SYSTEM STATUS: OPERATIONAL
NODE: HOLDEN-BASE
UPTIME: 35y 000d
--:--:-- UTC
brian@holden — 80×24
brian@holden:~$
brian@holden:~$

type help in the terminal

// operator profile

Brian Holden

Senior security professional with roughly three and a half decades in IT, the last several years focused on privileged access management. I build and run the tooling that keeps credentials rotated, access scoped, and audits boring — mostly around Delinea Secret Server, PowerShell automation, and the SIEM stack that watches all of it.

Privileged Access Management Delinea Secret Server PowerShell Automation SIEM & Detection Tooling Compliance Reporting Mail Security (Mimecast)

// focus areas

Where I spend my time

Privileged Access Management

Vault design, rotation policy, least-privilege scoping, and the unglamorous work of keeping a large secret inventory clean, current, and defensible at audit time.

Automation & Tooling

PowerShell-first tooling that turns manual credential and permissions work into repeatable, reportable processes — built to survive contact with a real production environment.

Security Operations

SIEM integration and tuning, mail-security administration, and the day-to-day operational discipline that keeps detection signal ahead of noise.

Compliance & Reporting

Gap analysis and reporting that maps technical control state to the language auditors and leadership actually need to see.

// notes from the field

Recent write-ups

PAM

Credential rotation at scale, without breaking things

Notes on staged rotation for service accounts with hard-coded dependencies, and how to find those dependencies before they find you.

SIEM

Tuning detections so people still trust the alerts

A practical approach to alert-fatigue triage: what to mute, what to escalate, and how to tell the difference without guessing.

COMPLIANCE

Turning a secret inventory into an audit-ready story

How gap analysis on a large vault environment turns into a report someone outside security can actually read and act on.

siem.local — event stream live
2026-08-24T03:12:41Z INFO vault heartbeat ok
2026-08-24T03:13:02Z INFO rotation job completed batch=0447
2026-08-24T03:13:55Z WARN login retry threshold approaching svc=mimecast-relay
2026-08-24T03:14:02Z INFO checksum=Uk9UQVRF verified ok
2026-08-24T03:14:37Z INFO mesh beacon received node=HOLDEN-BASE
2026-08-24T03:15:10Z WARN config drift detected — scheduled remediation

// off the grid

Signal & mesh

Outside of vault work I run a permanent Reticulum propagation node and hold a General class amateur radio license. I like infrastructure that keeps working when the usual infrastructure doesn't — which probably explains both the day job and the hobby.

signal.decode — 20m band

Received transmission, shift unknown. The band tells you the number.

// restricted

Vault access

A minimal secret store demo. Doesn't hold anything real — but the passphrase check is.

secret-server-lite — authenticate

Passphrase hint: what you do to data before it leaves the perimeter.

// connect

Get in touch

Open to conversations about PAM, security automation, and the occasional mesh-networking tangent. Reach out through your channel of choice.