BC.Brandon Chaney
Brandon Chaney

Hi, I’m Brandon.

I’m an IT Specialist at Access Ohio, supporting Microsoft 365, Active Directory, endpoints, and networking across a multi-site organization in Columbus, Ohio.

I’m focused on growing into security operations and incident response. I enjoy tracing activity across logs and packet captures, building small tools, and documenting how I reached a conclusion. Longer term, I’d like to move into penetration testing.

My interest in technology started with game development and design. I’ve always enjoyed solving unusual problems and learning new technologies, and security gives me plenty of opportunities to do both.

Outside of work, I go climbing with friends, take long walks with my partner, and unwind with visual novels on my PS Vita.

MY TOOLBOX

Skills & tools.

Tools I use in projects and day-to-day systems work.

Detection & response

SysmonWazuhSplunkElasticMicrosoft SentinelShuffleTheHive

Investigation & forensics

WiresharkVolatility 3VelociraptorKAPESuricataGhidra

Systems & networking

WindowsLinuxActive DirectoryMicrosoft 365DNS / VPNAzure

Code & security testing

PythonPowerShellSQLNmapBurp SuiteGit

THE WORK BEHIND THE ANSWERS

Would I be a good fit?

Common questions, answered with evidence.

Can you operate in a real IT environment?

Yes. In my current IT Specialist role, I support a production environment of roughly 300 users across nine sites. My day-to-day work covers endpoints, identity, networking, Microsoft 365, and remote access.

EVIDENCE

  • ~300 users across nine sites
  • Microsoft 365 + Active Directory
  • Endpoint + network administration
  • VPN, firewall, and access troubleshooting
EXPERIENCE
Can you investigate security events?

Through lab investigations and writeups, I practice starting with evidence, forming a hypothesis, and following activity across data sources. I document the steps that support a conclusion, along with what remains uncertain.

EVIDENCE

  • Wireshark: SMB, NTLM, Kerberos, and TLS
  • Hack The Box Sherlock investigations
  • KC7: KQL queries and evidence correlation
  • Writeups explaining the clues and decisions
  1. 01 / TRIAGEIdentify suspicious activity
  2. 02 / CORRELATEConnect the evidence
  3. 03 / INVESTIGATETest the explanation
  4. 04 / DOCUMENTExplain findings and limits
INVESTIGATION NOTES
Do you understand the systems behind the alerts?

My infrastructure work gives me context for how users, devices, identities, and networks interact. Troubleshooting authentication, connectivity, and access helps me ask better questions when I look at security activity.

EVIDENCE

  • Active Directory + Microsoft 365 administration
  • Windows endpoints and remote access
  • DNS, VPN, and firewall troubleshooting
  • UniFi + SonicWall network tooling
SYSTEMS EXPERIENCE
Can you build and automate, not just use tools?

I build small tools and connected workflows to make repeated analysis more useful. My projects include indicator enrichment, an automated SOC pipeline, and custom static malware triage tooling.

EVIDENCE

  • Wazuh → Shuffle → TheHive SOC pipeline
  • Python IOC analyzer with VirusTotal + OTX
  • MalTriage: hashes, PE metadata, and strings
  • Documented setup, workflow, and results
PROJECTS
How do you continue developing your skills?

I combine structured study with hands-on practice, then turn what I learn into investigations, tools, and writeups. My current learning includes Microsoft security operations and further practice with KQL and incident analysis.

EVIDENCE

  • LetsDefend + Hack The Box investigations
  • KC7: KQL 101, 201, and 301
  • SC-200: Microsoft security operations study
  • Projects and writeups that put learning to work
CERTIFICATIONS