DevOps. Self-hosted. Security.
RSS FeedNotes on DevOps, infrastructure, self-hosting and cybersecurity — practical guides from real-world operations.
Read the posts below or head over to the About page.
Recent Posts

Wazuh and Kubernetes: collecting cluster audit logs and seeing who does what (part 5/6)
Part 5 of the Wazuh series: taking the SIEM beyond individual hosts and into Kubernetes — audit policy and its levels, shipping logs with Fluent Bit, a decoder for audit JSON, and rules for exec, secrets reads, and privileged pods mapped to MITRE ATT&CK for Containers.

Wazuh Active Response: automatically banning, isolating, and responding to incidents (part 4/6)
Part 4 of the Wazuh series: turning a fired detection into an automatic reaction — the anatomy of Active Response, the built-in firewall-drop, a custom nftables blocking script with a timeout and an admin-subnet safety exception, and how not to ban yourself.

Wazuh: writing custom rules and decoders so your SIEM doesn't drown in noise (part 3/6)
Part 3 of the Wazuh series: the anatomy of rules and decoders, a custom SSH brute-force detection with a threshold you own, a decoder for your application's JSON logs, overriding default rules instead of editing them, and testing everything with wazuh-logtest without restarting the manager.

Wazuh: enrolling agents, turning on FIM and rootcheck for Linux and Windows (part 2/6)
Part 2 of the Wazuh series: enrolling agents on Ubuntu and Windows — automatically via authd or manually with keys — enabling syscheck FIM with realtime and whodata, plus rootcheck, a CIS SCA policy and agent groups. The real question: how to get signal instead of a stream of alerts about benign changes.