Lab LABS
23 Sept 2026 · 21 min read · Intermediate
Turn a Raspberry Pi 5 into a practical Mini SOC with Wazuh. Monitor up to 25 Windows, Linux and macOS endpoints, detect vulnerabilities, watch file changes and centralize security alerts without buying an enterprise SIEM.
Raspberry Pi 5 Wazuh Mini SOC SIEM ARM64 Endpoint monitoring Small business
Read article →
Guide HARDENING
21 Sept 2026 · 18 min read · Intermediate
Design RouterOS around roles, zones and policy before the network becomes complicated. Add VLANs, VPNs, servers and additional WAN links later without rebuilding the security model.
MikroTik RouterOS 7 VLAN Firewall Network design Interface lists Router hardening Small business
Read article →
Guide HARDENING
21 Sept 2026 · 14 min read · Intermediate
Use 2026 evidence to plan the next security budget around identity, exposed systems, recovery, telemetry, suppliers and AI — before buying another dashboard.
Cybersecurity 2027 Security planning Identity Recovery Exposure management AI security Resilience Supply chain NIS2 Cyber Resilience Act
Read article →
Guide HARDENING
16 Sept 2026 · 20 min read · Intermediate
A practical Windows hardening guide for small businesses. Secure local administrators, Defender, BitLocker, RDP, firewall, LAPS, ASR rules, Office macros, updates and backups without building an enterprise security department.
Windows Windows 11 hardening cybersecurity small business Microsoft Defender LAPS BitLocker ASR sysadmin ransomware
Read article →
Critical VULNERABILITIES
16 Sept 2026 · 17 min read · Intermediate
CVE-2026-69730 is a critical Windows DNS Server remote code execution vulnerability rated CVSS 9.8. Learn what is affected, why domain controllers are at risk, how to check your servers, and why September's Windows updates also caused RDS problems.
CVE-2026-69730 Windows Server DNS Active Directory RCE Microsoft cybersecurity sysadmin Patch Tuesday
Read article →
Guide TOOLS
16 Sept 2026 · 31 min read · Intermediate
A practical cURL guide for system administrators. Test APIs, DNS, HTTPS, certificates, authentication, proxies, redirects, webhooks, downloads, performance and network connectivity directly from the command line.
curl sysadmin Linux Windows macOS networking HTTP HTTPS REST API troubleshooting DevOps cybersecurity
Read article →
Guide TOOLS
16 Sept 2026 · 22 min read · Intermediate
Learn what n8n is, how IT administrators and businesses can use it, practical automation examples, self-hosting basics, security risks, AI integration and real-world workflow ideas.
n8n automation sysadmin DevOps IT automation workflow automation self-hosted API cybersecurity AI automation
Read article →
Guide PLAYBOOKS
10 Sept 2026 · 15 min read · Intermediate
An administrative Windows password reset can restore sign-in while breaking access to DPAPI-protected secrets, EFS files and private keys. Learn how to identify the account type, preserve a working session, back up recovery material and prove the data still opens.
Windows DPAPI EFS Password Recovery Windows 11 Active Directory Microsoft Entra ID Windows Hello Sysadmin
Read article →
Critical VULNERABILITIES
9 Sept 2026 · 13 min read · Intermediate
Two exploited Windows privilege-escalation flaws entered CISA KEV while unauthenticated DNS and DHCP Server RCEs scored 9.8. Identify affected roles, verify builds, patch, contain exposure and hunt for pre-patch compromise.
Microsoft Patch Tuesday Windows Security CVE Zero-Day Windows Server DNS DHCP CISA KEV
Read article →
Guide LABS
8 Sept 2026 · 20 min read · Intermediate
A practical cross-platform guide to choosing and deploying VPNs on MikroTik RouterOS 7, with working site-to-site and road-warrior configurations.
MikroTik RouterOS VPN WireGuard IKEv2 OpenVPN
Read article →
Reference TOOLS
5 Sept 2026 · 21 min read · Intermediate
A blunt, evidence-led comparison of MikroTik and Cisco across price, licensing, security, performance, support and operational effort, with practical RouterOS and IOS XE audit commands.
MikroTik Cisco RouterOS IOS XE Network security Total cost of ownership
Read article →
Lab LABS
5 Sept 2026 · 23 min read · Intermediate
Clone Windows 11 safely with Rescuezilla, Clonezilla or Hasleo, prepare a bootable USB, size EFI and recovery partitions correctly, and recover a clone that will not boot.
Windows 11 Disk cloning SSD Rescuezilla Clonezilla BitLocker
Read article →
Guide HARDENING
5 Sept 2026 · 17 min read · Intermediate
Understand what a web application firewall does, when it is useful, where it fails, and how to deploy Cloudflare Free or OWASP CRS without locking out real users.
WAF Web application firewall OWASP CRS Cloudflare ModSecurity WordPress
Read article →
Guide HARDENING
5 Sept 2026 · 7 min read · Intermediate
Prevent injection with parameterised APIs, typed allowlists, shell-free design, contextual encoding, least privilege and deployment-level regression tests.
Data injection Secure coding Parameterised queries Input validation OWASP A05
Read article →
Guide PLAYBOOKS
5 Sept 2026 · 7 min read · Intermediate
Combine code review, safe staging tests, structured application events, web telemetry and endpoint evidence to find injection flaws and investigate attempted exploitation.
Data injection Detection engineering OWASP ZAP SAST Incident response
Read article →
High VULNERABILITIES
5 Sept 2026 · 7 min read · Intermediate
Concrete SQL, NoSQL, command, LDAP, template, log and CSV injection examples, each paired with safer code and a regression check.
Data injection SQL injection Command injection LDAP injection Secure coding
Read article →
High VULNERABILITIES
5 Sept 2026 · 7 min read · Intermediate
Follow an injection attack through decoding, string construction, interpretation and impact, including second-order injection and background-job trust boundaries.
Data injection Attack path Input validation CWE-74 Application security
Read article →
Reference VULNERABILITIES
5 Sept 2026 · 7 min read · Beginner
SQL injection is one member of a larger injection family. Compare interpreters, evidence, impact and the controls that actually fit SQL, shell, LDAP and NoSQL sinks.
Data injection SQL injection OWASP A05 CWE-74 Secure coding
Read article →
Reference VULNERABILITIES
5 Sept 2026 · 7 min read · Beginner
Data injection happens when untrusted data changes the meaning of a query, command, template or downstream protocol. Learn the trust boundary, common forms and first checks.
Data injection OWASP A05 Application security Secure coding CWE-74
Read article →
Lab TOOLS
5 Sept 2026 · 10 min read · Advanced
Build, convert and tune Sigma rules for SQL-injection strings, application validation failures and suspicious processes spawned by web servers.
Sigma Data injection Detection engineering SIEM Web security
Read article →
Medium VULNERABILITIES
4 Sept 2026 · 13 min read · Intermediate
An authenticated RouterOS API session may retain its old privileges after an account is downgraded. Here is how to find exposed services, terminate active sessions, restrict the API and verify the result.
MikroTik RouterOS CVE-2026-14227 API security Session management Network hardening Incident response
Read article →
High HARDENING
4 Sept 2026 · 22 min read · Intermediate
A problem-and-solution hardening runbook for Ubuntu Server, Debian and Rocky Linux: patching, SSH keys, firewalls, Fail2ban, AppArmor or SELinux, audit logs, file-integrity checks and proof that the result actually works.
Linux Server hardening Ubuntu Server Debian Rocky Linux SSH Fail2ban Firewall
Read article →
High VULNERABILITIES
4 Sept 2026 · 16 min read · Intermediate
A source-checked look at the unusually dense 2026 run of Microsoft Defender vulnerabilities, what the thirteen CVEs actually affect, and how to verify Windows, macOS and Linux endpoints rather than merely hoping automatic updates worked.
Microsoft Defender CVE Patch management Microsoft Defender for Endpoint Advanced Hunting Vulnerability management
Read article →
High VULNERABILITIES
3 Sept 2026 · 16 min read · Intermediate
CVE-2026-62832 lets a low-privileged local attacker abuse Windows User Profile Service and the venerable UsrClass.dat registry hive to reach another user's settings and turn them into privileged code execution.
Microsoft Windows CVE-2026-62832 LegacyHive Privilege escalation Windows Registry Incident response
Read article →
High INCIDENTS
18 Aug 2026 · 12 min read · Advanced
A first-hour response that revokes access, preserves cloud evidence, checks the persistence paths attackers commonly leave behind, and explains the recovery route when you cannot sign in.
Microsoft Graph PowerShell Exchange Online PowerShell
Read article →
High INCIDENTS
18 Aug 2026 · 16 min read · Intermediate
A practical fibre troubleshooting story: we investigated optical budgets, modules, speed and configuration before remembering that one transmitter must meet the other receiver.
RouterOS terminal
Read article →
High INCIDENTS
18 Aug 2026 · 17 min read · Intermediate
How a helpful OpenClaw assistant turned a WhatsApp contact list into shared authority over Gmail and the host—and how to rebuild it with real trust boundaries.
Built-in shell tools Shell ps, ss and login tools
Read article →
High INCIDENTS
18 Aug 2026 · 19 min read · Intermediate
What to do after running software of unknown origin: contain the computer, replace exposed sessions and secrets from a clean device, then decide whether to investigate or rebuild.
Built-in shell tools PowerShell and Windows Event Log ss or PowerShell
Read article →
Lab LABS
18 Aug 2026 · 21 min read · Intermediate
A practical perimeter check you can run today: find the correct public address, scan it from a genuinely external network, understand every result, fix exposure, and prove the change.
Nmap OWASP ZAP Baseline
Read article →
Reference TOOLS
18 Aug 2026 · 16 min read · Intermediate
Check your own public IP, on-premises mail server and WordPress site with safe commands, evidence-led interpretation and practical remediation.
Nmap dig OpenSSL s_client
Read article →
High VULNERABILITIES
18 Aug 2026 · 15 min read · Intermediate
The 15 newest CISA Known Exploited Vulnerabilities entries, with safe version checks, exposure evidence, practical remediation, incident triage and closure tests.
Vendor administration interfaces PowerShell Built-in shell tools
Read article →
High VULNERABILITIES
17 Aug 2026 · 9 min read · Intermediate
Access-control failures let authenticated or anonymous users read, change, or invoke resources outside their intended authority.
curl Express middleware Node test runner and Supertest
Read article →
Lab LABS
16 Aug 2026 · 8 min read · Intermediate
Create a small virtual environment with clear trust boundaries, snapshots, controlled internet access, and a written reset plan.
Docker
Read article →
Guide HARDENING
15 Aug 2026 · 8 min read · Advanced
Separate administration from daily work, require strong authentication, reduce standing privilege, and prepare monitored emergency access.
Microsoft Graph PowerShell
Read article →
Reference TOOLS
14 Aug 2026 · 8 min read · Intermediate
Use packet capture to explain endpoints, protocols, timing, and failures while respecting encryption and data sensitivity.
tshark Wireshark or tshark
Read article →
Guide PLAYBOOKS
13 Aug 2026 · 11 min read · Advanced
A role-based cloud identity response checklist from declaration through session revocation, evidence, persistence review, lockout recovery, and monitoring.
Microsoft Graph PowerShell Exchange Online PowerShell
Read article →
High INCIDENTS
12 Aug 2026 · 9 min read · Advanced
How to slow the damage, preserve options, and make recovery decisions without turning an outage into an evidence-destruction exercise.
find PowerShell SMB cmdlets restic
Read article →
High VULNERABILITIES
11 Aug 2026 · 8 min read · Intermediate
Misconfiguration turns powerful features, management interfaces, sample content, and verbose errors into avoidable attack paths.
Docker CLI RouterOS terminal curl
Read article →
Lab LABS
10 Aug 2026 · 8 min read · Beginner
Capture a small, authorised traffic sample and turn DNS, TCP, TLS, and timing into a defensible explanation.
tshark Wireshark or tshark
Read article →
Guide HARDENING
9 Aug 2026 · 8 min read · Intermediate
Reduce exposed authentication paths, require managed keys, limit privilege, and verify access before closing the existing session.
sshd OpenSSH SSH client
Read article →
Reference TOOLS
8 Aug 2026 · 8 min read · Intermediate
Use Nmap for asset and service discovery without turning an inventory task into an uncontrolled production test.
Nmap OWASP ZAP Baseline
Read article →
Guide PLAYBOOKS
7 Aug 2026 · 8 min read · Advanced
Coordinate business continuity, isolation, evidence, identity protection, external obligations, and clean recovery.
find PowerShell SMB cmdlets restic
Read article →
High INCIDENTS
6 Aug 2026 · 10 min read · Beginner
A proportionate response based on what the user entered, downloaded, approved, or executed—not panic based on the click alone.
grep Python standard library
Read article →
High VULNERABILITIES
5 Aug 2026 · 9 min read · Advanced
Dependencies, build systems, package registries, updates, and release credentials form a trust chain that attackers can target upstream.
Trivy
Read article →
Lab LABS
4 Aug 2026 · 8 min read · Advanced
Deploy a single-node learning environment, add one endpoint, verify log flow, and document the first useful alert.
Wazuh agent_control logger and Wazuh dashboard wazuh-logtest
Read article →
Guide HARDENING
3 Aug 2026 · 8 min read · Intermediate
Use Microsoft’s baseline as a starting point, stage changes, record exceptions, and test both security and business workflows.
Microsoft Defender PowerShell BitLocker PowerShell secedit
Read article →
Reference TOOLS
2 Aug 2026 · 8 min read · Advanced
Understand agent, server, indexer, and dashboard responsibilities before scaling collection or importing rules.
Wazuh agent_control logger and Wazuh dashboard wazuh-logtest
Read article →
Guide PLAYBOOKS
1 Aug 2026 · 9 min read · Intermediate
Triage the message, interaction, identity, endpoint, and recipient scope without detonating the lure or deleting the only evidence.
grep Python standard library
Read article →
High INCIDENTS
31 Jul 2026 · 9 min read · Advanced
Investigate consent abuse as an identity incident: permissions, users, tokens, app activity, and the path that convinced someone to approve it.
Microsoft Graph PowerShell
Read article →
High VULNERABILITIES
30 Jul 2026 · 9 min read · Intermediate
Cryptographic failures expose data because encryption, key management, transport protection, or algorithm choices do not match the threat.
OpenSSL Provider API client
Read article →
Lab LABS
29 Jul 2026 · 8 min read · Intermediate
Generate bounded failed logins against lab identities and build a detection that groups attempts by source, target count, and time.
Sigma Sigma CLI logger and central search
Read article →
Guide HARDENING
28 Jul 2026 · 8 min read · Intermediate
Protect the management plane, remove unnecessary services, constrain the firewall, and make configuration recovery routine.
RouterOS terminal
Read article →
Reference TOOLS
27 Jul 2026 · 8 min read · Intermediate
Write behaviour-focused rules with complete metadata, then validate field mapping and generated queries on the real target platform.
Sigma Sigma CLI PowerShell
Read article →
Guide PLAYBOOKS
26 Jul 2026 · 8 min read · Advanced
Capture the application and grant, disable access, find affected data and users, and prevent the same consent path from recurring.
Microsoft Graph PowerShell
Read article →
High INCIDENTS
25 Jul 2026 · 9 min read · Intermediate
Treat a failed restore as an incident, then separate media integrity, credentials, dependencies, capacity, and runbook failures.
restic
Read article →
High VULNERABILITIES
24 Jul 2026 · 9 min read · Intermediate
Injection occurs when untrusted data changes the meaning of a query, command, template, interpreter, or downstream protocol.
node-postgres Node.js child_process curl
Read article →
Lab LABS
23 Jul 2026 · 9 min read · Intermediate
Use a synthetic message to inspect headers, authentication results, URLs, and attachment metadata without contacting attacker infrastructure.
grep Python standard library
Read article →
Guide HARDENING
22 Jul 2026 · 8 min read · Intermediate
Reduce daemon authority, container privilege, mutable images, exposed sockets, and unbounded resources.
Docker CLI Docker Compose
Read article →
Reference TOOLS
21 Jul 2026 · 8 min read · Intermediate
Build rules from stable combinations of strings and structure, with a corpus that measures both misses and false positives.
YARA
Read article →
Guide PLAYBOOKS
20 Jul 2026 · 8 min read · Beginner
Use device state, encryption, data classification, identity, remote management, and legal requirements to choose proportionate action.
BitLocker PowerShell Microsoft Graph PowerShell PowerShell and Windows Event Log
Read article →
High INCIDENTS
19 Jul 2026 · 9 min read · Advanced
A careful triage path for suspicious processes, new persistence, unexpected network traffic, and altered accounts on a Linux host.
ps, ss and login tools journalctl and find dpkg or rpm
Read article →
High VULNERABILITIES
18 Jul 2026 · 9 min read · Intermediate
Insecure design describes missing or ineffective controls in the workflow itself, even when the implementation has no obvious coding bug.
Node.js fetch HTTP API Docker Compose
Read article →
Lab LABS
17 Jul 2026 · 8 min read · Beginner
Turn a specific behaviour and log source into a portable rule with metadata, test cases, and known false positives.
Sigma Sigma CLI PowerShell
Read article →
Guide HARDENING
16 Jul 2026 · 8 min read · Advanced
Inventory enterprise applications, permission grants, credentials, owners, and real use before removing stale or excessive access.
Microsoft Graph PowerShell
Read article →
Reference TOOLS
15 Jul 2026 · 8 min read · Advanced
Use artefacts and VQL collections to answer scoped forensic questions while preserving provenance and limiting unnecessary data.
Velociraptor VQL
Read article →
Guide PLAYBOOKS
14 Jul 2026 · 8 min read · Intermediate
Replace and revoke the secret, but also establish exposure time, permissions, use, copies, dependencies, and newly created persistence.
Git Shell Provider API client
Read article →
High INCIDENTS
13 Jul 2026 · 9 min read · Intermediate
Decide quickly using encryption, device state, cached credentials, data sensitivity, remote actions, and identity evidence.
BitLocker PowerShell Microsoft Graph PowerShell PowerShell and Windows Event Log
Read article →
High VULNERABILITIES
12 Jul 2026 · 9 min read · Intermediate
Authentication failures include weak recovery, session handling, automated attack resistance, and MFA choices—not only password policy.
curl Application logger Microsoft Graph PowerShell
Read article →
Lab LABS
11 Jul 2026 · 8 min read · Beginner
Create a narrow file-identification rule from synthetic samples, then test for false positives and brittle strings.
YARA
Read article →
Guide HARDENING
10 Jul 2026 · 8 min read · Advanced
Separate backup identity and infrastructure, keep immutable or offline copies, and prove recovery with measured exercises.
restic
Read article →
Reference TOOLS
9 Jul 2026 · 8 min read · Intermediate
Use SQL-like queries for inventory and state while respecting table cost, platform differences, scheduling, and result interpretation.
osqueryi
Read article →
Guide PLAYBOOKS
8 Jul 2026 · 8 min read · Advanced
Protect availability while preserving web, identity, process, file, network, deployment, and cloud evidence.
ps, ss and login tools journalctl and find curl
Read article →
High INCIDENTS
7 Jul 2026 · 9 min read · Intermediate
Rotate the secret, but first understand where it appeared, what it could do, how it was used, and what automation depends on it.
Git Shell Provider API client
Read article →
High VULNERABILITIES
6 Jul 2026 · 9 min read · Intermediate
Integrity failures arise when applications trust updates, serialised data, cached objects, plugins, or workflow messages without verifying origin and authorised change.
Trivy YARA Git
Read article →
Lab LABS
5 Jul 2026 · 9 min read · Intermediate
Scan a tiny lab subnet, compare discovered services with the expected inventory, and document ownership before assessing risk.
Nmap OWASP ZAP Baseline
Read article →
Guide HARDENING
4 Jul 2026 · 8 min read · Beginner
Harden registrar identity, transfer controls, DNS changes, mail records, certificate policy, and recovery contacts.
dig OpenSSL
Read article →
Reference TOOLS
3 Jul 2026 · 8 min read · Intermediate
Configure focused Windows event generation, forward it reliably, and tie each event class to an investigation or detection need.
Sysmon PowerShell wevtutil
Read article →
Guide PLAYBOOKS
2 Jul 2026 · 8 min read · Intermediate
Separate malicious traffic, flash demand, dependency failure, and capacity exhaustion while keeping communication and evidence intact.
ss or PowerShell logger and central search Node.js fetch
Read article →
High INCIDENTS
1 Jul 2026 · 9 min read · Advanced
Coordinate identity response, payment interruption, bank contact, evidence preservation, and business communications when an invoice is manipulated.
Microsoft Graph PowerShell Exchange Online PowerShell grep
Read article →
High VULNERABILITIES
30 Jun 2026 · 9 min read · Intermediate
Security logging fails when important events are absent, ambiguous, delayed, unprotected, or impossible to turn into a timely decision.
Application logger logger and central search journalctl
Read article →
Lab LABS
29 Jun 2026 · 8 min read · Advanced
Collect a small, documented set of endpoint artefacts from a disposable Windows VM and preserve provenance for review.
Velociraptor VQL
Read article →
Guide HARDENING
28 Jun 2026 · 8 min read · Intermediate
Set safe transport and browser policies, but verify application compatibility and avoid treating headers as a substitute for secure code.
curl OpenSSL OWASP ZAP Baseline
Read article →
Reference TOOLS
27 Jun 2026 · 8 min read · Beginner
Use deterministic recipes for decoding, hashing, extraction, and comparison while avoiding accidental data disclosure.
CyberChef
Read article →
Guide PLAYBOOKS
26 Jun 2026 · 8 min read · Advanced
Coordinate legal, HR, privacy, identity, endpoint, and data evidence without tipping off the subject or exceeding authorised monitoring.
Built-in shell tools Application logger osqueryi
Read article →
High INCIDENTS
25 Jun 2026 · 9 min read · Intermediate
Recover registrar control, stabilise authoritative DNS, protect email, and determine whether the change enabled credential or certificate abuse.
dig OpenSSL
Read article →
High VULNERABILITIES
24 Jun 2026 · 9 min read · Advanced
Systems become insecure when errors, resource exhaustion, partial failure, or unexpected state bypasses controls or leaves data inconsistent.
Node.js fetch HTTP API Docker Compose
Read article →
Lab LABS
23 Jun 2026 · 8 min read · Intermediate
Measure recovery point, recovery time, dependencies, and data integrity by restoring a synthetic service into an isolated environment.
restic
Read article →
Guide HARDENING
22 Jun 2026 · 8 min read · Intermediate
Collect the events responders need, protect the pipeline, and assign alerts before expanding volume.
Application logger logger and central search journalctl
Read article →
Reference TOOLS
21 Jun 2026 · 8 min read · Intermediate
Scan images, filesystems, configuration, and dependencies with scope and policy, then connect findings to deployed exposure and an owner.
Trivy
Read article →
Guide PLAYBOOKS
20 Jun 2026 · 8 min read · Intermediate
Turn a supplier notification into an inventory, access, data, continuity, and evidence response for your own organisation.
Trivy Git
Read article →