Know When You've Been Touched: SSH Alerts + Intrusion Detection
Turn your VPS into a server that speaks up. Learn how to receive instant SSH login alerts and detect unauthorized system changes using PAM, cron, and Ntfy.
Notes from my board on what's happening in the field and what I'm learning along the way: the practitioner work behind Ministry in Context.
I have a physical board behind my desk covered in sticky notes. Topics I'm tracking. Things that clicked. Runbooks I built for myself before I realized someone else might need them. News that mattered and my take on why.
This page is the digital version of that board. It's not a course. It's not polished for a general audience. It's practitioner-to-practitioner: the kind of notes you'd share with your colleague over Teams.
If you're maintaining certifications, staying current, or just trying to think more clearly about a problem: you're in the right place.
Everything falls into one of these buckets. Each one is worth a different kind of attention.
Topic deep-dives written from experience, not from a textbook. Frameworks, concepts, and controls explained the way a practitioner would explain them to a colleague.
Browse guides →Operational, step-by-step. Built because I needed them first. Each one is something I've actually run in my homelab or tested in a real environment, not a theoretical procedure.
Browse runbooks →Current advisories, vulnerabilities, and incidents, with context. Not a feed: a practitioner's take on what actually matters and what the implications are for your environment.
Browse industry news →Shorter notes on patterns, lessons, and things I keep seeing in the field. The kind of thing you'd write on a sticky note and tape to your monitor so you don't forget it.
Browse observations →For career changers, complete beginners, and veterans making the transition into cybersecurity. Real experience, a proven roadmap, and no shortcuts glossed over.
Browse getting started →Latest guides, runbooks, and analysis: sorted by what's most useful right now.
Turn your VPS into a server that speaks up. Learn how to receive instant SSH login alerts and detect unauthorized system changes using PAM, cron, and Ntfy.
Bots begin probing your VPS within minutes of it going online. Learn how to configure Fail2ban to automatically detect repeated SSH login failures, ban malicious IPs, and protect your server 24/7.
How to configure policy-based routing (PBR) in Linux so traffic from a specific IP or interface uses a separate routing table.
The foundation came first. Every certification on this list was a deliberate step — not a collection, a path. This is the foundation the content on this site is built on. If there's one thing this site stands for, it's that there are no shortcuts to knowing what you're doing.
Content on this site may qualify toward CPE/CEU requirements for ISACA, CompTIA, and other certifying bodies: verify with your organization's continuing education policy.
When something worth writing goes up, you'll hear about it first. Practical, peer-level cybersecurity content: no vendor spin, no course pitches.
No spam. Unsubscribe anytime.