It's been a while since I've written anything publicly. I used to be fairly active documenting what I was building as a developer, and somewhere along the way - between shipping products and then pivoting toward cybersecurity - I went quiet. This is me picking that habit back up, starting with the most honest thing I can write about: a small, beginner-level tool I just finished.
I'm not writing this to announce a launch. I'm writing it because documenting the learning is the actual point.
Where I'm At
I come from a full-stack development background - I've shipped a few SaaS products solo. Over the past several months I've been transitioning into cybersecurity, specifically working toward a SOC Analyst role. I'm doing hands-on labs on LetsDefend, going through ISC2 CC and Google Cybersecurity material, and generally trying to learn by doing rather than just collecting certificates.
One thing I noticed early: every SOC case follows a similar manual pattern. You get an IOC - an IP, a domain, a file hash - and you check it across two or three different threat intel sources by hand. VirusTotal here, AbuseIPDB there, MalwareBazaar if it's a hash. Same value, three tabs, three logins, three waits.






