visitor@hunterweygandt:~$ |

Hunter Weygandt

Build. Break. Secure. Repeat.

About Me

visitor@hunterweygandt:~$ whoami|

I’m a Senior Systems Analyst at Meriplex with experience across IT infrastructure, Microsoft 365, identity, endpoint management, networking, troubleshooting, and security.

I work in an MSP environment, so I support a wide range of client systems and environments. I spend a lot of my time working with Microsoft 365, Entra ID, Intune, Active Directory, Windows, networking, and general infrastructure. I also handle the security side of a lot of normal IT work, including Conditional Access, MFA, account security, phishing investigations, email authentication, malware scans, endpoint protection, and suspicious sign-ins.

I work with a ton of enterprise security tools, mostly from the systems and troubleshooting side. I use them to verify endpoint protection, run scans, review quarantined items, troubleshoot agents, and respond to users reporting malware, adware, or suspicious activity.

I’ve always enjoyed troubleshooting problems that require digging a little deeper than the obvious answer. That interest is a big part of what pulled me further into security. I like working through logs, authentication activity, network behavior, and system changes to understand what actually happened instead of only fixing the immediate symptom.

Outside of work, I run a home lab where I can go much deeper into both infrastructure and security. My environment includes Proxmox, Active Directory, Wazuh, OPNsense, Suricata, Windows, Linux, Docker, and other platforms. I use it to build systems, test configurations, simulate attacks, investigate security events, and write detections.

One of my larger projects involved building an isolated Active Directory environment, executing several common AD attacks, collecting the resulting Windows telemetry, and creating custom Wazuh rules to detect that activity. Projects like that let me work with areas of security that I don't normally handle in my day-to-day job.

I hold CompTIA Security+ and have completed the TryHackMe SOC Level 1 learning path. I’m continuing to grow deeper into security operations, but I don’t consider my IT background something I’m moving away from. Understanding systems, identity, networking, DNS, endpoints, and how users actually interact with an environment is a big part of how I approach security.

Skills

visitor@hunterweygandt:~$ cat skills.txt|

Networking & Infrastructure

Security

Cloud & Identity

Tools

And many more! For a full list of skills visit my LinkedIn.

Certifications

visitor@hunterweygandt:~$ cat certs.txt|

Active

For all the details, please visit my LinkedIn.

Projects

visitor@hunterweygandt:~$ ls -la projects/|

Cybersecurity Server

I built a Proxmox-based cybersecurity lab with Parrot, Kali, HackTheBox, a vulnerable Windows VM, an isolated honeypot network, OSINT focused Kali/Trace Labs tools VM, KASM, OPNSense, and a Wazuh SIEM monitoring stack. I have used this environment to practice OSINT, offensive security, threat detection, and safe malware analysis.

Read the full write-up →

Vulnerable AD Detection Lab

I built a deliberately vulnerable Active Directory lab to practice detection engineering across the full initial-access-to-domain-dominance chain. Running on a domain controller, two workstations, and a central Wazuh manager — isolated behind OPNsense on VLAN 60 — it covers seven attacks: Kerberoasting, AS-REP Roasting, Password Spraying, LLMNR/NBT-NS Poisoning, ACL Abuse, Pass-the-Hash, and DCSync. Six are paired with custom Wazuh rules that flag activity the stock ruleset misses; one (LLMNR) required a network sensor because host agents can't see it.

Read the full write-up →

Building This Site

Built this site from scratch and documented the whole process: registering a domain, moving DNS to Cloudflare, hosting on GitHub Pages, locking down HTTPS and security headers, and setting up custom email with SPF, DKIM, and DMARC.

Read the full write-up →

See more of my projects here →