# About
I'm an IT professional with 15 years across managed services and healthcare IT — most recently as a Level II Service Management Specialist on a 24/7 service desk — now pivoting into offensive security.
The pivot is deliberate: years of triaging incidents, flagging anomalies across 800,000+ records, and responding to a system-wide outage taught me how defenders think. Now I'm learning to think like an attacker — legally, in labs, and under authorization only — through hands-on penetration testing practice, security coursework, and the road to the CEH certification.
# Certifications & Training
Earned
- ✓ CompTIA A+
- ✓ CompTIA Network+
- ✓ CompTIA IT Operations Specialist (CIOS)
- ✓ ITIL 4 Foundation
- ✓ OPSWAT Certified File Security Associate (OCFA)
- ✓ Google Cybersecurity Professional
- ✓ B.S., Data Management / Data Analytics — WGU
In Progress
- … Certified Ethical Hacker (CEH) — EC-Council
- … TryHackMe & HackTheBox — active lab work
# Methodology & Tools
How I approach a test — practiced in labs, applied with discipline.
- Reconnaissance — passive footprinting, DNS enumeration, service discovery
- Scanning & Enumeration — Nmap, service versioning, share and user enumeration
- Vulnerability Analysis — mapping findings to exposures, manual verification
- Exploitation — fundamentals in lab environments, privilege escalation basics
- Reporting — structured findings with severity, evidence, and remediation guidance
Tool labels are honest: lab = hands-on in practice environments (TryHackMe / HackTheBox); learning = currently studying.
# Lab Writeups
Notes from the lab. Retired machines only — no live spoilers, ever.
📟 Kali Linux CLI Cheat Sheet
My complete command reference, organized by engagement phase — daily driver, recon & enumeration, exploitation, post-exploitation, wireless. Built from scratch and verified.
resource🧪 TryHackMe Room Writeups
In progress — writeups land here as I complete rooms. Methodology notes, dead ends included: the failures teach more than the flags.
coming soon# Bug Bounty
Currently in the training phase: methodology first, programs second. HackerOne and Bugcrowd profiles go live here once I'm submitting.
Scope discipline is non-negotiable — authorized targets only, full report quality on every submission.
in training# Home Lab
- Attack platform: Kali Linux — persistent encrypted USB (Ventoy multiboot) plus VM
- Practice ranges: TryHackMe and HackTheBox labs
- Target VMs: intentionally vulnerable machines for offline practice
- Supporting stack: Parrot OS, Wireshark, Python scripting environment
Everything here runs against lab targets I own or am authorized to test. That boundary is the whole point of the craft.
# Data Background
The analyst foundation underneath the security work — kept, reframed.
📊 Anomaly Detection at Scale
QA review methodology across 800,000+ records — flagging outliers for investigation. The same muscle behind identifying anomalous network behavior.
🧪 Experimental Discipline
A/B testing and structured analysis background — hypothesis, control, evidence. Directly transferable to methodical penetration test execution.
# Contact
$ reach out —