Cybersecurity • Engineering • Governance

Building resilient systems where security, delivery, and governance align.

Building a hands-on security lab focused on attack simulation, detection engineering, automation, and governance.

Roadmap

2026 Security Lab Roadmap

This roadmap outlines the systems I’m building to simulate attacks, detect them, and automate response inside a personal security lab.

Each phase builds toward a practical SOC-style environment.

PHASE 1 · FOUNDATION

PlannedCybersecurity

Attack Simulation Lab

Stage 01

Simulates real-world attacks in a controlled environment using attacker and victim virtual machines. Generates realistic logs and artifacts for detection experiments.

offensivedefensivelab

Focus areas

  • SSH brute force
  • Network scanning
  • Reverse shells
  • Attack telemetry generation
PlannedCybersecurity

Home SOC Lab

Stage 02

Build a personal SOC-style monitoring environment that collects and analyzes logs from the attack lab.

detectionSIEMplatform

Stack

  • Wazuh
  • Elastic
  • Suricata
  • pfSense

PHASE 2 · DETECTION & AUTOMATION

PlannedEngineering

SOC Automation Tool

Stage 03

A Python tool that parses security logs, enriches suspicious IP addresses, and generates automated incident reports.

automationIRplatform

Features

  • Log parsing
  • IP enrichment
  • WHOIS lookup
  • geoIP
  • Threat scoring
  • Incident report generation
PlannedCybersecurity

Threat Intelligence Aggregator

Stage 04

Aggregates threat intelligence feeds and normalizes indicators of compromise for use in the SOC lab.

threatintelautomation

Sources

  • AbuseIPDB
  • AlienVault OTX
  • PhishTank

PHASE 3 · HUMAN + AI

PlannedCybersecurity

Phishing Awareness Simulator

Stage 05

Simulates phishing campaigns to measure user awareness and analyze click behavior.

awarenessdefensive

Metrics

  • Click rate
  • Credential submission rate
  • Reporting rate
PlannedEngineering

Secure Local LLM Lab

Stage 06

Explores how organizations can safely use local AI models for security workflows.

LLMAIsecurity

Focus

  • Local LLM deployment
  • Prompt logging
  • Security log analysis
  • AI-assisted incident triage

Detection Engineering

Building detection logic and telemetry pipelines inside the SOC lab.

Platform Reliability

Designing the infrastructure that powers attack simulation, monitoring, and automation.

Risk Governance

Mapping operational controls to measurable security outcomes and ownership.

Case studies

Detailed write-ups will be published progressively.

The roadmap above outlines the lab build sequence for 2026. Detailed case studies will be added here as projects move from Planned to In Progress to Completed.