Lab 21: I Finally Closed the Detection Gap
Eight labs ago, I ran a brute force attack against my own system and watched zero alerts fire. I knew the attack happened. The logs confirmed it. But the SIEM never saw it — because the logs that matt

Search for a command to run...
Articles tagged with #elastic
Eight labs ago, I ran a brute force attack against my own system and watched zero alerts fire. I knew the attack happened. The logs confirmed it. But the SIEM never saw it — because the logs that matt

In Lab 12, I built the detection rules. Three prebuilt Elastic rules targeting Linux attack techniques. One custom KQL rule for SSH authentication failures. The pipeline was configured, the rules were

Lab 11 got the pipeline running. Logs were flowing from my Kali Linux host into Elastic SIEM. The agent was enrolled. The data was real. But a SIEM that ingests logs and does nothing with them is just

I'd been reading about SIEM tools for months before I actually touched one. SIEM — Security Information and Event Management — shows up in almost every SOC job description. It's the platform analysts
