Security Operations

SecOps built around visibility, control and safe response.

A joined-up set of homelab security controls that turns telemetry, scan results and protective services into actions that can be reviewed and operated with confidence.

  • CrowdSec
  • Greenbone
  • Suricata
  • Pi-hole
  • Prometheus
  • Grafana

Why SecOps Matters

Security is a continuous operational responsibility.

A collection of security tools does not create a security operation on its own. Signals need to be monitored, findings need context, and changes need to be controlled so protective measures improve the platform rather than create new risk.

SecOps brings prevention, detection, vulnerability assessment and response into one operating model. It supports quicker investigation and provides evidence that controls are working as intended.

Operating Model

From signal to controlled response.

Security controls are useful only when they are visible, maintained and understood.

01

Detect

Suricata and CrowdSec identify suspicious activity from network and reverse-proxy telemetry.

02

Protect

Cloudflare edge controls and Pi-hole DNS filtering reduce exposure before traffic reaches services or client devices.

03

Assess

Greenbone scans surface credible weaknesses and prioritise new or worsened findings.

04

Improve

Observability and review-led playbooks support measured, repeatable remediation.

Security Capabilities

Prevention, detection and response.

01 · Prevention

Edge and DNS protection

Cloudflare provides the first external layer of prevention through DNS, TLS, web application firewall rules, rate limiting and DDoS mitigation for publicly exposed services routed through it.

Pi-hole adds an internal layer, filtering DNS requests across the network and stopping client devices resolving known advertising, tracking and unwanted domains before a connection can be made.

View Pi-hole project →View dashboard snapshot →

02 · Detection

Threat detection and response

CrowdSec combines behavioural detection, community intelligence and automated firewall decisions for internet-facing and infrastructure services. For direct access through the public IP or DuckDNS, it sees the real source address and can block decisions at the origin firewall.

View CrowdSec case study →

03 · Response

Evidence-led remediation

Greenbone identifies credible weaknesses across managed Linux systems so remediation can be prioritised, approved and applied in a controlled way.

View Greenbone case study →

Engineering Outcome

Security work presented as an operational capability.

SecOps ties together prevention, detection, assessment and remediation so the individual tools form one understandable, supportable service.