r00t_th3_h4rd_w4y

Published: 2025-02-21

I’m not really an online community or content creation type of person. I never have been, and I do not have plans to become one. Nothing against people who do, it’s just never been my thing. You will probably see me lurking in a bunch of Discord servers though. Say hi if you see me there. I am trying to be more active, and I also want to see where other people in the field spend their time. Part of starting this blog is pushing myself to be more present online. Breaking into a new industry without existing connections is always going to be harder, so I am hoping this helps spark conversations, interactions, and new relationships over time.

A bit of context on the blog title, r00t_th3_h4rd_w4y. A lot of what I have done in life has been learned the hard way. When I got into music, YouTube was not really a thing. I started as an intern, lived in the studio for about a year, worked my way up to assistant, and only then felt stable enough to get my own apartment. I needed to know that my spot was secure and that opportunities were not going to disappear overnight. Most of the learning, and definitely the most valuable parts, were hands-on and in the field. It started with shoulder surfing senior staff, then gradually being trusted to take over while they watched, and eventually being left to sink or swim. That process shaped how I learn and how I work to this day.

For anyone interested in that side of my life, you can see most of my music work here Muso.ai does a solid job correlating credits. A few things are missing and the streaming numbers do not include every provider, but overall it is fairly accurate.

Coming back to r00t_th3_h4rd_w4y, that style of learning ended up being invaluable to me. I originally started tinkering with computers as a kid through video game hacking, phone phreaking, and similar curiosity-driven experiments. Eventually my focus shifted fully into music, and that stayed the priority until Covid. During that period, I wanted to build a fully secure remote and private cloud connection between my studio and my home. I got stuck on the security side of that problem, and that curiosity pulled me back in. Computers, hacking, and security slowly stopped being just background interests and turned into a serious hobby with whatever free time I could find. I bounced between free training, vulnerable machines, Splunk labs, security news, RSS feeds, blogs, and podcasts.

I am now getting ready to build my own private cloud and remote networking setup for both business and personal use. I will write more about that soon. I have been making steady progress in upskilling toward cybersecurity. I am currently working through the mid-capstone for TCM’s PJPT, the File Upload Attacks section of the HTB CWES, and reinforcing PJPT concepts through the HTB Penetration Tester Path. I have rooted all of these PJPT boxes so far:

Progress screenshot

I also run my own target machine with Juice Shop and DVWA, feeding logs into a blue-team setup using Elasticsearch, Kibana, Beats, and Logstash for detection and analysis practice. I have been seeing a lot of discussion around Wazuh lately as well, so that is likely next on my list to experiment with in the coming weeks.