Cybersecurity practitioner based in South Africa, actively building toward my first SOC Analyst or Incident Response role through hands-on labs, real-world simulation platforms, and documented investigations.
I don't just follow courses — I investigate, reconstruct attack timelines, and write about what I find.
I want to be on the side that catches the threat before the damage is done. Everything I'm building here is working toward that.
Currently open to: Entry-level SOC Analyst · Incident Response · DFIR Location: South Africa · Open to remote
| Repo | Focus | Status |
|---|---|---|
| tryhackme-writeups | OSINT · CTF · MITRE ATT&CK mapping | ✅ Active |
| kc7-investigations | KQL · Threat hunting · Attack timeline reconstruction | ⏳ In progress |
| letsdefend-soc-cases | SOC alert triage · Sigma rules · Detection engineering | ⏳ In progress |
| mydfir-30-day-challenge | 30-day SOC analyst challenge · Daily logs | |
| cisco-networking-labs | Packet Tracer · VLANs · Routing · ACLs | ⏳ In progress |
| MYDFIR 30-Day SOC Analyst Challenge | |
| ⏳ In progress | KC7 Encryptodera — write-up |
| ⏳ In progress | LetsDefend alert triage cases |
| ⏳ In progress | Cisco Networking labs |
| ✅ Complete | TryHackMe OhSINT write-up |
🔄 In progress: CompTIA Security+
| Qualification | Institution | Year |
|---|---|---|
| National Diploma in Information Technology | Central University of Technology | 2014 |


