Security Sketchbook

Visualizing cybersecurity concepts through diagrams, stories, and investigations.

What you'll find here

Sketches

Visual explanations of cybersecurity concepts like Kerberos, MITRE ATT&CK, Windows Event IDs, and telemetry flow.

Blog

Longer writeups that turn diagrams and analogies into full explanations.

Labs

Hands-on notes, SOC investigations, log analysis, detection ideas, and technical experiments.

Featured ideas

Kerberos Explained Visually

Authentication tickets, trust, and access flow shown as a visual system.

MITRE ATT&CK as a Robbery

A storytelling framework for understanding attacker behavior.

SOC Investigation Walkthrough

What actually happens when an alert fires and how the story gets built from logs.