Semester Semester 2 · in progress
Diploma Cyber Security · ~Q4 2026
Focus Detection engineering · multi-agent AI infrastructure

Last updated 10 Sep 2026

Studies

  • Back at TAFE — semester 2 started a month ago and is well under way
  • Current unit work: setting up and configuring a network from a given scenario
  • Ethics and policies projects still ahead this semester

Projects & Labs

  • Built Homelab Council — one request reviewed independently by Claude, Codex and Kimi, behind a human approval gate
  • Ran the first full three-agent panel: all three corrected each other, and the plan that came out was one none of them proposed alone
  • Turned down a fourth agent after the panel reviewed the proposal and rejected it, including a safety property I had claimed and it disproved
  • Wired the agents into tracing: every run is one session, scored on five measures, with failures recorded and not just successes
  • Gave the council a web dashboard behind SSO, then found six bugs in it within an hour of actually using it
  • Rebuilt that dashboard to read like a log console — colour means severity now, and the overview shows where runs stop, how each agent replied, and every approval on record
  • Let the council dashboard execute an approved plan, after arguing myself out of the idea that typing a flag at a terminal was a security control — the gate is the approval record, not the input device
  • Split the lab’s front page into tabs and pinned a health strip to all of them — alerts, swap, clock drift and container count, each from one query that returns a number even when the answer is zero
  • Ran a full container-image remediation pass: 2042 actionable findings down to 1497, every image pinned
  • Put the AI gateway behind single sign-on, with per-project keys carrying their own spend caps
  • Built the lab a SOC: seven log sources centralised, 36 detection rules, and one dashboard over all of it — collection first, dashboard last
  • Put Kimi on top of the SOC as a read-only analyst — it triages an alert, separates what the evidence shows from what it is guessing, and recommends; it has no tools so it cannot act on any of it
  • Had Kimi audit the thing Claude built, and it correctly refused to sign off the network controls it had not tested itself
  • Proved a brute-force rule that had matched nothing in 30 days actually fires, by generating the failed logins myself
  • Found my own access-log redaction had a hole on the response side, after it had already written session tokens to disk
  • Planning a Raspberry Pi as a filter proxy + ad blocker on the home network
  • Built a network digital twin: NetBox holds what should be listening, a bounded nmap scan holds what actually answers, and neither source is allowed to update the other
  • Found the scan had a blind spot in the middle of its own purpose — a test service on an uncommon port was never detected, because the scan only covers nmap’s top 200
  • Added near-miss detection after noticing the analyst dashboard looked empty: rules that sit at 80% of their threshold now show up instead of leaving no trace at all

Learning

  • Deepening Linux skills and pfSense configuration
  • Upskilling in Windows PowerShell
  • Strengthening core networking concepts
  • Working out where AI agents genuinely belong in an ops workflow — and where a deterministic check has to sit in front of one

Gaming

Single Player Tarkovmodding + playing heavily Minecraftheavily modded Warframe LEGO Batman Legacy Batman: Arkham Knightmodding + playing Call of Duty: Black Ops III Gray Zone Warfare S.T.A.L.K.E.R. 2: Heart of Chornobyl Terraria Forza Horizon 5 Just Cause 4 Just Cause 3 Red Dead Redemption 2 Black Myth: Wukong and many more