Tags

Wazuh

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

MITRE-ATT&CK

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

Sysmon

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

AWS

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Back to Top ↑

CloudTrail

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Back to Top ↑

SIEM

Back to Top ↑

Incident-Response

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

Resposta-a-Incidentes

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

Back to Top ↑

Windows

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

PowerShell

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

Detection-Engineering

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

Engenharia-de-Detecção

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

Back to Top ↑

S3

Back to Top ↑

EventBridge

Back to Top ↑

SNS

Back to Top ↑

IAM-Access-Analyzer

Back to Top ↑

EC2

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Back to Top ↑

SSRF

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Back to Top ↑

IMDSv2

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Back to Top ↑

OWASP

AWS SSRF Investigation: IMDS, CloudTrail, and Hardening

2 minute read

A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal destination blocking, and least privilege.

Back to Top ↑

Splunk

Back to Top ↑

SOC

Back to Top ↑

Python

Back to Top ↑

OpenAI

Back to Top ↑

LLM

Back to Top ↑

pfSense

Back to Top ↑

Proxmox

Back to Top ↑

Endpoint-Security

PowerShell Alert Triage with Sysmon and Wazuh

1 minute read

Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legitimate administrative behavior.

Back to Top ↑

Segurança-de-Endpoints

Triagem de alerta PowerShell com Sysmon e Wazuh

1 minute read

Laboratório prático de triagem de endpoint com Sysmon e Wazuh, comparando execuções de PowerShell, analisando telemetria de criação de processos e contextualizando atividade potencialmente suspeita.

Back to Top ↑

Cloud-Security

Back to Top ↑

Segurança-em-Nuvem

Back to Top ↑

Alert-Triage

Back to Top ↑

Alert-Analysis

Back to Top ↑

Análise-de-Alertas

Back to Top ↑