lane to Gemma and Budgeting Tokens Like a Resource
The local models got treated like a fleet instead of a collection: benchmarked, reconfigured, migrated, retired, and put on a token budget.
An AI Secretary With a Kill Switch: Calendars, Sender Policy, and Emergency Control
Hermes became a real secretary: it can read my calendars and handle personal email — so before it got those powers, it got a sender policy, an approval flow, and a remote emergency stop.
Hardening the iOS Companion: Untrusted Links, Redacted Errors, and the 'Full Power' Question
A full-app security pass on the iOS companion: how it opens links, downloads images, reports errors, and manages connection state — plus an honest argument with myself about how much power the phone should have.
Tailscale Broke My Stack: Node Identity, Hostnames, and Private Services
My private network layer stopped cooperating: connections dropping daily, an iOS companion endpoint that vanished, and services that worked yesterday returning nothing today. The root causes were about node identity and…
Widening an Agent's Write Scope on Purpose (and Making Its Findings Earn Evidence)
I deliberately expanded my local agent's write access in stages — one folder, then one repo, then the filesystem with recoverable tasks — and fixed its website audits so they can no longer assert findings they did not…
Gated Autonomy: A Phone Approval Loop Before Any Agent Sends Anything
I built an approval pipeline so autonomous outreach can research and draft on its own, but nothing gets sent until I approve it from my phone.
WebCheckup: Turning the Mini-Audit Into a Real Multilingual Service
The website mini-audit project grew up: it got a real name — WebCheckup — a scored repeatable rubric, professional PDF reports, and landing pages plus report templates in four languages.
Too Many Projects: Auditing My Own Tool Sprawl Like an Asset Inventory
I reached the point where I honestly did not know what I had anymore: too many projects, apps, agents, and half-finished experiments. So I ran a "what is going on" audit across the whole workstation.
Linux User and Group Management as Access Control Practice
I turned a Google Cybersecurity Certificate Linux activity into a blog-ready lab: creating a user, assigning groups, changing file ownership, adding secondary access, deleting the user, and cleaning up leftover groups.
Building a Cybersecurity Glossary Without Breaking My Notes
I built a broad cybersecurity glossary inside my Obsidian vault and linked it across existing notes. The work looked like knowledge management, but the real lesson was validation: large automated edits to notes need…
Testing Hermes Agent: Strong First Builds, Weak Self-Verification
I installed and tested Hermes Agent as a GUI-first autonomous local agent. It was impressive at building a first working app, but the more important lesson came from verification: its self-debugging claims were not…
Building an AI Inference Orchestrator With Routing, Retries, and Cost Awareness
I worked on an AI Inference Orchestrator: a layer that classifies tasks, chooses candidate models, runs them through a controlled pipeline, retries when appropriate, records cost/savings information, and surfaces…
Benchmarking My Local LLM Stack Instead of Trusting Vibes
I compared the local model stack on my laptop and made a concrete routing decision: Ollama with my juribuora-agent-coder:30b model is the daily backend, DS4 stays installed but experimental, and LM Studio remains useful…
June 2026
Remote Agent Hub and the Discipline of Honest Feature Labels
I worked on productizing the Remote Agent Hub: a local-first iPhone command center for my workstation agents. The most important part was not adding more buttons. It was making the app honest about what is implemented,…
Turning My iPhone Into a Command Center for Local Agents
I worked on the idea that a security tool is only useful if I can understand what it is doing while it runs. My local AI workstation had power, but too much of that power still lived in terminal output, scattered logs,…
Building Least-Privilege Tool Profiles for My AI Agents (and Finding My Own Risk Scorer Was Inverted)
My AI agents can currently reach every tool I've connected — filesystem, Gmail, GitHub, everything — regardless of what the task actually needs. I started building scoped permission profiles so each task type only gets…
'Build Succeeded' Isn't Proof: Writing a Real UI Test for the Auth Flow
Following up on the pairing-token auth I added to my agent daemon and iOS app: instead of leaving it at "compiles successfully," I wrote a real end-to-end UI test that drives the actual app against the actual live…
Giving My Local Agent Daemon Real Auth (And Almost Leaking the Token in the 401 Page)
Closing a known, accepted gap: my local agent daemon had zero authentication. Anything on the network that could reach it could control it. I built a real pairing-token layer for the daemon and its iOS companion app.
Productizing a Website Security Mini-Audit, and Finding an Access Gap in My Own Funnel
Turning a website security mini-audit into an actual sellable service — landing page, intake funnel, and a real GitHub Pages deployment — and catching an access-control gap in my own delivery pipeline along the way.
A 348-Term Glossary and the False Positives That Came With It
Building a broad cybersecurity, networking, Linux, and developer-tooling glossary across my study vault, then linking every matching mention — and cleaning up the collateral damage that caused.
Building a Local MITRE ATT&CK Technique Library from My Own Notes
Turning every MITRE ATT&CK technique ID scattered across my study vault into a real, sourced reference library instead of a bunch of bare T#### mentions.
Benchmarking an Autonomous Agent: Strong One-Shot Builds, Unreliable Self-Debugging
Testing a fully autonomous local agent (Hermes) on a real app build, plus wiring it to a Telegram control channel.
A Human Memory Layer: The RAG Vault My Agents Write and I Read Anywhere
Setting up an Obsidian vault, synced to my iPhone, as the human-readable memory layer for the local agent system.
AI-OS: Governance, Routing, and a Verification Gateway for My Local Agents
Turning a pile of local AI tools into an "operating system": routing, governance rules, task contracts, and verified execution.
Benchmarking a Local LLM Coding Stack: Harness, Routing, and Review Findings
Building and benchmarking the local LLM coding stack — a test harness, routing rules, and fixing what code review found.
An iOS Companion for My Local Agent, Private by Design
Building an iOS companion app to control the laptop's local agent remotely, without exposing anything to the public internet.
Running DS4: A Serious Local Model on a Laptop With Limits
Getting the DS4 runtime and a quantized DeepSeek model running locally as my default agent model.
Linux Permissions and Authorization: A Google Cybersecurity Certificate Portfolio Activity
Managing file permissions and authorization in Linux, documented as a portfolio artifact for the Google Cybersecurity Certificate.
Auditing My Own Website, Then Fixing What the Report Found
Running the mini-audit against the Farina website I built myself, and remediating the findings.
Building a Website Trust & Security Mini-Audit Service
Packaging what I learned about web security into a small, honest audit service for local Italian businesses.
When the Learning Log Breaks: Fixing My Blog's Own Publishing Pipeline
Debugging and fixing the blog's own GitHub Pages publishing so a batch of finished posts could actually go live.
Giving a Local LLM Hands: LM Studio, Function Calling, and MCP Servers
Turning a local LLM in LM Studio into an agent that can actually do things, using function calling and MCP servers.
Project Retrospective: Turning a Real Website Build Into Portfolio Evidence
Converting the Farina website project into honest cybersecurity-adjacent portfolio material.
Public Website Security Review for a Static Business Site
Reviewing the Farina website from a practical defender mindset.
Testing, Linting, Type Checking, and Build Validation
Using validation commands to catch problems before deployment.
Privacy, Analytics, and Consent-Aware Configuration
Keeping analytics useful without making privacy an afterthought.
Custom Domain, DNS, and Website Availability
Connecting the Farina domain setup to DNS, CNAME, and production reachability.
GitHub Pages Deployment and CI/CD Trust Boundaries
Understanding automated deployment as a privileged operational workflow.
Image Optimization and Performance as Operational Security
Using modern image formats and build scripts to keep the site fast and maintainable.
SEO, Metadata, and Structured Data Without Forgetting Security
Building discoverability while keeping public information intentional.
Contact Forms, Validation, and Anti-Spam Thinking
Reviewing the contact flow as both a conversion path and an abuse target.
Mobile-First UX and Customer-Facing Reliability
Improving the website for real users on phones, not just desktop previews.
Routing, Pages, and Public Attack Surface
Mapping website routes as user journeys and public exposure points.
May 2026
Repository Structure and Operational Hygiene
Organizing the Farina website repository so the project remains understandable and maintainable.
React, TypeScript, Vite, and Tailwind as a Production Stack
Understanding why the Farina site uses a modern frontend stack instead of plain static HTML.
Real Client Website Scope and Business Requirements
Planning the Farina Farm website as a real production project rather than a practice page.
macOS Persistence, LaunchDaemons, and Endpoint Triage
Investigating macOS persistence mechanisms and practicing endpoint triage methodology using real system artifacts.
Frontend Architecture, Website Optimization, and GitHub Workflows
Understanding how modern frontend websites are structured, optimized, deployed, and operationally maintained.
Local AI Models, Coding Agents, and Operational Automation
Exploring local AI models, autonomous coding workflows, and the operational/security implications of AI-assisted development environments.
OS, Network, and Cloud Hardening
Finishing Course 3 by studying hardening techniques that reduce network and system compromise risk.
Sniffing, Spoofing, and Interception Tactics
Clarifying the difference between passive traffic observation, forged identity, and interception-style attacks.
DoS, DDoS, SYN Floods, Smurf, and Amplification
Studying denial-of-service attacks and how different flooding, reflection, and amplification patterns appear in traffic.
Reading tcpdump-Style Logs and DNS/ICMP Failures
Practicing how to interpret packet-level evidence and explain a DNS-related network incident.
Enterprise Network Flow and Attack Surface Mapping
Mapping how data moves through an enterprise environment and where exploitation can happen.
Firewalls, VPNs, Proxies, Security Zones, and CIDR
Understanding the defensive infrastructure that controls network access and visibility.
Network Protocols, Ports, DNS, HTTP, and Remote Access
Studying common protocols and ports as practical SOC vocabulary.
Network Architecture, Cloud Networks, and the TCP/IP Model
Starting Course 3 by building a practical mental model of network architecture and communication.
From Risk Management to Portfolio Evidence
Consolidating Course 2 into practical portfolio artifacts: audit notes, SIEM triage, playbooks, and risk language.
Incident Response Playbooks and Escalation Discipline
Using playbooks to turn alerts into repeatable incident response actions.
SIEM Logs, Dashboards, and Alert Triage
Understanding how SIEM tools collect logs and help analysts turn raw events into investigations.
Security Frameworks, Controls, NIST CSF, OWASP, and Audits
Studying how frameworks and controls help organizations reduce risk and how audits turn vague concerns into evidence.
Threats, Risks, Vulnerabilities, and the NIST RMF
Beginning Course 2 by separating threats, vulnerabilities, and risks, then connecting them to structured risk management.
Frameworks, Controls, Ethics, and Analyst Tooling
Finishing the foundation course by connecting frameworks, controls, ethics, and common cybersecurity tools to practical analyst work.
Attack History, Business Impact, and Security Domains
Using cybersecurity history, common attacks, attacker motivation, and security domains as a map for real-world defensive work.
Cybersecurity Analyst Mindset and Phishing Triage
Starting the Google Cybersecurity Certificate by translating the introductory material into practical SOC analyst thinking.
Cookie Banners, Technical Cookies, and Website Privacy Checks
Understanding when a website may need a cookie banner and how to verify the real technical behavior of a site.
Privacy-First Website Analytics
Understanding website analytics from a privacy-first and security-aware perspective.
IP Spoofing, Sniffing, and Attack Technique Classification
Clarifying the difference between IP spoofing, sniffing, attacks, and attacker techniques.
DoS, DDoS, Smurf Attacks, and Amplification
Understanding denial-of-service attacks, including floods, reflection, amplification, and Smurf attacks.
DNS and ICMP Traffic Incident Analysis
Analyzing DNS and ICMP traffic to understand why a website or service failed to respond.
Turning Network Concepts into Incident Reports
Practicing how to turn technical network evidence into a clear incident summary.
Cybersecurity Roles Across the Attack Surface
Understanding which cybersecurity roles defend different parts of an enterprise environment.
Enterprise Attack Surface and Exploitation Points
Mapping where exploitation can happen across an enterprise network.
Mapping an Enterprise Network End to End
Understanding how data moves through an enterprise network from user action to application response.
April 2026
From Protocol Memorization to SOC Thinking
Consolidating network protocol knowledge into a practical SOC investigation mindset.
Security Design Principles and OAuth
Reviewing core cybersecurity design principles and understanding what OAuth actually does.
Network Protocols, Ports, and SOC Visibility
Understanding common network protocols, their ports, and why they matter for SOC investigations.
Investigating Botnets and IoT Malware
Understanding botnets, IoT malware, and how compromised devices are coordinated at scale.
Understanding Cryptomining Malware
Understanding cryptomining malware and how attackers abuse compromised systems for profit.
Lateral Movement Techniques in Enterprise Networks
Understanding lateral movement and how attackers move from one compromised system to another inside a network.
The Colonial Pipeline Ransomware Incident
Studying the Colonial Pipeline ransomware incident and how credential compromise can affect critical infrastructure.
The NotPetya Cyberweapon and Destructive Malware
Studying NotPetya as destructive malware disguised as ransomware.
The WannaCry Global Ransomware Outbreak
Studying the WannaCry ransomware outbreak and how worm-like propagation created global impact.
Understanding Ransomware Attacks
Understanding how ransomware attacks work and why encryption is usually the final stage of a longer intrusion.
Squiblydoo and Rundll32 Script Execution
Understanding Squiblydoo, a LOLBin technique that abuses rundll32.exe for script execution.
Metasploit and Exploitation Frameworks
Understanding Metasploit and how exploitation frameworks are used to gain initial access.
PowerShell Empire and Fileless Malware Techniques
Understanding PowerShell Empire, fileless malware techniques, and why PowerShell abuse matters in Windows investigations.
Understanding Cobalt Strike and Post-Exploitation Frameworks
Understanding how post-exploitation frameworks such as Cobalt Strike are used after attackers gain initial access.
Understanding Fail2Ban and Automated Defense
Exploring how systems automatically block attackers after repeated failures.
Turning Raw Logs into Patterns and Evidence
Understanding how aggregation transforms logs into meaningful signals.
Detecting SSH Brute Force Attacks Using auth.log
Analyzing Linux authentication logs to identify brute-force login attempts.
From Commands to Systems Thinking in Cybersecurity
Recognizing the shift from using commands to understanding systems.
Verifying Services and Understanding Why Connections Fail
Understanding why a service may fail even when a system is reachable.
Mapping IP Addresses to Devices Using ARP
Understanding how to identify devices on a network using ARP (Address Resolution Protocol).
Understanding NAT vs Bridged Networking in a Lab Environment
Understanding how virtual machine networking works and why NAT vs bridged mode matters in a cybersecurity lab.
Testing Network Connectivity and Verifying Open Ports
Testing connectivity between systems and verifying whether services are reachable over the network.
Investigating SSH Connection Failures and Security Warnings
Troubleshooting SSH connection failures and understanding security warnings during remote access.
Debugging DNS Resolution and Understanding Hosting Mismatch
Understand why a domain was not resolving correctly and learn how DNS interacts with hosting services.
Understanding GitHub Authentication, Cloning, and Local Repositories
Clarify how GitHub authentication works and understand the relationship between remote repositories and local copies.
AI Agents, Model Context Protocol (MCP), and Security Implications
Today’s goal was to explore the emerging concept of AI agents and how protocols like the Model Context Protocol (MCP) allow AI systems to interact with external tools and environments.
Understanding Local LLM Infrastructure and Model Quantization
Today’s focus was understanding how local Large Language Models (LLMs) actually run on personal machines and what makes them possible without requiring massive datacenter hardware.
Understanding Phishing Attacks and Email Security Controls
Today I focused on understanding phishing attacks, one of the most common entry points for security incidents.
Investigating the Dark Web Safely and Understanding Tor
Today’s focus was understanding how analysts safely investigate dark web resources and why operational security is critical when interacting with unknown infrastructure.
Understanding Local AI, Model Hosting, and the Cloud vs Local Debate
Today’s goal was to better understand the growing ecosystem of local AI models and how they compare with cloud-hosted AI services.
March 2026
Studying Malware Families: TrickBot, WannaMine and Cryptomining Threats
Today I explored several real malware families to understand how modern threats operate.
DLL Files, Code Signing, and Malware Trust Verification
Today I explored how DLL files work in Windows and how security teams verify whether a file is legitimate using digital signatures.
LOLBins Deep Dive: Squiblydoo (rundll32 and mshtml Abuse)
Today I explored one of the most famous LOLBins (Living Off The Land Binaries) techniques used in Windows attacks: Squiblydoo.
Offensive Security Frameworks and LOLBins
Today I explored several well-known offensive security frameworks and techniques used by attackers after initial access.
Typosquatting and Malicious Domain Impersonation
Today I explored typosquatting, a technique attackers use to trick users into visiting malicious domains that closely resemble legitimate websites.
Investigating Phishing Through Email Gateway Logs
Today I focused on understanding email gateway logs, which are an important source of telemetry when investigating phishing incidents.
Understanding Phishing Attacks and Email Security Layers
The goal for today was to deepen my understanding of phishing attacks, which remain one of the most common initial access techniques used by attackers.
First Steps with Python and JavaScript for Security
Today’s goal was to begin exploring basic programming concepts through two introductory TryHackMe rooms:
CLI Fundamentals, OS Security, and Understanding How Data is Represented
Today’s objective was to strengthen foundational cybersecurity knowledge by completing several TryHackMe learning rooms covering:
Understanding Advanced Persistent Threat (APT) Groups
Today’s goal was to explore the concept of Advanced Persistent Threat (APT) groups and understand how nation-state actors conduct long-term cyber operations.
Investigating Phishing Infrastructure and Email Attacks
The focus of today’s study was understanding how phishing campaigns operate and how defenders analyze email infrastructure to identify malicious activity.
Detecting Authentication Attacks in System Logs
The goal for today was to understand how authentication logs reveal brute-force and password-spraying attacks.
Encoded PowerShell and Obfuscated Command Execution
Today’s objective was to understand how attackers hide malicious commands using obfuscation techniques, particularly in PowerShell.
Understanding LOLBins and Living-off-the-Land Attacks
The goal of today’s session was to understand the concept of Living-off-the-Land attacks and the role of LOLBins (Living-Off-the-Land Binaries) in modern intrusion techniques.
Pivot Training for Log Investigation
Today’s focus was on learning pivot training, a technique used by SOC analysts to navigate large log datasets efficiently.
Detecting Beaconing and Command-and-Control Traffic
The goal of today’s session was to understand how malware communicates with external command-and-control (C2) servers and how analysts detect these patterns in logs.
Detecting Suspicious Process Chains
The objective for today was to learn how process relationships reveal malicious behavior.
SOC Thinking: Turning Logs into Evidence
The goal of today’s session was to understand how Security Operations Center (SOC) analysts transform raw logs into actionable evidence.
Sysmon Telemetry, Lab Automation, and Full Cyber Lab Architecture
The objective for today was to transform the Windows VM from a simple investigation machine into a telemetry-generating endpoint and to complete the infrastructure blueprint of the entire cyber lab.
Building a Reproducible Windows SOC VM and Lab Infrastructure
The goal for today was to start transforming the lab from a collection of tools into a structured, reproducible cybersecurity environment.
Building a Portable Zsh Environment with GitHub Dotfiles
The goal of today was to build a portable and reproducible terminal environment.
SSH Brute-Force Investigation and Automated Defense
Develop a first real investigation mindset by:
Ports, Services, and Investigating Listening Processes
Understand how network services actually run on a system by:
Linux Process Investigation and First Log Exploration
Move from memorizing commands to observing real system behavior.
Linux Process Baselining with ps and top
Stop treating Linux commands like trivia and start building a baseline understanding of running processes.
Networking Mental Model Reset (DNS, TCP/UDP, HTTPS/TLS, QUIC)
Rebuild a clear mental model of what actually happens when I type a website address in a browser, without mixing layers or relying on vague explanations.
Expanding the SOC Learning Roadmap (Identity, Triage, and Hiring Readiness)
Convert ongoing cybersecurity study into a structured execution system aimed at SOC employment.
OSI Model, Encapsulation, and Core Network Protocols
Build a solid mental model of networking using the OSI framework in preparation for CompTIA Network+ concepts and future SOC analysis work.
February 2026
Regex Behavior and Text Processing Foundations
Strengthen text-processing skills through regular expressions and command-line filtering — essential for log analysis and threat hunting.
Streams, Exit Codes, and Bash Redirection
Develop a deeper operational understanding of how Linux commands communicate:
SOC Thinking with Linux Pipelines, Pivots, and Process Chains
Build a stronger SOC analyst mental model using Linux command-line workflows by learning how to turn raw output into evidence through:
Understanding Command Resolution & Filesystem Investigation with find
Move beyond simply using Linux commands and understand:
Command Resolution, PATH Internals & Shell Environment Investigation
Move beyond simply *using commands* and understand how the system decides what actually runs when a command is executed.
Effective Shell Part 2: Pipelines, Readline Search, Job Control
Get faster and more accurate in interactive Bash by building real muscle memory for:
Effective Shell Fundamentals: ls, du, man, Heredocs, Updates, and Docker Permissions
Rebuild clean, reliable shell fundamentals by studying *Effective Shell* Part 1 and turning it into practical command-line muscle memory.
Tools Lane Setup, Effective Shell, and Shutdown Triage
Reinforce general Linux fundamentals with a practical focus on:
Consolidation, Repetition, and Anki-Driven Recall
Consolidate earlier Linux and command-line learning through:
stdout, stderr, wget, and Output Validation
Strengthen core Linux command-line fundamentals by practicing:
Building My Detection Engineering Repo + Hardening My Blog Setup
- Get something real and tangible shipped today (even if I had to stop abruptly).
Auditing a Media Archive and Taking Control of Backups
Stop chaos from spreading.
Bare-Metal Dual Boot on Intel Mac (macOS + Ubuntu Server)
Build a stable, non-destructive dual-boot setup on an Intel MacBook Pro (2013):
Intel Mac Dual-Boot Experiments, Architecture Friction, and Lab Prep
Set up an Intel MacBook Pro (2013) as a dual-boot target machine with:
Cookies, Sessions, and Trust Boundaries
Understand how HTTP authentication works in practice, focusing on:
Linux Privilege Escalation: SUID, SGID, Sticky Bit (Foundations)
Build a correct mental model of Linux privilege escalation foundations by understanding:
Building a Proper Terminal Logging Pipeline
Create a reliable, professional-grade terminal logging system that:
Linux Permissions, Identity, Pipes, and Data Processing Fundamentals
Understand Linux permission models, user/group identity, ownership management, symbolic links, default permission behavior (umask), and gain foundational mastery of pipes, redirection, and core data-processing tools…
SSH and Networking Flow Between VMs
Understand and practice real network communication between two Linux machines by chaining together SSH, SCP, and HTTP file transfers, and reason clearly about where each protocol fits in the networking flow.
Linux Files, Permissions, and Safety
Understand how Linux handles files and permissions at a fundamental level, and build safe, repeatable habits around destructive commands and log inspection.
January 2026
Linux Fundamentals Part 3 (Finale)
Finish Linux Fundamentals Part 3 and understand how Linux systems are actually managed day-to-day (editors, processes, services, automation, logs).
Linux Fundamentals Part 2 (SSH, Filesystem, Permissions)
Deepen Linux fundamentals by working with remote access, filesystem operations, and permissions, focusing on skills directly transferable to real systems.
Linux Fundamentals Part 1
Get comfortable navigating and interrogating a Linux system using core terminal commands, instead of blindly copy-pasting.
Killing Minima Ghosts & Owning the Stack
Stabilize the blog setup by fully removing leftover theme dependencies, fixing broken assumptions, and taking full ownership of the Jekyll stack.
Workflow Ergonomics & GitHub Pages Stabilization
Reduce daily workflow friction and stabilize my GitHub Pages blog after repeated theme and configuration issues.
Polishing Website & Fixing Jekyll Environment
Polish my GitHub Pages website, troubleshoot Jekyll environment issues, and consolidate past days’ notes for publication.
Blogging with GitHub Pages (Publishing Foundations)
Learn the basics of publishing a blog using GitHub Pages and understand the tooling behind a static site workflow.
Recovery Day Logged Honestly
Maintain continuity and honesty in daily logging, even when no active study or practice happens.
How Websites Work (Big Picture)
Understand how a website works end-to-end, from the user’s device to the server response, and reinforce this understanding through visual mapping.
Networking & Web Fundamentals (Consolidation Day)
Strengthen foundational understanding of how networks and the web work, while improving my personal knowledge system to support long-term learning.
Environment Setup & Foundations
Build a clean, reproducible cybersecurity lab and a unified knowledge system to support long-term learning and documentation.