Rroutetorootinblog.routetoroot.io·3d ago · 4 min readLab 22: Same Logs, New SIEM — Setting Up Splunk From ScratchLab 21 closed the detection gap in Elastic. 31 alerts fired. End-to-end detection confirmed. The Elastic SIEM phase of the portfolio was complete. So naturally, I installed a second SIEM. Lab 22 is th00
Rroutetorootinblog.routetoroot.io·Sep 5 · 4 min readLab 21: I Finally Closed the Detection GapEight labs ago, I ran a brute force attack against my own system and watched zero alerts fire. I knew the attack happened. The logs confirmed it. But the SIEM never saw it — because the logs that matt20
Rroutetorootinblog.routetoroot.io·Aug 31 · 5 min readLab 13: The Attack Ran. The Alerts Didn't Fire.In Lab 12, I built the detection rules. Three prebuilt Elastic rules targeting Linux attack techniques. One custom KQL rule for SSH authentication failures. The pipeline was configured, the rules were30
MMKinthedataanalystpath.hashnode.dev·Aug 31 · 5 min readWhat It Actually Takes to Break Into Data Analytics in AustraliaI've spent the last year working closely with career switchers and job seekers trying to break into data analytics, and the same pattern shows up over and over. Someone finishes a course, builds a res00
Rroutetorootinblog.routetoroot.io·Aug 28 · 5 min readLab 12: How I Taught My SIEM to Recognize an AttackLab 11 got the pipeline running. Logs were flowing from my Kali Linux host into Elastic SIEM. The agent was enrolled. The data was real. But a SIEM that ingests logs and does nothing with them is just10
Rroutetorootinblog.routetoroot.io·Aug 20 · 2 min readPatch Tuesday Just Dropped 421 CVEs. One Was Already Being Exploited.Every second Tuesday of the month, Microsoft drops a security update. And every month, the security community holds its breath a little. August 2026's Patch Tuesday was a big one. 421 CVEs patched acr00
KWKatarzyna Walshinkasiawalsh.hashnode.dev·Aug 2 · 3 min readFor beginners who doubt they belong in techI want to encourage people with non-traditional backgrounds and those struggling with imposter syndrome to stick with your dreams and to continue learning software development. If you're doubting your00
Rroutetorootinblog.routetoroot.io·Jul 27 · 4 min readI Finally Stopped Reading About SIEMs and Built OneI'd been reading about SIEM tools for months before I actually touched one. SIEM — Security Information and Event Management — shows up in almost every SOC job description. It's the platform analysts 00
Rroutetorootinblog.routetoroot.io·Jul 14 · 4 min readSOC or GRC? Why I'm Targeting Both (And How I'm Deciding)When people ask me what kind of cybersecurity role I'm going after, I give them the same answer every time: "SOC analyst or GRC analyst — whichever one hires me first." That usually gets a laugh. But 00
JRJoy Rijithinjoyc.hashnode.dev·Jun 28 · 4 min readFrom 12 Years in QA to GCP Cloud Engineer — What the Switch Actually Looked Like This is not a success story with a clean arc. It's messier than that. I spent 12 years as a QA engineer. Not dabbling — 12 years. That was my career, my identity, and what I thought I'd keep doing. T01J