X

You can join MEGA, the most secure cloud storage, with this referral link: https://mega.nz/aff=7Y94iYz_csg

  • Home
  • Patreon Login
  • All posts
  • Recent
  • Merch Store
  • Follow
  • Follow
  • Follow
  • Follow
  • Follow

Why the SolarWinds hack matters

by Tristan Dostaler | Dec 14, 2020 | Cybersecurity, DFIR, Hack, Information Technology, InfoSec, TL;DR;

Maybe you saw the news on the SolarWinds hack. If you didn’t, you should follow me on Twitter: https://twitter.com/TristanDostaler
In this post I want to explain, in a way understandable by everyone, why this hack matters.

Information Security synonyms

by Tristan Dostaler | Dec 2, 2020 | Cybersecurity, Information Technology, InfoSec

If we try to reduce the security problem to only the technology, we’ll fail miserably.

SIEM Solutions 101 — Basic usage

by Tristan Dostaler | Nov 26, 2020 | Cybersecurity, Information Technology, InfoSec, SIEM, SIEM 100 series

In this post I’ll explain the basics on using a SIEM: how to search logs and how to send alerts.

SIEM 201 — What is Sysmon

by Tristan Dostaler | Nov 25, 2020 | Cybersecurity, Information Technology, InfoSec, SIEM, SIEM 200 series, TL;DR;

In this post I’ll explain what is Sysmon, how to install it and how to use it to detect important pattern.

SIEM 102 — Detect Windows bruteforce

by Tristan Dostaler | Nov 25, 2020 | Cybersecurity, Information Technology, InfoSec, SIEM, SIEM 100 series

When we have a lot of Windows machine in our environment, it can be useful to be able to detect a bruteforce on a machine.

SIEM 202 — Detecting remote PsExec

by Tristan Dostaler | Nov 24, 2020 | Cybersecurity, DFIR, Information Technology, InfoSec, SIEM, SIEM 200 series

In this post I’ll explain how to detect an attacker that uses PsExec to connect to your computer when you don’t have visibility over the attacker’s computer.

SIEM 101 — Initial setup

by Tristan Dostaler | Nov 24, 2020 | Cybersecurity, Information Technology, InfoSec, SIEM, SIEM 100 series, TL;DR;

In this post, I’ll explain how to initially setup a SIEM so you can receive your first logs.

Never receive an alert from Windows Defender? You should!

by Tristan Dostaler | Nov 23, 2020 | Cybersecurity, Information Technology, InfoSec, Pentest, Personal, SIEM

The fact that we didn’t know Defender blocked an attack and we only learned it when we receive the report should be considered a disaster!

SIEM 101 — Introduction

by Tristan Dostaler | Nov 23, 2020 | Cybersecurity, Information Technology, InfoSec, SIEM, SIEM 100 series

In the following days, I’ll write a few blog posts explaining how to easily learn to use a SIEM.

Your server is secure? Really?

by Tristan Dostaler | Nov 23, 2020 | Cybersecurity, Information Technology, InfoSec, SIEM

You’ve hardened all you could on your servers or computers, and think your secure? Think again!

Next Entries »

MEGA referal

You can join MEGA, the most secure cloud storage, with this referral link: https://mega.nz/aff=7Y94iYz_csg

Recent Posts

  • Lockbit ransomware – How to recover your data
  • How to secure WordPress
  • SIEM 103 — Detect Windows bruteforce part 2

Subscribe!

Support

Buy me a coffee
Become a patron at Patreon!

Follow Me

  • Twitter
  • Facebook
  • RSS Feed
  • Discord

Media and Support

  • Twitter
  • Facebook
  • RSS Feed
  • Discord
Buy me a coffee

Referal and Benefits

You can join MEGA, the most secure cloud storage, with this referral link: https://mega.nz/aff=7Y94iYz_csg

Become a patron at Patreon!

Recent posts

  • Lockbit ransomware – How to recover your data
  • How to secure WordPress
  • SIEM 103 — Detect Windows bruteforce part 2
  • Why I switched from Logz.io to Humio
  • CIS controls – where to start in securing a medium/big enterprise

Subscribe!

  • Privacy Policy