Architecture & Build Templates
Reference architectures and hardware build guides — system-level designs with verified component licensing, sized tiers, and honest hour counts
Build Series Vol. 01 — Detection & Monitoring
Wazuh, Suricata and Zeek assembled into a stack one person can operate, with the tuning and detection validation that almost every deployment skips.
Build Series Vol. 02 — Asset Inventory & Discovery
Discovery tells you what is out there. The source of truth holds what you have decided about it. The control lives in the reconciliation between them, not in either list.
Build Series Vol. 03 — Vulnerability Management
Finding what is exploitable, fixing what matters, and proving both — with a prioritisation model that still works when the severity score is missing.
Build Series Vol. 04 — Incident Response Lab
The capability to investigate, contain and report — built before you need it, including the reporting clocks measured in hours rather than days.
Build Series Vol. 05 — Backup & Recovery
Copies an attacker holding domain admin cannot reach, and restores you have actually performed and timed — including the full-estate rebuild nobody plans for.
Build Series Vol. 06 — Identity & Access
One front door, authenticators that survive phishing, privileged identities separated from daily work, and access that genuinely ends when people do.
Build Series Vol. 07 — Endpoint Hardening & Configuration
Baselines per system class, enforced continuously and measured for drift, across a fleet that includes machines you do not manage and cannot reach on a network.
Build Series Vol. 08 — Network Segmentation & Zero Trust
The containment substrate the rest of the series assumes: isolating a host, keeping a compromised endpoint away from the backups, restricting an unmanaged device to a narrow slice.
Build Series Vol. 09 — Cloud & SaaS Security Posture
The control plane where the estate actually lives — misconfiguration, privilege graphs, public exposure, and the SaaS tenants nobody has ever baselined.
Build Series Vol. 10 — Email & Domain Defense
Domain authentication all the way to enforcement, transport security, portfolio hygiene, and the monitoring that tells you when someone is impersonating you.
RA-01 — The Open SOC Reference Architecture
The open-source SOC diagram everyone shares has two commercial products on it. This is the corrected version — six planes, 24 components with verified licenses and named replacements, an AI analyst plane with a defensible autonomy ceiling, and three sized builds with honest hour counts.
HW-01 — SOC in a Box
The RA-01 architecture landed on one machine you can hold — a coreboot NUC with the Management Engine disabled, Nitrokey as the root of trust, three disks mapped to three storage tiers, and a 14-test acceptance suite you run before pointing a single agent at it.