// rootdrifter — security practitioner

Root//Drifter

Hardened systems · offensive methodology · detection engineering

● Active ● Available

Not technical? Start here →

Security knowledge is a right, not a product. rootdrifter is building in public to prove it.

About

rootdrifter is the working handle of a security professional building toward cleared entry-level roles in the UK, Netherlands, and Germany.

The approach is to build and to break with the same discipline, and to document both to a standard a reviewer can audit. That has produced a hardened Linux workstation and a compartmentalised mobile platform, a grey-box penetration test mapped to recognised benchmarks, and dissertation-level research into whether language models can reason causally about social engineering rather than just pattern-match it. Current focus: CompTIA Security+, active CTF practice, and a Wazuh SIEM home lab for hands-on detection engineering.

Academic background: a First Class BSc in Computer Networks & Cyber Security. This site stays pseudonymous by design — a named CV with full academic and contact detail is available on request.

Portfolio

Full portfolio →  all six projects

Latest writing

28 Jun 2026 3 min read security-notes INCOMING
SIEM Alert Fatigue: Why Tuning Matters More Than Rules

Most SOCs do not have a detection problem — they have a signal-to-noise problem. Why the tuning loop, not the rule count, decides what gets caught.

Read →
28 Jun 2026 4 min read security-notes INCOMING
Verified Boot and Secure Elements: What GrapheneOS Gets Right

A relocked bootloader, a hardware root of trust, and a boot chain you can independently verify — how verified boot actually works and why the discrete secure element matters.

Read →
28 Jun 2026 4 min read network INCOMING
WireGuard vs OpenVPN: A Practical Comparison

Auditability, failure behaviour, and cryptokey routing: the comparison that matters in practice, grounded in running full-tunnel WireGuard on real infrastructure.

Read →

All posts →

More transmissions incoming · Subscribe for early access

Active work

In progress CompTIA Sec+ SY0-701
In progress Wazuh SIEM home lab — detection engineering
Active CTF practice — TryHackMe / HackTheBox
Live rootdrifter.io — content platform, publishing progressively
Available Cleared entry-level roles — UK / NL / DE

Contact

// available for cleared work

[email protected]  ·  github.com/rootdrifter

Open to cleared security roles in the UK, Netherlands, and Germany. CV available on request.