Evidence first
Record source context, timestamps, assumptions, confidence, and uncertainty instead of treating conclusions as self-evident.
About
Ceremonial identity
The coat of arms is the ceremonial signature of Welbourne Security. The radar remains the operational mark used throughout the security platform.
View the ceremonial entrance
Record source context, timestamps, assumptions, confidence, and uncertainty instead of treating conclusions as self-evident.
Browser utilities are designed to avoid uploads and make the boundary clear before any sensitive data is handled.
Reporting should be short enough to act on and detailed enough to reproduce.
Work stays within authorization, avoids unnecessary collection, and does not turn public data into harassment or harm.
Capabilities
A working map of the tooling and techniques behind the projects, writeups, and blue-team reference on this site. It centres on detection and response, supported by offensive testing, OSINT, and ICS work.
SIEM triage and detection engineering, pulling signal out of noise across authentication, beaconing, and lateral movement. Currently deepening Microsoft Sentinel and KQL for SC-200.
Live Windows IR and host forensics: triage, memory analysis, and timeline reconstruction with playbooks for common cases.
Hands-on offensive practice and custom tooling, including the RFIDemon Raspberry Pi RFID analysis workstation.
Supporting OSINT and signals-intelligence workflows with a privacy-first stance, mapping exposure and keeping collection proportionate.
IT/OT defensive concepts and repeatable ICS assessment, backed by CISA ICS-300 and ICS-401 training.
Active on Hack The Box and TryHackMe, with CTF design and delivery experience from running Pwn2Play.