Skip to content
View CRobin0780's full-sized avatar

Block or report CRobin0780

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
CRobin0780/README.md

👋 Hi, I'm Chris Robinson

🎯 Military veteran transitioning into IT/Cybersecurity | SysAdmin & SOC Analyst
🛡️ Building a production-grade enterprise SOC homelab: Fort Reign
📍 Colorado Springs, CO | Active Secret Clearance | Open to SysAdmin & Azure Admin roles
💼 Client Support Administrator @ Apex Systems → Amentum IRES (DoD)


🏰 Fort Reign — Enterprise SOC Homelab

Fort Reign is a fully operational enterprise-style infrastructure and security operations environment built on a 3-node Proxmox cluster. It mirrors real-world DoD and enterprise environments with hybrid identity, centralized SIEM, endpoint detection, threat intelligence, and automated infrastructure management.

Infrastructure

ComponentDetails
Hypervisors3-node Proxmox cluster — Dell T7810 (64GB), OptiPlex 7070 (32GB), OptiPlex 3050 (16GB)
NetworkUbiquiti ER-X router · Cisco SG300 managed switch · 4-VLAN design (Management, Enterprise, Attack, IoT)
DomainWindows Server 2022 Active Directory · DNS · DHCP · Group Policy
Hybrid IdentityMicrosoft Entra Connect · Password Hash Sync · MFA · DCSync attack path mapped via BloodHound
AutomationAnsible control node managing 6 Linux servers · Self-hosted Gitea version control

🔐 Security Stack (Phases 1–5)

SIEM & Monitoring

ToolStatusDetails
Wazuh✅ Live3 agents · Sysmon integrated · DC01, FRG-W10-01, FRG-W10-02
Splunk✅ LiveWazuh forwarding pipeline · Detection dashboards in progress
Security Onion✅ LiveSPAN port monitoring · IDS · PCAP analysis

SOC Tools

ToolStatusDetails
Velociraptor✅ LiveEndpoint forensics & live response · 3 agents enrolled · VQL hunts running
MISP✅ LiveThreat intelligence platform · 5 active feeds (CIRCL, Feodo, URLhaus, MalwareBazaar, Phishtank)
BloodHound CE✅ LiveAD attack path analysis · DCSync rights mapped · MSOL sync account finding documented

📁 Repositories

Enterprise infrastructure build — Active Directory, DNS, DHCP, Group Policy, VLAN segmentation, Proxmox cluster, Ansible automation, static IP management.

Key skills demonstrated:

  • Windows Server 2022 AD deployment and hardening
  • 4-VLAN network architecture with inter-VLAN routing
  • Ansible playbooks for patch management and configuration
  • Entra Connect hybrid identity with Password Hash Sync
  • Self-hosted Git (Gitea) for infrastructure version control

Full SOC stack deployment — SIEM pipeline, endpoint detection, threat intelligence, and incident response.

Key skills demonstrated:

  • Wazuh SIEM with Sysmon telemetry and Windows audit policies
  • Splunk log aggregation with Wazuh Universal Forwarder
  • Security Onion network security monitoring with SPAN port
  • Velociraptor endpoint forensics — VQL hunts across all endpoints
  • MISP threat intelligence with automated IOC feed ingestion
  • BloodHound AD attack path analysis — DCSync exposure documented
  • IR report writing (IR-2026-001: DCSync rights via Entra Connect)

Azure hybrid identity and cloud administration lab — extends on-prem Fort Reign into Azure.

Key skills demonstrated:

  • Microsoft Entra ID tenant configuration
  • Entra Connect hybrid identity synchronization
  • MFA deployment and Conditional Access policy design
  • RBAC and Azure resource management

🛠️ Technical Skills

Infrastructure & SystemsProxmoxWindows Server 2022Active DirectoryDNSDHCPGroup PolicyLinux (Ubuntu 24.04)Rocky Linux

Security OperationsWazuhSplunkSecurity OnionVelociraptorMISPBloodHoundSysmonIDS/IPSPCAP AnalysisThreat HuntingIncident Response

Identity & CloudMicrosoft Entra IDEntra ConnectHybrid IdentityMFAAzureRBACConditional Access

NetworkingVLANsInter-VLAN routingUbiquiti EdgeOSCisco SG300pfSenseWiresharknmap

Automation & DevOpsAnsibleBashPowerShellPythonGiteaGitsystemdNetplan

Frameworks & ComplianceNIST RMFMITRE ATT&CKNIST 800-53DoD 8570ITIL v4


📜 Certifications

CertificationStatus
CompTIA A+✅ Earned
CompTIA Network+✅ Earned
CompTIA Security+ CE✅ Earned
AZ-900 Azure Fundamentals✅ Earned
ITIL v4 Foundation✅ Earned
AZ-104 Azure Administrator🔄 In Progress
CompTIA Linux+📅 Planned
RHCSA📅 Planned
CCNA📅 Planned

🎖️ Military Background

4 years U.S. Military service as a Logistics Officer — supply chain management, resource allocation, mission planning, and leading teams under operational conditions. The same discipline applied to building Fort Reign: structured phases, documented SOPs, version-controlled configs, and operational logging.

Active Secret clearance.


📫 Connect

LinkedInGitHub


Fort Reign is an ongoing build. New tools, attack simulations, and documentation added regularly.

Pinned Loading

  1. fortreign-sysadmin-lab-legacyfortreign-sysadmin-lab-legacyPublic

    Enterprise homelab infrastructure — Active Directory, Proxmox cluster, VLAN segmentation, Ansible automation, hybrid identity with Entra Connect.

    PowerShell

  2. fortreign-soc-lab-oldfortreign-soc-lab-oldPublic

    Production-grade SOC homelab — Wazuh, Splunk, Velociraptor, MISP, BloodHound, Entra Connect hybrid identity. 6-phase build with IR reports and Ansible automation.

  3. CRobin0780CRobin0780Public