What the SOC Analyst path actually taught me — running my own SIEM alongside it
Going through HTB's SOC Analyst path while running a purple team lab changed what stuck. The detections aren't the point. Seeing where they break is.
Security practitioner working across detection engineering, Active Directory security, and offensive security — I build detections, then attack the environment to see whether they hold up.
This is where I publish research write-ups, detection rules, and the lessons that come out of hands-on lab work: building environments, breaking them, and figuring out what a defender would actually see.
2 posts1 ATT&CK technique1 detection rule
Writing and tuning detections — Wazuh rules, Sigma, and the baseline work that decides whether they actually fire.
Kerberos, delegation, certificate services, and the attack paths that quietly turn one account into domain-wide access.
Building labs, breaking them, and mapping what a defender would actually see when the attack runs.
Going through HTB's SOC Analyst path while running a purple team lab changed what stuck. The detections aren't the point. Seeing where they break is.
The rule is six lines of XML. The part that actually mattered was a query I ran before writing any of it.