DevOps. Self-hosted. Security.
RSS FeedNotes on DevOps, infrastructure, self-hosting and cybersecurity — practical guides from real-world operations.
Read the posts below or head over to the About page.
Recent Posts

Wazuh: writing custom rules and decoders so your SIEM doesn't drown in noise (part 3/6)
Part 3 of the Wazuh series: the anatomy of rules and decoders, a custom SSH brute-force detection with a threshold you own, a decoder for your application's JSON logs, overriding default rules instead of editing them, and testing everything with wazuh-logtest without restarting the manager.

Wazuh: enrolling agents, turning on FIM and rootcheck for Linux and Windows (part 2/6)
Part 2 of the Wazuh series: enrolling agents on Ubuntu and Windows — automatically via authd or manually with keys — enabling syscheck FIM with realtime and whodata, plus rootcheck, a CIS SCA policy and agent groups. The real question: how to get signal instead of a stream of alerts about benign changes.

Wazuh from scratch: standing up an open-source SIEM/XDR in one evening (part 1/6)
Kicking off a series on Wazuh, the free open-source SIEM/XDR. Part one is installation only: manager, indexer and dashboard via Docker Compose, TLS certificates, first login, and an honest look at how single-node differs from production.

Cilium Tetragon: eBPF runtime security that blocks, not just logs
Falco and most eBPF security tools can only alert after the fact. Tetragon, Cilium's runtime security engine, can do more — kill a process synchronously in the kernel before the syscall even returns. We break down the TracingPolicy anatomy, enforcement risks, and the safe rollout pattern: audit first, Sigkill later.