All CosmicBytez Labs articles tagged #blue-team, across news, security advisories, how-to guides, and projects.
Capture, filter, and triage network traffic like an analyst. Learn Wireshark display filters, tshark for headless captures, and how to spot common attack patterns on the wire.
Learn to write effective YARA rules to identify malware, hunt threats, and scan endpoints for indicators of compromise — from basic syntax to real-world rule sets.
Build a production-grade security incident response platform using TheHive 5, Cassandra, Elasticsearch, and MinIO — then integrate it with Wazuh alerts...
Set up OpenCanary honeypot services on a Raspberry Pi or VM to detect lateral movement, credential stuffing, and unauthorized access before attackers...
Deploy Sysmon for deep process, network, and file telemetry, then centralise those events to a Windows Event Collector server using WEF — all without a...
Deploy Velociraptor — the open-source DFIR platform — to collect forensic artifacts, run live endpoint hunts with VQL, and build an incident response...
Deploy Zeek (formerly Bro) on Linux to passively monitor network traffic, generate structured logs, write detection scripts, and forward data to your SIEM...
Deploy a full deception technology stack using T-Pot and OpenCanary to capture real attacker behaviour, generate threat intelligence, and sharpen your...