Incident Journal: Events & Experiences
Working notes from investigations and detection engineering, mapped to the NIST incident response lifecycle.
Working notes from investigations and detection engineering, mapped to the NIST incident response lifecycle.
How to lock down a systemd service with the sandboxing directives that ship in the box, how to measure the result, and where it sits next to a firewall and a hardened SSH setup.
A short walkthrough of fail2ban's mental model, the minimum useful config, and how it complements iptables and a hardened SSH setup.
A practical walkthrough of iptables rule logic, chain structure, and building a sensible default policy from scratch.
A practical walkthrough of SSH hardening steps that meaningfully reduce your attack surface without breaking anything.
How passive reconnaissance using open source intelligence reveals more than most people expect, without sending a single packet.
Using tcpdump to capture, filter, and interpret live network traffic from the command line.
A look at where rootless containers, immutable operating systems, and open source software intersect, and why those three things together are becoming the new baseline.
A walkthrough of using chkrootkit to scan a Linux host for known rootkit signatures.
A Python log analyzer that reads SSH and web server logs and flags suspicious patterns like brute-force attempts, port scans, and probing of restricted URLs.