Skip to content
-
Security You Can Trust, Expertise You Can Rely On. TekGenX Consulting
NetwerkLABS

Powered By TEKGENX CONSULTING

  • ATTACK
    • PenTest
    • Web Pentest
    • C2 Frameworks
    • VulnLAB
  • DETECT
    • Detection Engineering
    • EDR | SIEM | SOAR
    • Purple Teaming
    • MITRE ATT&CK
  • DEFEND
    • CTEM
    • Attack Surface Management (ASM)
    • Network Infrastructure
    • Vulnerability Management
    • WAF | Firewalls | IDS/IPS
  • LEARNING PATHS
    • Wazuh SIEM & XDR
    • Attack & Defend AD
    • Cheat Sheets
  • GRC
    • ISO/IEC 27001
    • NIS2 | CyFUN
    • NIST
    • CIS Controls
  • CTI
    • Threat Intel
    • CyBER-NEWS
Subscribe

DETECT

  • Home
  • DETECT
Importing the Wazuh 5.0 Beta OVA into Proxmox
Posted inDETECT EDR | SIEM | SOAR LEARNING PATHS

Importing the Wazuh 5.0 Beta OVA into Proxmox

Wazuh 5.0 is currently in beta, and the project also ships it as a ready-to-run OVA appliance. That's convenient if you just want to kick the tyres on the new release, but Proxmox doesn't import OVAs…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: SIEM, wazuh, EDR, XDR
Exploring Wazuh: Introduction
Posted inLEARNING PATHS Wazuh SIEM & XDR DETECT

Exploring Wazuh: Introduction

Introduction The Wazuh Agent At the heart of every monitored endpoint sits the Wazuh agent — a lightweight, cross-platform component that acts as your eyes and ears on the systems you care about. Once deployed, it…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: wazuh
Wireshark Threat Hunting – From Packets to Indicators [HTTP: DEEP-DIVE]
Posted inSOC Analyst Threat Detection and Incident Response Traffic Analysis

Wireshark Threat Hunting – From Packets to Indicators [HTTP: DEEP-DIVE]

HTTP/HTTP2 Deep-Dive — Wireshark DFIR // HTTP / HTTP2 — Deep-Dive Filter Reference Granular Wireshark display filters for HTTP/1.1 and HTTP/2 — request methods, path & file access, credential extraction, brute force detection, SQL injection, XSS,…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: wireshark
Wireshark Threat Hunting – From Packets to Indicators [SMB: DEEP-DIVE]
Posted inDFIR SOC Analyst Threat Detection and Incident Response

Wireshark Threat Hunting – From Packets to Indicators [SMB: DEEP-DIVE]

SMB & Windows Auth Deep-Dive — Wireshark DFIR // SMB & Windows Auth — Deep-Dive Filter Reference Granular Wireshark display filters for SMB2 file & share access (paths, users, operations, error codes), NTLM authentication flow, Kerberos…
Read More
Posted by Avatar photo Bharath Narayanasamy
Wireshark Threat Hunting – From Packets to Indicators
Posted inSOC Analyst Threat Detection and Incident Response Traffic Analysis

Wireshark Threat Hunting – From Packets to Indicators

Wireshark DFIR Cheat Sheet // Wireshark DFIR Cheat Sheet Display filters, detection techniques, traffic analysis workflows, and TShark CLI commands for Digital Forensics & Incident Response. Filters are mapped to MITRE ATT&CK where applicable. Wireshark 4.x…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: wireshark
SIEM: Onboarding WIndows Servers
Posted inIntrusion Detection and Response DETECT MITRE ATT&CK

SIEM: Onboarding WIndows Servers

When integrating Windows servers into your Security Information and Event Management (SIEM) platform, selecting the right log sources is crucial for effective threat detection while maintaining optimal system performance. This comprehensive guide outlines the essential Windows…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: SIEM, Windows
Hunting the hunters: DFIR with Velociraptor (PART-II)
Posted inDFIR

Hunting the hunters: DFIR with Velociraptor (PART-II)

We covered the deployment of Velociraptor Server and Client components in the first part of this series. You can read it here if you're interested. This part of the series will walk you through the capabilities…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: dfir, Velociraptor, threat_detection
Hunting the hunters: DFIR with Velociraptor (PART-I)
Posted inDFIR

Hunting the hunters: DFIR with Velociraptor (PART-I)

Introduction In the ever-evolving world of Digital Forensics and Incident Response (DFIR), having a powerful tool at your disposal is essential. Velociraptor stands out as an advanced, open-source endpoint monitoring, digital forensics, and cyber response platform.…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: dfir, Velociraptor
Vulnerability Management: FARADAY
Posted inVulnerability Scanning DETECT GRC

Vulnerability Management: FARADAY

Faraday: Open Source Vulnerability Manager Faraday is a powerful open-source vulnerability management platform designed to help cybersecurity teams streamline their pentesting, vulnerability assessment, and remediation processes. Built with a collaborative and automation-driven approach, Faraday enables security…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: vuln, faraday
Wireshark 101 | Traffic Analysis and Investigation (PART 04)
Posted inDETECT RESPOND DFIR

Wireshark 101 | Traffic Analysis and Investigation (PART 04)

Encrypted Protocol Analysis: Decrypting HTTPS When investigating web traffic, analysts often run across encrypted traffic. This is caused by using the Hypertext Transfer Protocol Secure (HTTPS) protocol for enhanced security against spoofing, sniffing and intercepting attacks.…
Read More
Posted by Avatar photo zyberbkay Tags: wireshark

Posts pagination

1 2 3 4 Next page

Recent Posts

  • XSS vs SSRF: Two Different Trust Boundaries, Two Different Attacks
  • Importing the Wazuh 5.0 Beta OVA into Proxmox
  • Exploring Wazuh: Introduction
  • Metasploit: Quick Reference Sheet
  • HAVOC C2: COMMAND & CONTROL FRAMEWORK [PART – I]

Categories

AD attacks brute-force caldera CISO dfir Elastic hydra linux LTM NIST red-team SIEM snort splunk Threat Intel threat_detection Threat_hunting vulnhub wazuh wireshark

Copyright 2026 — NetwerkLABS. Powered by TekGenX Consulting. All rights reserved.
Scroll to Top

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by