Project Blackwall

A ground-up network overhaul from a flat 10.0.0.0/16 network to a fully segmented, zero-trust infrastructure. Eight VLANs, MikroTik switching, a bare-metal OPNsense “outer ICE”, split-horizon DNS with Bind9, and Authentik as a centralised identity plane — built on a £750 budget with second-hand enterprise hardware.

  • Scope: VLAN micro-segmentation, OPNsense routing/firewall, MikroTik L2 switching, MPSK WiFi, Bind9 split-horizon DNS, Authentik SSO/RADIUS
  • Timeline: 2025–2026
  • Stack: OPNsense, MikroTik CRS328, TP-Link Omada, Bind9, Authentik, Dell PowerEdge R330/R730xd
  • Budget: ~£750

[writeup] [whitepaper]


Project Argus

A multi-phase access segmentation, detection, and response programme. Follows Project Blackwall with 6 planned phases: tightening inter-VLAN firewall rules, identity and secrets management, network visibility, detection engineering with Sigma and Atomic Red Team validation, automated orchestration via Tracecat, and ongoing deception and compliance hardening. Defined by a set of design principles: automation over manual toil, version-controlled infrastructure, documentation as a first-class output.

  • Scope: Firewall rule migration, Authentik RADIUS/SSO/PKI, OpenBao secrets, NetFlow/Suricata visibility, Wazuh SIEM, Sigma/ART detection, Tracecat SOAR, Canarytokens/OpenSCAP hardening
  • Timeline: 2026 (ongoing — Phase 1 in progress)
  • Stack: OPNsense, Authentik, OpenBao, Wazuh, Suricata, Tracecat, MikroTik, Ansible, GitLab CI

The 642 Project

A creative writing challenge: 642 prompts, 1000+ words each, totalling over 642,000 words. Because sometimes the unreasonable choice is the right one.

[project page]