A self-hosted lab built to practice the job, not just study for it: a bare-metal hypervisor behind a segmented firewall, a SIEM whose detections I verify by attacking my own network, and automation agents that work while I don't. Everything below runs in my home right now.
Bare-metal Proxmox VE host I built and administer myself — the foundation the whole lab runs on, carrying six virtual machines and containers.
Dedicated firewall with segmented WAN/LAN interfaces sitting in front of everything. Nothing moves between segments unless a rule explicitly says it can.
SIEM with endpoint agents deployed across the lab. I don't assume the detections work — I prove it by running controlled attacks from Kali Linux and confirming each alert fires.
Scheduled scans against intentionally vulnerable targets — Metasploitable2 and DVWA — producing real findings to practice the triage workflow analysts do daily.
Zero-trust remote access into the lab over an outbound-only tunnel, plus network-wide DNS filtering. The attack surface from the internet's point of view: zero open ports.
Self-hosted n8n running in Docker, orchestrating AI agent workflows — including one that hunts job postings on my behalf while the rest of the lab hums along.
The hardware side of the skill set: a repair-and-resell business — sourcing damaged laptops, diagnosing before purchase, and restoring them to full working condition.
Windows Server & Active Directory, Linux, Network Security, Firewalls & VPNs, Ethical Hacking, and Digital Forensics — Dean's List every semester, graduating December 2026.