Cybersecurity • SOC • AI Automation

Practical cybersecurity, SOC operations, and AI automation.

I help people and security teams turn complex cyber work into clear processes, stronger reporting, useful training, and practical automation.

What I do

Modern cybersecurity support with a practical, hands-on approach.

Cansguy is where I share and build practical cybersecurity, network security, SOC operations, and automation work. The focus is simple: clear processes, better documentation, useful training, and workflows that save time.

Operate

SOC workflow improvement

Improve triage, escalation notes, incident timelines, and handovers so alerts turn into clear decisions.

Detect

Microsoft Sentinel and Defender XDR

Improve investigations, tune detections, and turn Microsoft security signals into clear actions.

Automate

AI-assisted security workflows

Use n8n, AI agents, scripts, and prompts to reduce repetitive SOC and reporting work.

Teach

Cybersecurity training and labs

Build practical labs and training content that helps people learn analyst thinking.

Secure

Network security foundations

Bring network security context into alert review, documentation, and investigation work.

Explain

Security reporting and technical writing

Create customer-ready reports, playbooks, knowledge articles, and plain-language security documentation.

SOCMicrosoft SentinelDefender XDREntra IDIncident Responsen8nAI Agents

About

Learning, building, and helping others grow in cyber.

My work sits at the intersection of cybersecurity operations, network security, training, and automation. I enjoy breaking down complex security problems into practical steps, sharing what I learn, and building workflows that make security work easier to repeat.

Current focus

Cybersecurity, AI, and automation

Building practical workflows for SOC tasks, research, documentation, reporting, and cyber training.

2022

Cybersecurity trainer and engineer

Supported cyber skills development, threat intelligence, incident management, and security solution improvement.

2016 to 2018

Network Security Administrator

Investigated security incidents, supported network security platforms, and worked with enterprise infrastructure technologies.

Portfolio

Projects, labs, and practical builds.

Selected examples of the practical work I am building across security documentation, SOC automation, cyber learning, and AI-assisted workflows.

SOC Reports

Security documentation

Incident summaries, service reports, process notes, playbooks, and customer-ready technical content.

Automation

Automation workflows

n8n workflows, AI-assisted summaries, enrichment steps, and repeatable SOC admin processes.

Cyber Labs

Cyber learning labs

Hands-on cyber labs, analyst exercises, AI experiments, and beginner-friendly training material.

Proof and deliverables

Practical outputs, not just broad capability statements.

The focus is on useful security operations material that can be reused by analysts, managers, and small teams.

SOC workflow packsTriage notes, escalation templates, incident timelines, and handover formats.
Microsoft security notesSentinel, Defender XDR, Entra ID, KQL thinking, and investigation summaries.
AI automation workflowsn8n workflows, reusable prompts, daily summaries, and enrichment ideas.
Training contentCyber labs, awareness material, analyst exercises, and beginner-friendly guides.
Work with me

Want to build clearer, smarter cybersecurity workflows?

I can help with practical security operations support, Microsoft security workflow improvement, training content, technical writing, and lightweight automation ideas.

SOC workflow improvement

Triage notes, escalation templates, incident timelines, handover formats, and reporting structures that help analysts move from alerts to decisions.

Microsoft Sentinel and Defender support

Practical help with incident review, Defender investigation notes, Entra ID signals, KQL thinking, detection tuning ideas, and stakeholder-friendly summaries.

AI and n8n automation ideas

Reusable prompts, daily summaries, research workflows, enrichment steps, and repeatable admin processes for security or business operations.