1 published · 5 upcoming
Breaking Out of the AppSec Bubble
Getting Security Onion running, debugging VirtualBox networking, and figuring out why giving a SIEM only two network adapters breaks everything.
Read postEndpoint Visibility: Wazuh and the Windows Log Problem
Default Windows event logging is basically useless for threat hunting. What Sysmon fixes, and how to get it all into a SIEM.
Simulating Attacks and Hunting for Them
Running ATT&CK techniques against a victim VM and hunting for them across Suricata, Zeek, and Sysmon. The core detection loop.
Case Management with TheHive
Building the habit of opening a case, documenting what you found, running enrichment, and closing it properly.
Threat Intelligence with MISP
Free threat feeds, IOC enrichment, and what threat intelligence actually looks like when you set it up yourself.
Live Forensics with Velociraptor
VQL queries, live endpoint collection, and hunting for artifacts after running Atomic Red Team tests.