Network Traffic Analysis with Wireshark
Documented packet investigations covering web traffic, scanning, SMB authentication, Kerberos, and TLS decryption.
View investigationsSECURITY OPERATIONS / INCIDENT RESPONSE
$ whoami
I investigate how systems behave, build detections around what matters, and share what I learn along the way.
IT specialist by day · Security investigations and tooling beyond the day job
brandon@lab:~$ whoami
brandon
// TRANSMISSION LOG
New investigations and projects from my public GitHub.
// FIELD NOTES
Practical work across investigation, automation, and security testing.
Documented packet investigations covering web traffic, scanning, SMB authentication, Kerberos, and TLS decryption.
View investigationsBuilt an end to end alert flow: Sysmon detection, Wazuh alerts, Shuffle enrichment, and TheHive case creation.
Explore the pipelineCreated a Python tool to classify indicators, query VirusTotal and OTX, and summarize risk across batches.
View sourceCollected attack telemetry from an exposed Windows VM and investigated it with Microsoft Sentinel and KQL.
View projectTraced a FreePBX SQL injection to code execution, then documented Linux privilege escalation through incron.
Read the writeup// WHO I AM
A systems perspective on security.
Currently, I'm an IT Specialist at Access Ohio, supporting Microsoft 365, Active Directory, endpoints, and networking across a multi-site organization.
I'm focused on growing into security operations and incident response. And one day, I'd like to become a penetration tester. I have a lot to learn still, but I hope to get there one step at a time.
I've always enjoyed solving unique problems, and learning new technologies. My interest in technology started with game development and design. Outside of work, I go climbing with friends, take long walks with my partner, and unwind by playing visual novels on my PS Vita.
// TOOLBOX
Tools I use in projects and day to day systems work.