Notes from the Blue / IT blog

Independent IT blog · Security & Infrastructure

What you learn
when you actually dig in.

An independent blog covering detection engineering, homelab builds, and general IT topics — with hands-on tutorials, field notes, and honest write-ups from real-world experience.

Written by a practitioner. For practitioners.

// TUTORIALS Step-by-step guides you can actually follow and replicate.
// FIELD NOTES Lessons from things that worked — and things that didn't.
// WRITE-UPS Deep dives into security topics with context and analysis.
// GENERAL IT Tools, workflows, and concepts worth knowing about.

01 //
Detection Engineering
Building detection logic that actually works — from threat modelling to alert tuning, log quality, and rule lifecycle management.
02 //
Homelab & Self-Hosting
Running a serious lab at home: virtualisation, networking, automation, and the tools that make it actually useful.
Proxmox OPNsense n8n Docker Traefik NetBird
03 //
General IT
Networking fundamentals, Linux internals, tooling picks, and topics that don't fit a neat category but are worth understanding.
"Dwell time is the window between intrusion and detection. What happens inside that window is the whole game." — Editorial philosophy of the lab
Site live
First articles — coming soon
Newsletter — planned
--:--:-- UTC+1