Scheduled Task Detection
Creating and tuning a detection for suspicious task creation (Windows)
Creating and tuning a detection for suspicious task creation (Windows)
Blocking RDP brute-force attackers using Sentinel playbooks.
Simple lab environment setup for Azure
Before implementing any controls, it is worth establishing a baseline to evaluate their effectiveness. In this case, we are measuring the number of failed RDP attempts before implementing IP-blocki...
WebServer, MySQL, RabbitMQ, and Data Processor VMs set up + port forwarding rule for the webserver.
Wazuh VM + agent deployment checkpoint
Full Security Onion setup guide (VMware)
Deploying OpenVAS via docker
OPNsense interfaces and routing setup
Ingesting OPNsense and NetFlow logs for Security Onion