NervHQ
Enterprise-grade home network & security infrastructure
A multi-host network built the way a small enterprise would be, with layered controls:
segmentation across 10.6.7.0/24 for services and clients and
10.6.8.0/24 for name resolution and remote access, centralised SIEM
monitoring, IDS/IPS inline at the perimeter, and encrypted remote access. It is the
proving ground — every alert, tuning decision and incident writeup on my résumé
originates here.
- Wazuh SIEM 4.14 — manager, indexer & dashboard tiers with Filebeat shipping
- pfSense perimeter with Suricata IDS/IPS inline, behind a bridged AT&T fibre modem
- Pi-hole sinkhole + Unbound DNSSEC-validating recursive resolution
- WireGuard remote access with per-peer keys