A messy brain dump of projects, hacks, and other notes.

Come along while I debug life one typo at a time.

half-baked security

Recent Posts

Deploying Microsoft ASR Rules Without Breaking Your Environment: A Practical Engineer’s Approach

Deploying Microsoft Attack Surface Reduction (ASR) rules requires careful execution to avoid disrupting business processes. Begin in Audit mode to...

Temporarily Disable Defender for Endpoint

Sometimes I am presented with scenarios where I have to assist different IT team members with performance issues on servers and workstations. In most...

Ingest Palo Alto FW Logs into Microsoft Sentinel SIEM

Recently I’ve had to switch the Palo Alto connector in Microsoft Sentinel from Palo Alto Networks (Firewall) via Legacy Agent to Palo Alto...

How to Stop Alert Fatigue in Microsoft Sentinel

As Security Engineers and SOC Analysts, one of our main pain points is the sheer amount of false positive incidents and alerts that we have to sift...

Defender for Office 365 – Allow Phishing Simulation Emails

Throughout the years working in Cybersecurity I’ve dealt directly or indirectly with Security Awareness Training programs multiple times. One of...

Microsoft Sentinel IOC Integration – BlueVoyant Threat Intel Setup

BlueVoyant is a Cybersecurity firm offering different products and solutions including: Managed Detection and Response, Third-party Risk Management...

Breach & Attack Simulation Setup – Caldera and Vectr Integration

Tools: Adversary Emulation Platform: Caldera: https://caldera.mitre.org/ Reporting Platform: Vectr: https://vectr.io/ Philosophy Full-stack vs Assumed...

DriftingBlue6 Walkthrough – OffSec Proving Grounds Play Machine

After running a port scan on the IP, I investigated the open ports individually and found the following: Port 80: HTTP Textpattern CMS. Found a few...

ClamAV Walkthrough – Offsec Proving Grounds Practice Machine

This is one of the shortest boxes I came across on PGP. After running a quick NMAP scan, I inspected the open ports as follows: MSB Port 139 Port 199...