Security operations · Detection engineering · Threat intelligence Jacksonville, Florida · brunoacabrera.tech · LinkedIn
I build defensive infrastructure, then try to prove it is lying to me.
A working ping does not prove a tunnel is encrypted. An open port does not prove a service is healthy. A hostname that resolves does not prove the client updating it still works. Most of what I have learned came from the gap between those two things.
A segmented production network at home, documented in the open:
- Four VLANs on a Cisco Catalyst, routed by a virtualized pfSense firewall
- Suricata on the trusted segment, 47,605 rules, tuned with the reasoning written down
- Elasticsearch / Logstash / Kibana, with Redis buffering the sensor so a cluster restart costs zero events
- WireGuard remote access with dynamic DNS and an independent watchdog
- Pi-hole + unbound doing DNS-over-TLS with DNSSEC validation
- An HTTP tarpit and a post-quantum VPN lab, both confined to an isolated segment
| homelab-security | Architecture, SIEM pipeline design, IDS tuning decisions, and a full incident log of everything that broke and how it was diagnosed |
- B.S. Cybersecurity & Information Assurance, Western Governors University (2027)
- CompTIA Security+ · ISC2 CC · JNCIA-Junos · CCNA in progress
- Author, Byteproof Parenting (March 2026)
- DEF CON 34 volunteer staff · DC904 / 2600 · PyJax · JaxLUG
The most useful document I have written is the one listing my own mistakes: incidents and fixes. An architecture diagram shows what someone intended. That one shows what happened when it met hardware.