Forwarded from UNDERCODE TESTING
๐ฆ๐๐ฎ๐ข๐ฅ๐๐ข๐ง๐ ๐๐๐ ๐๐จ๐ฆ๐ ๐๐๐ :
A Security Operations Center (SOC) is vital for any organization. In this project, I designed and deployed a fully functional SOC home lab using open-source tools: Wazuh, ELK Stack, TheHive, and Cortex.
๐๐๐ฃ๐๐๐ญ๐ข๐ฏ๐๐ฌ :
Ensure proactive monitoring and efficient incident management.
Simulate attack scenarios to test detection and response capabilities.
๐๐ก๐ ๐๐จ๐ซ๐ค๐๐ฅ๐จ๐ฐ :
Wazuh Agents: Collect security data from various systems (Linux and Windows) and send it to the Wazuh Manager.
Wazuh (SIEM): Transfers data via Filebeat to Elasticsearch for storage and analysis.
Kibana: Visualizes data through dashboards with the Wazuh plugin for real-time monitoring.
TheHive (Incident Management Platform): Manages incidents using data from the Wazuh Manager.
Cortex (Automated Analysis Engine): Automates analyses and integrates with VirusTotal for suspicious file evaluation.
SOC Analyst: Utilizes these tools collectively to monitor systems, analyze incidents, and respond effectively to security threats.
๐๐๐ฌ๐ญ๐ข๐ง๐ ๐๐ง๐ ๐๐๐ฌ๐ฎ๐ฅ๐ญ๐ฌ :
To validate the lab's performance, I executed multiple attack scenarios to ensure the tools could detect, analyze, and respond effectively. Example scenarios include:
+ Malware detection: Identifying malicious files and responding appropriately.
+ SQL injection attack detection: Detecting and mitigating database attack attempts.
Thank you Mohamed Benkhirat for you nice content.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
A Security Operations Center (SOC) is vital for any organization. In this project, I designed and deployed a fully functional SOC home lab using open-source tools: Wazuh, ELK Stack, TheHive, and Cortex.
๐๐๐ฃ๐๐๐ญ๐ข๐ฏ๐๐ฌ :
Ensure proactive monitoring and efficient incident management.
Simulate attack scenarios to test detection and response capabilities.
๐๐ก๐ ๐๐จ๐ซ๐ค๐๐ฅ๐จ๐ฐ :
Wazuh Agents: Collect security data from various systems (Linux and Windows) and send it to the Wazuh Manager.
Wazuh (SIEM): Transfers data via Filebeat to Elasticsearch for storage and analysis.
Kibana: Visualizes data through dashboards with the Wazuh plugin for real-time monitoring.
TheHive (Incident Management Platform): Manages incidents using data from the Wazuh Manager.
Cortex (Automated Analysis Engine): Automates analyses and integrates with VirusTotal for suspicious file evaluation.
SOC Analyst: Utilizes these tools collectively to monitor systems, analyze incidents, and respond effectively to security threats.
๐๐๐ฌ๐ญ๐ข๐ง๐ ๐๐ง๐ ๐๐๐ฌ๐ฎ๐ฅ๐ญ๐ฌ :
To validate the lab's performance, I executed multiple attack scenarios to ensure the tools could detect, analyze, and respond effectively. Example scenarios include:
+ Malware detection: Identifying malicious files and responding appropriately.
+ SQL injection attack detection: Detecting and mitigating database attack attempts.
Thank you Mohamed Benkhirat for you nice content.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Cactus #Ransomware Targets awimccom
https://undercodenews.com/cactus-ransomware-targets-awimccom/
@Undercode_News
https://undercodenews.com/cactus-ransomware-targets-awimccom/
@Undercode_News
UNDERCODE NEWS
Cactus Ransomware Targets awimccom - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ Lockbit3 #Ransomware Targets Marmon-Herrington
https://undercodenews.com/lockbit3-ransomware-targets-marmon-herrington/
@Undercode_News
https://undercodenews.com/lockbit3-ransomware-targets-marmon-herrington/
@Undercode_News
UNDERCODE NEWS
Lockbit3 Ransomware Targets Marmon-Herrington - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from DailyCVE
๐ Solana SPL Token Swap, Unsound Usages of Type Casting (Moderate)
https://dailycve.com/solana-spl-token-swap-unsound-usages-of-type-casting-moderate/
@DailyCVE
https://dailycve.com/solana-spl-token-swap-unsound-usages-of-type-casting-moderate/
@DailyCVE
DailyCVE
Solana SPL Token Swap, Unsound Usages of Type Casting (Moderate) - DailyCVE
2024-12-23 : This advisory highlights an issue with the Solana SPL Token Swap libraryโs usage of `u8` type casting. While [โฆ]
Forwarded from DailyCVE
๐ KVM, Undefined Behavior, #CVE-2024-XXX (Moderate)
https://dailycve.com/kvm-undefined-behavior-cve-2024-xxx-moderate/
@Daily_CVE
https://dailycve.com/kvm-undefined-behavior-cve-2024-xxx-moderate/
@Daily_CVE
DailyCVE
KVM, Undefined Behavior, CVE-2024-XXX (Moderate) - DailyCVE
2024-12-23 : This advisory describes an undefined behavior vulnerability in the `kvm_ioctls` crate. The `VmFd::create_device` function incorrectly downcasts a mutable [โฆ]
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
A Wave of Strikes: #Amazon, Starbucks, and the Fight for Union Recognition
https://undercodenews.com/a-wave-of-strikes-amazon-starbucks-and-the-fight-for-union-recognition/
@Undercode_News
https://undercodenews.com/a-wave-of-strikes-amazon-starbucks-and-the-fight-for-union-recognition/
@Undercode_News
UNDERCODE NEWS
A Wave of Strikes: Amazon, Starbucks, and the Fight for Union Recognition - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Ultramarine #Linux 40: A Refined and Elegant #Fedora Spin
https://undercodenews.com/ultramarine-linux-40-a-refined-and-elegant-fedora-spin/
@Undercode_News
https://undercodenews.com/ultramarine-linux-40-a-refined-and-elegant-fedora-spin/
@Undercode_News
UNDERCODE NEWS
Ultramarine Linux 40: A Refined and Elegant Fedora Spin - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Full Speed Ahead: Self-Driving Cars Poised for Explosive Growth Under Trump
https://undercodenews.com/full-speed-ahead-self-driving-cars-poised-for-explosive-growth-under-trump/
@Undercode_News
https://undercodenews.com/full-speed-ahead-self-driving-cars-poised-for-explosive-growth-under-trump/
@Undercode_News
UNDERCODE NEWS
Full Speed Ahead: Self-Driving Cars Poised for Explosive Growth Under Trump - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
#Ransomware Group Ransomhub Targets Semfincom
https://undercodenews.com/ransomware-group-ransomhub-targets-semfincom/
@Undercode_News
https://undercodenews.com/ransomware-group-ransomhub-targets-semfincom/
@Undercode_News
UNDERCODE NEWS
Ransomware Group Ransomhub Targets Semfincom - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ง Spread Holiday Cheer with a Personalized Video Message from Santa
https://undercodenews.com/spread-holiday-cheer-with-a-personalized-video-message-from-santa/
@Undercode_News
https://undercodenews.com/spread-holiday-cheer-with-a-personalized-video-message-from-santa/
@Undercode_News
UNDERCODE NEWS
Spread Holiday Cheer with a Personalized Video Message from Santa - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Ray-Ban Meta Smart Glasses: A Glimpse into the Future of AR
https://undercodenews.com/ray-ban-meta-smart-glasses-a-glimpse-into-the-future-of-ar/
@Undercode_News
https://undercodenews.com/ray-ban-meta-smart-glasses-a-glimpse-into-the-future-of-ar/
@Undercode_News
UNDERCODE NEWS
Ray-Ban Meta Smart Glasses: A Glimpse into the Future of AR - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from DailyCVE
๐ต Sure, here is the article rewritten without code and summarized:
https://dailycve.com/sure-here-is-the-article-rewritten-without-code-and-summarized/
@Daily_CVE
https://dailycve.com/sure-here-is-the-article-rewritten-without-code-and-summarized/
@Daily_CVE
DailyCVE
Sure, here is the article rewritten without code and summarized: - DailyCVE
2024-12-23 WildFly Management Console Cross-Site Scripting Vulnerability An attacker can potentially execute a malicious script in the WildFly management console, [โฆ]
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ฑ #Copilot Gets a Native App on #Windows 11: A Closer Look
https://undercodenews.com/copilot-gets-a-native-app-on-windows-11-a-closer-look/
@Undercode_News
https://undercodenews.com/copilot-gets-a-native-app-on-windows-11-a-closer-look/
@Undercode_News
UNDERCODE NEWS
Copilot Gets a Native App on Windows 11: A Closer Look - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from DailyCVE
๐ด Apache Hive, Spark: CookieSigner Exposes Correct Signature on Verification Failure (High)
https://dailycve.com/apache-hive-spark-cookiesigner-exposes-correct-signature-on-verification-failure-high/
@Daily_CVE
https://dailycve.com/apache-hive-spark-cookiesigner-exposes-correct-signature-on-verification-failure-high/
@Daily_CVE
DailyCVE
Apache Hive, Spark: CookieSigner Exposes Correct Signature on Verification Failure (High) - DailyCVE
2024-12-23 : This article describes a high-severity vulnerability in Apache Hive and Spark. When verifying cookie signatures, the CookieSigner component [โฆ]
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ฅ๏ธ The Rise of Non-Human Identities: Managing the Explosion of Machine Identities in the Enterprise
https://undercodenews.com/the-rise-of-non-human-identities-managing-the-explosion-of-machine-identities-in-the-enterprise/
@Undercode_News
https://undercodenews.com/the-rise-of-non-human-identities-managing-the-explosion-of-machine-identities-in-the-enterprise/
@Undercode_News
UNDERCODE NEWS
The Rise of Non-Human Identities: Managing the Explosion of Machine Identities in the Enterprise - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ The Sunset of Truth: State Department's Disinformation Center Shuttered
https://undercodenews.com/the-sunset-of-truth-state-departments-disinformation-center-shuttered/
@Undercode_News
https://undercodenews.com/the-sunset-of-truth-state-departments-disinformation-center-shuttered/
@Undercode_News
UNDERCODE NEWS
The Sunset of Truth: State Department's Disinformation Center Shuttered - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ