Purple Team Lab: Active

Michael Bell // Cybersecurity Engineer

Bridging Electronics Engineering & Advanced Threat Hunting.

Attack like a Red Team. Defend like a Blue Team. Improve together through instrumentation, validation, and practical engineering.

mike@ThreatHuntHQ:~

$ ./initialize-purple-team-lab.sh

[OK] Wazuh SIEM connected

[OK] Suricata IDS streaming

[OK] Zeek telemetry active

[OK] corp.local endpoints online

Current objective

Turn attack behavior into actionable detection logic.

SYSTEM ONLINE_

Engineering foundation

22+ years of systems thinking, now applied to cyber defense.

I am an electronics hardware engineer transitioning into cybersecurity. My background spans hardware validation, firmware, enterprise systems, and the disciplined troubleshooting needed to understand how complex systems fail.

22+Years in engineering
// 01

Electronics & Embedded Hardware

PCB validation, signal analysis, hardware troubleshooting, and product development built on measurable evidence.

// 02

Firmware Development

Nineteen years working with C/C++, low-level systems, embedded code, and the boundary between hardware and software.

// 03

Systems Administration

Hands-on ownership of a small enterprise network, including Windows systems, Active Directory, and operational support.

// 04

Purple Team Defense

Applying engineering rigor to attack simulation, telemetry, detection logic, investigation, and defensive improvement.

Home SOC environment

A purple-team lab built to attack, observe, and improve.

A working environment for validating telemetry, reproducing attack paths, and turning observations into defensible controls.

Purple Team Lab network topology showing pfSense, Active Directory, Wazuh, Kali Linux, and detection systems
THREATHUNTHQ // LAB NETWORK 10.0.0.0/24 // CONTROLLED ENVIRONMENT

10.0.0.0/24

pfSense Network Gateway

The control point for segmented lab traffic, internet access, and observation of attack paths across the environment.

FirewallRoutingSegmentation
Projects & resources

Practical work for practitioners who learn by building.

Repository links are being prepared
01

Threat Detection

SIEM, detection engineering, threat hunting, telemetry, and SOC operations.

SIGMA / WAZUH
02

Security Engineering

Security architecture, vulnerability management, risk, and defensive controls.

DESIGN / HARDEN
03

Offensive Security

Penetration testing, attack simulation, purple-team techniques, and learning labs.

SIMULATE / VERIFY
04

Tools & Scripts

Python, PowerShell, parsers, utilities, and practical security automation.

BUILD / AUTOMATE
05

Home SOC Lab

Wazuh, pfSense, Suricata, Zeek, and Windows telemetry in a working environment.

OBSERVE / RESPOND
06

Field Resources

Cheat sheets, investigation guides, technical references, and lab notes.

LEARN / SHARE
PowerShell // Event audit
Get-WinEvent -FilterHashtable @{LogName="Security"; Id=4625} | Select-Object TimeCreated, Message
Bash // Network discovery
sudo nmap -sV -O --script vuln 10.0.0.0/24
Education & continued learning

Engineering roots. Cybersecurity trajectory.

1999 to 2004

Completed

Bachelor of Science

Electrical and Electronics Engineering Technology

Pennsylvania College of Technology

2020 to 2027

In progress

Bachelor of Science

Information Technology, Cybersecurity Focus

Ira A. Fulton Schools of Engineering at Arizona State University

2020 to 2028

In progress

Master of Science

Information Technology, Cybersecurity Focus

Arizona State University

Secure channel

Let's connect and build stronger defenses.

Open to cybersecurity engineering, threat hunting, detection engineering, and purple-team opportunities.

mike@ThreatHuntHQ:~$ open_channel --email