Cybersecurity
Threat Hunter
Curiosity and Threat Hunting
I’ve always enjoyed digging into things until I understand how they work. As a kid, I’d often get in trouble for taking things apart, often with a few unaccounted-for screws when I reassembled them. Cybersecurity seemed like a bottomless pit of information and knowledge, and that curiosity is what drew me to threat hunting.
Now people hire me to go beyond what their security tools detect and find the needle in the haystack. I want to know what happened, why it happened, what connects to it, and what everyone else might have overlooked.
The work often starts with an incomplete picture: a weak signal, unusual behavior, a piece of threat intelligence, or something in the data that doesn’t quite fit. I get to follow those threads, test ideas, and occasionally find something that existing detections missed.
I enjoy the investigation itself. It’s a whole lot of sifting through logs and noise, but I often get some exciting moments when I uncover something cool and unexpected. Even when a hunt doesn’t uncover malicious activity, it usually teaches me something about the environment, the technology, or how people actually use their systems.
Community
I’ve attended DEF CON three times and enjoy the talks, networking, and CTFs. This year I participated in three CTFs and finished in the top three in one of them.
I’ve also attended BSides events and regularly participate in a local security meetup. I enjoy meeting people who approach problems differently, hearing what they’re researching, and comparing notes about the strange things we encounter.
Beyond Cybersecurity
That curiosity isn’t limited to cybersecurity. I tend to take whatever I’m interested in and go several layers deeper than necessary.
Endurance sports are a good example. I run, cycle, swim, and race triathlons, but I’m also fascinated by the data behind the training. I’ve built a personal wiki and dashboard that brings together metrics from Garmin, Strava, FORM, Stryd, and other sources. GitHub, Obsidian, and MCP-based workflows help me track trends and answer questions that the individual apps and expensive platforms don’t answer well.
Cybersecurity and endurance sports may look unrelated, but I approach them in much the same way: gather the signals, understand the systems, look for patterns, and keep digging until the data tells a useful story.
