SasquatchSec
Tracking what hides in the noise.
I spent most of my career as a do-it-all cybersecurity engineer. Some weeks that was appsec. Other weeks it was SOC, incident response, vulnerability and exposure management, or straight security engineering. Jack of all trades, master of none, though oftentimes better than master of one. Recently a lot of my work was vulnerability and exposure management consulting. I'm shifting more toward endpoint security now, mostly EDR, SIEM, and device controls.
Away from the job I've always been a tinkerer. Building PCs, fixing cars and bikes, poking at a home lab. I play flight sims, extraction and battle royale shooters, military simulation games, and a fair amount of retro stuff. When the weather's decent I'm usually on a mountain, gravel, or road bike.
Tracking Kit
These are the areas I work in most. Four of them. Same basic job either way: find the problem and help get it fixed.
- SPEC 01
Endpoint Security
I work on endpoint detection and response, SIEM, and device controls. A lot of days that means cleaning up telemetry, tuning detections, and checking coverage against how attackers actually move.
- SPEC 02
Vulnerability & Exposure Management
A big chunk of my work is finding what is exposed, cutting through scanner noise, and pushing remediation. I want a short list of real risk, not hundreds of findings that never get touched.
- SPEC 03
Penetration Testing
I run offensive tests against networks, apps, and cloud. I look for paths an attacker could chain together. The writeup covers impact and risk, not just the fix.
- SPEC 04
DFIR & SOC
If something already got in, I work the evidence. Triage, detection changes, forensics, and incident response when it turns into a real event.
Case Files
HackTheBox walkthroughs, CTF notes, and DFIR cases. Some are sealed and need a key to open.
All writeups →Field Library
Series on the trail and already logged. Tracks out of ten, short field notes.
Full reading log →