Skip to main content

Command Palette

Search for a command to run...

I Used to Hunt Audiences. Now I Hunt Attackers.

The ad brain and the hacker brain turn out to be the same brain.

Updated
6 min readView as Markdown
I Used to Hunt Audiences. Now I Hunt Attackers.
0
30 years in creative leadership (in the ad industry as a Creative Director) taught me one core skill: dissecting complex systems and finding the flaw before someone else does. My tech roots run back to 8-bit machine code on a C64 (yeah – 80s, baby!) Today, I’m combining that legacy hacker curiosity with modern threat detection and offensive security. BATTLE-TESTED LOGIC: Decades of high-pressure problem solving and systems analysis. HACKER MINDSET: I don't just follow playbooks; I reverse-engineer how the attack path actually works. CONTINOUS SKILL-UP: CompTIA Security+ certified (among other certs), building home labs, and constantly training for L1 ops to future Pentesting.

Part 7 of an ongoing series. Start with part 1 here.

It happened on a Tuesday, somewhere between a DNS tunneling exercise and my third cup of coffee.

I was staring at a network log — VPN entries, firewall hits, IDS alerts — trying to figure out what story it was telling me. And something clicked that had nothing to do with cybersecurity. It was an old reflex. A muscle memory from a different life.

I know how to do this.

Not the tools. Not the specific technique. Something older than that. The act of reading signals and asking: what is this person actually doing, and why?

I spent 30 years doing exactly that in advertising. I just didn't know it counted.


Here's what a Creative Director actually does, stripped of the bullshit:

You take a pile of data — research, briefs, audience insights, behavioral patterns — and you reconstruct intent. You figure out what someone wants, what they fear, what they'll respond to, what they're trying to hide even from themselves. You build a picture of a person from the traces they leave. Then you figure out how to reach them.

That's not so different from what a SOC analyst does with a packet capture.

I'm looking at network traffic. Someone connected to a VPN at 2:47am. Hit three servers in sequence. Queried a domain that's two weeks old. The data exfiltration — if that's what it is — is happening inside DNS requests, slow-dripped, each one small enough to look like noise.

What is this person actually doing, and why?

Same question. Different battlefield.


I wrote in my journal this week: "Everyday things get clearer and I catch myself thinking about some security topic the way I thought about solving some advertising problem in the past."

When I wrote it, I thought it was just an observation. Now I think it's the whole point of this series.

The comeback isn't just a career change. It's a translation. Thirty years of training in one domain, being reverse-engineered and reapplied in another. The tools are different. The vocabulary is different. The adversary is different — in advertising, the "adversary" is indifference; in security, the adversary is a person who actually wants to hurt you. But the cognitive move? Reading behavior. Reconstructing intent. Finding the anomaly in the pattern.

That's the same move. Every time.


This week I got deep into email forensics. Header analysis. Phishing detection. The forensics of a fake email are almost insultingly familiar to me: someone constructed a message designed to make you trust it. They picked the right sender name, the right subject line, the right tone of urgency. They A/B tested this, in their own grim way.

I've written those emails. Not phishing emails — campaign emails. Lead generation. "Your account needs attention." "Limited time." The mechanics of manufactured urgency that get someone to click without thinking.

Now I'm on the other side of it. Looking at the header. Checking the Reply-To address. Running the domain through VirusTotal. Asking: what are they trying to make me believe, and what does the infrastructure underneath tell me about who they actually are?

Thirty years of writing manipulation, now in service of detecting it.

There's a certain dark poetry in that.


NetworkMiner was new to me this week. It's a network forensics tool that reconstructs sessions from packet captures — pulls out files, credentials, messages, images. It shows you what actually moved across the wire, reassembled into something human-readable.

The first time I ran it on a sample capture, I had the same feeling I used to get opening a research deck before a campaign brief. Here is the evidence. Here is what the behavior actually was. Not what the person said they were doing — what they actually did.

Advertising research is full of this gap. People say they make rational decisions; they don't. They say they don't respond to emotional appeals; they do. You ignore what they say and watch what they do.

Forensics is the same epistemology. The log doesn't lie. The packet doesn't have an agenda. The behavior is in the data, if you know how to read it.


I want to be careful not to overstate this.

Knowing how to read behavioral signals doesn't make me a trained analyst. I'm still learning the tools. Still getting reps on TryHackMe. Still looking at certain log formats and needing to slow down, go back, re-read. The SOC Level 1 path is harder than I expected, and I mean that as a compliment — it's hard in the right ways, in ways that mean I'm actually learning something.

But the frame helps. Every time I hit something complex, I try to find the human question underneath the technical one. Not "what does this IP address tell me" — but "what was this person trying to do, and did they get away with it?"

That question, I know how to chase.


There's a line I keep coming back to from Part 6: the C64 kid never really stopped wanting to take systems apart — he just spent three decades doing it with briefs and campaigns instead of terminals and packets.

I meant it when I wrote it. I mean it more now.

The systems were always different. The impulse was always the same. Something exists. It has rules. The rules have edges. What happens at the edges?

In advertising: what happens when you break the convention? When the ad doesn't look like an ad? When you say the thing out loud that everyone is thinking but nobody says?

In security: what happens when the protocol does something it wasn't designed to do? When the traffic pattern doesn't match the declared intent? When someone is hiding something in the noise?

Both of those are the same question. What's really going on here?

I've been asking it my whole life. I just have better tools for it now.


The comeback isn't finished. It's not close to finished.

But I'll tell you something I couldn't have told you a year ago: I'm not just learning a new field. I'm recognizing something I already knew, from an angle I couldn't see before. That's a different thing. That's faster, in some ways. And stranger.

I catch myself in the middle of a network analysis exercise, and there's a part of my brain that's calm. Not because it's easy — it's not easy. But because the core skill, the thing underneath everything else, is familiar.

Read the signals. Reconstruct the intent. Find the anomaly.

I've been doing that since 1987, on a Commodore 64, in a bedroom in Germany, trying to figure out how the system worked so I could make it do something it wasn't supposed to.

Turns out that was job training.

Just took me a while to figure out for which job.