THE SAFEHOUSE / JOURNAL
THE SAFEHOUSE JOURNAL

Cybersecurity, explained clearly.

Writing on SOC operations, identity security, threat detection, and everyday digital safety — for security teams and everyday people alike.

1 August 2026· 1 min read

Welcome to The Safehouse Journal

Why this blog exists, what you'll find here, and what's coming next as we bring over the full back-catalog of SOC, identity, and awareness writing.

AnnouncementSOC
2 June 2026· 4 min read

📡 Telemetry That Works for You: Building Custom NXLog Pipelines Step-by-Step 📡

A step-by-step walkthrough of building a structured NXLog telemetry pipeline — input, processing, enrichment, filtering, and secure routing to your SIEM.

NXLogTelemetryPipelineSIEM
3 March 2026· 2 min read

March: Secure Remote Work & VPN Safety — Protecting Access from Anywhere

Remote work is permanent, and so is the expanded attack surface it creates. Practical controls for securing VPN access, home networks, and remote endpoints.

Cyber Awareness CalendarVPNRemote WorkZero Trust
25 February 2026· 2 min readMITRE ATT&CK Cyber Incident Matrix — Part 2

MITRE ATT&CK Cyber Incident Matrix (2026) — Part 2: Initial Access & Execution

How attackers break in and take control — the most common Initial Access techniques mapped to MITRE ATT&CK, and why these earliest stages of an attack matter most for detection.

MITRE ATT&CKCybersecuritySOCIncident Response
19 February 2026· 2 min readMITRE ATT&CK Cyber Incident Matrix — Part 1

MITRE ATT&CK Cyber Incident Matrix (2026) — Part 1: Understanding the Cyber Attack Landscape

An introduction to the MITRE ATT&CK framework — what it is, why it matters, and how its tactics and techniques give SOC teams a shared language for understanding modern, multi-stage cyberattacks.

MITRE ATT&CKCybersecuritySOCThreat Intelligence
17 February 2026· 3 min read

Installing & Configuring NXLog Agents: A Complete Guide to Service Setup

A complete, practical guide to installing and configuring NXLog agents as a service, end to end.

NXLogSetupWindows Server
27 December 2025· 3 min read

Aligning OSI Layer Attacks with MITRE ATT&CK & SOC Use Cases

Turning theory into actionable detection and response — mapping each OSI layer to its MITRE ATT&CK techniques and the concrete SOC use cases and actions analysts should take at each layer.

MITRE ATT&CKSOCOSI ModelDetection Engineering
23 November 2025· 4 min read

🚀 Supercharge Your FortiGate: Proactive Defence with Q-Feeds Threat Intelligence 🚀

Moving FortiGate from reactive to proactive defense using Q-Feeds threat intelligence integration.

FortiGateThreat IntelligenceQ-Feeds
27 October 2025· 5 min read

Cyber Awareness Month Special: Why Security Is Everyone's Responsibility

October reflection: a holistic view of security operations design — from threat intelligence and firewall defense to SOC operations, zero trust, and the case for shared accountability.

Cyber Awareness CalendarSOCZero TrustThreat Intelligence
16 August 2025· 2 min read

🔍 From Open Source Roots to Enterprise-Grade Power

NXLog's journey from a lean open-source project to an enterprise-grade log management platform.

NXLogOpen Source
6 July 2025· 2 min read

From Chaos 🌀 to Clarity ✨: Build Your First Smart Log Pipeline with NXLog

Hybrid infrastructure makes log collection non-negotiable — a guide to building your first smart pipeline with NXLog.

NXLogPipelineTelemetry
1 June 2025· 3 min read

Inside the Cyber Fortress: Mastering Security Operations

A tour of the ten pillars of modern Security Operations — SOC, SIEM, SOAR, EDR/XDR, threat hunting, incident response, digital forensics, vulnerability management, threat intelligence, and red/blue/purple team exercises.

SOCSIEMSOARIncident ResponseCybersecurity
12 May 2025· 2 min readIdentity Management — Part 7

Auditing & Monitoring Identities in Real Time: Alerting, Logging and Response

Closing out the Identity Management series — auditing and real-time monitoring across Windows Server, Azure AD, and Linux, and why it's a non-negotiable layer of identity security.

CybersecurityWindows ServerLinuxAuditing
11 May 2025· 3 min readIdentity Management — Part 6

Identity Lifecycle Management: Automating Access from Hire to Exit

The sixth post in the Identity Management series — automating onboarding, movement, and offboarding across Windows Server, Azure AD, and Linux.

Identity Lifecycle ManagementWindows ServerLinuxCybersecurity
8 May 2025· 3 min readIdentity Management — Part 5

Directory Services: The Core of Identity on Windows, Linux & Azure AD

The fifth post in the Identity Management series — how directory services work across Windows AD DS, Linux (OpenLDAP/SSSD), and Azure AD, with practical setup and best practices.

Directory ServicesWindows ServerLinuxActive Directory
6 May 2025· 3 min readIdentity Management — Part 4

Privileged Access Management (PAM): Locking Down the Keys to the Kingdom

The fourth post in the Identity Management series — controlling, monitoring, and auditing elevated-rights accounts across Windows Server, Linux, and Azure AD.

PAMPrivileged AccessLinuxWindows Server
4 May 2025· 2 min readIdentity Management — Part 3

Multi-Factor Authentication (MFA): Your Critical Second Layer of Defense

The third post in the Identity Management series — MFA options and setup across Windows Server, Linux, and Azure AD, plus real-world use cases and troubleshooting.

MFALinuxWindows Server
2 May 2025· 2 min readrsyslog for SIEM Integration — Part 2

Part 2: Configuring /etc/rsyslog.conf for SIEM Integration

The hands-on half — configuring /etc/rsyslog.conf step by step to feed a SIEM correctly.

LinuxrsyslogSIEM
2 May 2025· 2 min readIdentity Management — Part 2

Single Sign-On (SSO): One Login to Rule Them All

The second post in the Identity Management series — how SSO works across Windows Server (ADFS), Linux (SAML/OIDC), and Azure AD, with setup guidance for each.

LinuxWindows ServerSSOActive Directory
1 May 2025· 2 min readrsyslog for SIEM Integration — Part 1

Part 1: Understanding /etc/rsyslog.conf and Its Importance in Linux Logging

Why /etc/rsyslog.conf matters for Linux log management, and what every system administrator should understand about it.

LinuxrsyslogSIEM
30 April 2025· 4 min readNXLog Deep Dive — Part 5

Blog Part 5: NXLog in Action: Use Cases for Cybersecurity and Audit Compliance

Real-world NXLog use cases across cybersecurity monitoring and audit compliance — closing out the five-part series.

NXLogComplianceAudit
30 April 2025· 3 min read

Identity Management in 2025: A Strategic Pillar for Cybersecurity

An overview of Identity Management's core components — IAM, SSO, MFA, PAM, Federation, Governance, JIT access, and Lifecycle Management — as the identity layer becomes the new security perimeter.

Identity ManagementIAMCISOCybersecurity
30 April 2025· 2 min readIdentity Management — Part 1

Mastering Identity and Access Management (IAM) on Windows Server, Linux and Azure AD

Welcome to the first blog in the Identity Management series — IAM fundamentals across Windows Server, Linux, and Azure AD, with practical tools and time-saving tips.

IAMLinuxWindows ServerIdentity Management
30 April 2025· 2 min read

Cybersecurity is a Team Sport: Let’s Stop Overlooking Key Players

Cybersecurity isn't just SOC analysts and VAPT professionals — a look at the overlooked roles that make security programs actually work.

CybersecurityTeam CultureSOC
29 April 2025· 4 min readNXLog Deep Dive — Part 4

Blog Part 4: Troubleshooting NXLog: Top Errors and How to Fix Them

The most common NXLog errors in production, what causes them, and exactly how to fix each one.

NXLogTroubleshooting
28 April 2025· 4 min readNXLog Deep Dive — Part 3

Blog Part 3: How to Fine-Tune NXLog for Windows Server for Cybersecurity Success

Practical tuning steps to get NXLog performing reliably on Windows Server — from filtering noise to optimizing throughput.

NXLogWindows ServerPerformance Tuning
27 April 2025· 4 min readNXLog Deep Dive — Part 2

Blog Part 2: NXLog vs Syslog-ng vs Winlogbeat vs Snare — Which Log Collector Wins?

A side-by-side comparison of NXLog against Syslog-ng, Winlogbeat, and Snare — strengths, weaknesses, and where each one wins.

NXLogSyslog-ngWinlogbeatLog Management
26 April 2025· 3 min readNXLog Deep Dive — Part 1

Blog Part 1: Introduction to NXLog — The Unsung Hero for Windows Server Log Management

What NXLog is, why it matters for Windows Server environments, and a first look at a sample .conf file — the start of a five-part series.

NXLogWindows ServerLog Management