Skip to main content

About

Methodical security work with clear boundaries.

Ceremonial identity

The Welbourne coat of arms

The coat of arms is the ceremonial signature of Welbourne Security. The radar remains the operational mark used throughout the security platform.

View the ceremonial entrance

Evidence first

Record source context, timestamps, assumptions, confidence, and uncertainty instead of treating conclusions as self-evident.

Local where possible

Browser utilities are designed to avoid uploads and make the boundary clear before any sensitive data is handled.

Readable reporting

Reporting should be short enough to act on and detailed enough to reproduce.

Ethical constraints

Work stays within authorization, avoids unnecessary collection, and does not turn public data into harassment or harm.

Capabilities

What I work across.

A working map of the tooling and techniques behind the projects, writeups, and blue-team reference on this site. It centres on detection and response, supported by offensive testing, OSINT, and ICS work.

Detection & SOC Monitoring and threat detection

SIEM triage and detection engineering, pulling signal out of noise across authentication, beaconing, and lateral movement. Currently deepening Microsoft Sentinel and KQL for SC-200.

  • Splunk SPL
  • Microsoft Sentinel
  • KQL
  • SIEM triage
  • Detection rules
  • Log analysis
Response & DFIR Incident response and forensics

Live Windows IR and host forensics: triage, memory analysis, and timeline reconstruction with playbooks for common cases.

  • PowerShell IR
  • KAPE
  • Volatility
  • Zimmerman tools
  • Phishing & ransomware
Offensive & Tooling Testing and hardware work

Hands-on offensive practice and custom tooling, including the RFIDemon Raspberry Pi RFID analysis workstation.

  • Web exploitation
  • Reverse engineering
  • Cryptography
  • RFID / MIFARE
OSINT & Intelligence Collection and exposure review

Supporting OSINT and signals-intelligence workflows with a privacy-first stance, mapping exposure and keeping collection proportionate.

  • OSINT
  • SIGINT
  • Privacy review
  • Browser-local tooling
ICS / OT Security Industrial control systems

IT/OT defensive concepts and repeatable ICS assessment, backed by CISA ICS-300 and ICS-401 training.

  • ICS-300
  • ICS-401
  • IT/OT defence
  • Network mapping
Practice & Delivery Continuous practice and reporting

Active on Hack The Box and TryHackMe, with CTF design and delivery experience from running Pwn2Play.

  • Hack The Box
  • TryHackMe
  • CTF design
  • Reporting