Writing on SOC operations, identity security, threat detection, and everyday digital safety — for security teams and everyday people alike.
Why this blog exists, what you'll find here, and what's coming next as we bring over the full back-catalog of SOC, identity, and awareness writing.
A step-by-step walkthrough of building a structured NXLog telemetry pipeline — input, processing, enrichment, filtering, and secure routing to your SIEM.
Remote work is permanent, and so is the expanded attack surface it creates. Practical controls for securing VPN access, home networks, and remote endpoints.
How attackers break in and take control — the most common Initial Access techniques mapped to MITRE ATT&CK, and why these earliest stages of an attack matter most for detection.
An introduction to the MITRE ATT&CK framework — what it is, why it matters, and how its tactics and techniques give SOC teams a shared language for understanding modern, multi-stage cyberattacks.
A complete, practical guide to installing and configuring NXLog agents as a service, end to end.
Turning theory into actionable detection and response — mapping each OSI layer to its MITRE ATT&CK techniques and the concrete SOC use cases and actions analysts should take at each layer.
Moving FortiGate from reactive to proactive defense using Q-Feeds threat intelligence integration.
October reflection: a holistic view of security operations design — from threat intelligence and firewall defense to SOC operations, zero trust, and the case for shared accountability.
NXLog's journey from a lean open-source project to an enterprise-grade log management platform.
Hybrid infrastructure makes log collection non-negotiable — a guide to building your first smart pipeline with NXLog.
A tour of the ten pillars of modern Security Operations — SOC, SIEM, SOAR, EDR/XDR, threat hunting, incident response, digital forensics, vulnerability management, threat intelligence, and red/blue/purple team exercises.
Closing out the Identity Management series — auditing and real-time monitoring across Windows Server, Azure AD, and Linux, and why it's a non-negotiable layer of identity security.
The sixth post in the Identity Management series — automating onboarding, movement, and offboarding across Windows Server, Azure AD, and Linux.
The fifth post in the Identity Management series — how directory services work across Windows AD DS, Linux (OpenLDAP/SSSD), and Azure AD, with practical setup and best practices.
The fourth post in the Identity Management series — controlling, monitoring, and auditing elevated-rights accounts across Windows Server, Linux, and Azure AD.
The third post in the Identity Management series — MFA options and setup across Windows Server, Linux, and Azure AD, plus real-world use cases and troubleshooting.
The hands-on half — configuring /etc/rsyslog.conf step by step to feed a SIEM correctly.
The second post in the Identity Management series — how SSO works across Windows Server (ADFS), Linux (SAML/OIDC), and Azure AD, with setup guidance for each.
Why /etc/rsyslog.conf matters for Linux log management, and what every system administrator should understand about it.
Real-world NXLog use cases across cybersecurity monitoring and audit compliance — closing out the five-part series.
An overview of Identity Management's core components — IAM, SSO, MFA, PAM, Federation, Governance, JIT access, and Lifecycle Management — as the identity layer becomes the new security perimeter.
Welcome to the first blog in the Identity Management series — IAM fundamentals across Windows Server, Linux, and Azure AD, with practical tools and time-saving tips.
Cybersecurity isn't just SOC analysts and VAPT professionals — a look at the overlooked roles that make security programs actually work.
The most common NXLog errors in production, what causes them, and exactly how to fix each one.
Practical tuning steps to get NXLog performing reliably on Windows Server — from filtering noise to optimizing throughput.
A side-by-side comparison of NXLog against Syslog-ng, Winlogbeat, and Snare — strengths, weaknesses, and where each one wins.
What NXLog is, why it matters for Windows Server environments, and a first look at a sample .conf file — the start of a five-part series.