TOMEK.ST // SYSTEM ONLINE

IT.
SECURITY.
FORENSICS.

Technical services, security research and operational engineering.

STATUSONLINE
$ whoami
TOMEK.ST
$ focus
IT / CYBER / DFIR
$ mode
BUILD / ANALYZE / DEFEND
$ scope
PL / EU / REMOTE
01 / SERVICES

Technical services for real operational problems.

View services
AUTOMATION

Automation

Procedure first, loop second.

Explore →
SECURITY

Cybersecurity

Defence as config and telemetry, not a banner word.

Explore →
DFIR

Digital forensics

Artefact, time, source. Not a crime serial.

Explore →
DFIR

Incident response

Event, facts, decision. Not a retainer slogan.

Explore →
02 / SELECTED WORK

Projects built as operational systems, not screenshots.

View portfolio
Automation / SecOpsresearch

Security automation

Small scripts and webhooks for repeatable IT/SecOps steps. An experiment, not an enterprise platform.

PowerShell / Bash / Python / n8n
Open project →
Digital Forensicsresearch

Digital Forensics Lab

Artefact lab: copy, timeline, fact vs hypothesis. Procedure practice, not court expert work.

Linux / Windows / Disk analysis / Timeline
Open project →
Incident Responsedevelopment

Incident Response Lab

Triage and incident notes in a lab — alert, facts, decision, escalation.

Linux / Windows / SIEM / Incident response
Open project →
03 / CAPABILITIES

Technology stack focused on useful outcomes.

01Windows administration
02Linux administration
03Network security
04SOC / SIEM (lab)
05Incident response
06Digital forensics
07Hardening
08Automation
09PowerShell / Bash
10Virtualisation / lab
04 / PRODUCTS

Digital products for people who prefer practical documentation.

View products
ebook

Architecture of Invisibility

A publishing project in progress. Price is indicative.

View product →
checklist

SOC L1 Home Lab Checklist (product)

Paid, wider checklist. Not the same as the free resource.

View product →
05 / RESEARCH

Notes, research and technical field documentation.

View blog

SOC L1 Home Lab: environment architecture

A light L1 lab: host, two endpoints, a collector. The data path matters more than the tool pile.

Read →

Wazuh as a starting point for SIEM

From an endpoint log to an alert you can keep or close. Wazuh in a lab, not on a slide.

Read →

Windows Event Logs for SOC L1

Source and context beat a memorised number. Security, process, PowerShell — if audit is even on.

Read →
07 / CONTACT

Have a technical problem?

Describe the environment, problem and expected outcome. I will determine the appropriate technical path.

Send inquiry