[-] starkzarn@infosec.pub 2 points 1 week ago

False positive what? I didn't give any specific examples of alerts, just simply monitoring metrics. Are you referring to the note on the Dnsmasq memory leak?

[-] starkzarn@infosec.pub 2 points 1 month ago

Why the hell is the text tilted? Am I going crazy?

[-] starkzarn@infosec.pub 2 points 1 month ago

Excellent! Let me know if there are specific things you'd like to hear about.

[-] starkzarn@infosec.pub 2 points 1 month ago

Absolutely! I'd happily take any comments you have from running it in an enterprise setting, if you care to share.

[-] starkzarn@infosec.pub 2 points 1 month ago

I would love to if I had them! Haha. I'm working on the dashboard right now, which will be part two.

I don't have a great answer on the IOPS requirement, but I imagine it's less than something based on elasticsearch/open search based on the reindexing. I'll try and benchmark it if possible.

[-] starkzarn@infosec.pub 2 points 1 month ago

Hey, the journey is the destination sometimes. Glad you liked it!

[-] starkzarn@infosec.pub 2 points 1 month ago

Awesome! Thanks for the banter. It's easy to get stuck in your own echo chamber working IT every day, so it's nice to have these kinds of questions. Feel free to drop anything into comments too, maybe other readers will benefit too!

[-] starkzarn@infosec.pub 1 points 1 month ago

Realized I didn't answer the last question here on hardening. The answer is sure! I don't have much planned for the blog, as I was just thinking I'd take "public notes" for my tinkerings as they came. I've done linux administration for a long time though so I'd be happy to put together a post on baselines and hardening

[-] starkzarn@infosec.pub 2 points 1 month ago

Okay, rudimentary RSS feed added! It's available in the navbar, and autodiscovery with your RSS aggregator should work from any page. Let me know if you have issues.

[-] starkzarn@infosec.pub 1 points 1 month ago

What nice feedback to read. I think you and I are aligned in what this will hopefully become. I really just wanted to start publicly sharing my hobby notes instead of holing them up in a local Joplin file or something, so that's what I'm going to do. We may have similar hobbies though, which sounds like it'll benefit you. Haha.

[-] starkzarn@infosec.pub 2 points 2 months ago* (last edited 2 months ago)

No one has mentioned anything about how CISA -- as gutted as they are -- has stepped up to ensure funding for the next 11 months. CVEs aren't going anywhere.

[-] starkzarn@infosec.pub 1 points 2 years ago

That sort of configuration after the fact would be a fantastic addition, if not already in place.

view more: ‹ prev next ›

starkzarn

joined 2 years ago