Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
68 articles

#Security

All CosmicBytez Labs articles tagged #Security, across news, security advisories, how-to guides, and projects.

  • ProjectMay 27, 2026

    Runtime Security Monitoring with Falco: Detect Container

    Deploy Falco on a Docker host to monitor container syscalls at the kernel level, write custom homelab detection rules, and route real-time alerts through.

  • NewsMay 23, 2026

    npm Adds 2FA-Gated Publishing and Package Install Controls

    GitHub has rolled out new security controls for npm including staged publishing with 2FA approval requirements and package install policies, giving...

  • NewsMay 21, 2026

    Apple Blocked Over $11 Billion in App Store Fraud in 6 Years

    Apple has revealed it blocked more than $11 billion in fraudulent App Store transactions over the past six years, including $2.2 billion in 2025 alone,...

  • NewsMay 21, 2026

    Apple Rejected 2 Million App Store Submissions in 2025 for

    Apple's annual transparency report reveals the company blocked over 2 million App Store submissions, 1.1 billion accounts, and $2.2 billion in potentially...

  • HOWTOMay 11, 2026

    CrowdSec: Deploy a Community-Powered Intrusion Prevention System

    Install and configure CrowdSec on Linux to detect and block attacks using crowdsourced threat intelligence, custom scenarios, and iptables/nftables bouncers.

  • ProjectApr 22, 2026

    Self-Hosted Password Manager with Vaultwarden

    Deploy a fully self-hosted, Bitwarden-compatible password manager using Vaultwarden on Docker with Caddy reverse proxy, automatic TLS, WebSocket...

  • ProjectApr 1, 2026

    WireGuard Road Warrior VPN Server

    Build a self-hosted WireGuard VPN server on Ubuntu for secure remote access — with NAT masquerading, DNS leak protection, QR-code client provisioning, and...

  • HOWTOMar 27, 2026

    Container Security Scanning with Trivy: Images, IaC, and

    Learn how to use Trivy to scan container images, Dockerfiles, Kubernetes manifests, and Terraform for vulnerabilities and misconfigurations — then...

  • ProjectMar 27, 2026

    Build a Collaborative IPS with CrowdSec

    Deploy CrowdSec on a Linux server to get community-powered intrusion prevention — block brute-force attacks, credential stuffing, and vulnerability...

  • ProjectMar 26, 2026

    Keycloak SSO: Self-Hosted Identity Provider for Your Homelab

    Deploy Keycloak with Docker Compose and PostgreSQL to build a centralised single sign-on platform for your homelab services, with OIDC integration for...

  • HOWTOFeb 23, 2026

    Domain Controller Hardening: Securing Active Directory

    Comprehensive DC hardening guide covering tier model implementation, LDAP signing, NTLM restrictions, Kerberos hardening, AdminSDHolder, DSRM security,...

  • HOWTOFeb 23, 2026

    Windows Server Hardening: Complete Security Guide for

    Step-by-step Windows Server hardening covering CIS benchmarks, attack surface reduction, service hardening, firewall rules, credential protection, and...

  • ChecklistFeb 23, 2026

    IT Employee Offboarding Checklist

    Complete IT offboarding checklist for departing employees. Covers account deactivation, access revocation, device recovery, data management, and...

  • HOWTOFeb 11, 2026

    SentinelOne Application Control Policies

    Organizations face security risks from unauthorized applications, malware disguised as legitimate software, and shadow IT installations that bypass...

  • HOWTOFeb 11, 2026

    SentinelOne Control vs Complete Feature Comparison

    This document provides a comprehensive comparison between SentinelOne Singularity Control and Singularity Complete SKUs to help MSP teams understand the...

  • HOWTOFeb 11, 2026

    SentinelOne Create and Manage Exclusion Policies

    SentinelOne exclusion policies allow security teams to prevent false-positive detections and performance issues by excluding specific files, folders,...

  • HOWTOFeb 11, 2026

    SentinelOne Data Retention and Storage Management

    Organizations using SentinelOne Singularity Complete receive 14-365+ days of Deep Visibility EDR data retention by default. This historical telemetry...

  • HOWTOFeb 11, 2026

    SentinelOne Deep Visibility Threat Hunting

    Deep Visibility is SentinelOne's EDR telemetry engine that provides comprehensive endpoint data collection for threat hunting, incident investigation, and...

  • HOWTOFeb 11, 2026

    SentinelOne Deploy Agent Manual Installation

    Manual SentinelOne agent installation is used when automated deployment methods (GPO, RMM, SCCM) are unavailable or when installing on standalone...

  • HOWTOFeb 11, 2026

    SentinelOne Deploy Agent via Group Policy

    Deploying SentinelOne agents across Windows endpoints at scale using Active Directory Group Policy Objects (GPO) enables centralized, automated agent...

  • HOWTOFeb 11, 2026

    Deploy SentinelOne Policy

    Deploy, manage, and validate SentinelOne security policies across your endpoint estate using the SentinelOne Management API. This automated workflow supports:

  • HOWTOFeb 11, 2026

    SentinelOne Device Control Configuration

    USB drives, external hard drives, and Bluetooth peripherals represent significant security risks in enterprise environments. Malicious actors use USB...

  • HOWTOFeb 11, 2026

    SentinelOne File Fetch and Forensic File Collection

    During threat investigations, security analysts need to retrieve suspicious files from endpoints for deeper forensic analysis. Traditional methods...

  • HOWTOFeb 11, 2026

    SentinelOne Firewall Control Management

    Traditional endpoint protection focuses on file-based malware, but network-based attacks (lateral movement, command-and-control callbacks, port scanning,...

  • HOWTOFeb 11, 2026

    SentinelOne Forensics Rollback and Remediation

    This document provides comprehensive procedures for forensic evidence collection, ransomware rollback, and threat remediation using SentinelOne Complete...

  • HOWTOFeb 11, 2026

    SentinelOne Health Check: Agent Status Monitoring Guide

    Organizations deploying SentinelOne endpoint protection require continuous monitoring of agent health to ensure comprehensive threat coverage across their...

  • HOWTOFeb 11, 2026

    Invoke SentinelOne Threat Hunt

    Proactive threat hunting is essential for identifying sophisticated threats that evade automated detection systems. This script automates the process of...

  • HOWTOFeb 11, 2026

    SentinelOne MITRE ATT&CK Threat Hunting

    The MITRE ATT&CK framework catalogs 14 tactics and 200+ techniques used by adversaries. Security teams need to proactively hunt for these techniques in...

  • HOWTOFeb 11, 2026

    SentinelOne MSP Client Onboarding

    This runbook provides a standardized process for onboarding new MSP clients to SentinelOne Singularity Complete. Following this methodology ensures...

  • HOWTOFeb 11, 2026

    SentinelOne Policy Configuration Best Practices

    This guide provides comprehensive best practices for configuring SentinelOne policies in MSP environments managing multiple client sites with Singularity...

  • HOWTOFeb 11, 2026

    SentinelOne PowerShell API Automation

    The SentinelOne Management Console REST API enables automation of administrative tasks, reporting, threat response, and integration with existing security...

  • HOWTOFeb 11, 2026

    SentinelOne PowerShell Automation Scripts

    This document provides a comprehensive library of production-ready PowerShell scripts for automating SentinelOne operations in an MSP environment. These...

  • HOWTOFeb 11, 2026

    SentinelOne Purple AI Usage Guide

    Security Operations Centers (SOCs) face overwhelming alert volumes, complex threat investigations, and resource constraints. Analysts spend hours writing...

  • HOWTOFeb 11, 2026

    SentinelOne Ranger Network Discovery and IoT Visibility

    Modern enterprise networks contain a complex mix of managed endpoints (workstations, servers), IoT devices (IP cameras, printers, smart building systems),...

  • HOWTOFeb 11, 2026

    SentinelOne Remote Shell Operations

    Full Remote Shell is a SentinelOne Complete feature that provides authorized administrators with secure, native command-line access to managed endpoints...

  • HOWTOFeb 11, 2026

    SentinelOne RMM Integration Guide

    This runbook provides comprehensive guidance for integrating SentinelOne Singularity Complete with NinjaRMM and other RMM platforms. Proper RMM...

  • HOWTOFeb 11, 2026

    SentinelOne Sandbox Integration Configuration

    SentinelOne detects suspicious files but automated malware analysis requires sandbox integration. Manually uploading files to VirusTotal, Joe Sandbox, or...

  • HOWTOFeb 11, 2026

    SentinelOne STAR Advanced Automation and Watchlists

    Security teams face the challenge of detecting organization-specific threats, insider threats, and policy violations that generic detection rules cannot...

  • HOWTOFeb 11, 2026

    SentinelOne STAR Custom Detection Rules

    Storyline Active Response (STAR) is SentinelOne's cloud-based automated hunting, detection, and response engine that allows security teams to create...

  • HOWTOFeb 11, 2026

    SentinelOne Threat Investigation Workflow

    When SentinelOne detects a threat on an endpoint, security analysts must quickly investigate the alert to determine if it's a genuine malware infection,...

  • HOWTOFeb 11, 2026

    SentinelOne Timeline Forensics and Attack Chain Analysis

    Understanding the complete attack chain requires correlating hundreds of events (process creation, network connections, file modifications, registry...

  • ChecklistFeb 11, 2026

    IT Employee Onboarding Checklist

    Complete IT onboarding checklist for new employee setup. Covers account provisioning, hardware deployment, security configuration, software installation,...

  • ChecklistFeb 10, 2026

    Server Hardening Security Checklist

    Comprehensive checklist for hardening Linux and Windows servers before production deployment. Covers OS configuration, network security, access controls,...

  • ChecklistFeb 9, 2026

    Incident Response Checklist

    Step-by-step incident response checklist following NIST SP 800-61 framework. Covers preparation, detection, containment, eradication, recovery, and...

  • NewsFeb 5, 2026

    Samsung Ends Software Support for Galaxy S21 Series

    Samsung's February 2026 update roadmap removes Galaxy S21 lineup from support, while S22 series moves to quarterly updates.

  • HOWTOFeb 5, 2026

    Microsoft 365 Security and Compliance Configuration Guide

    Harden your Microsoft 365 tenant with security baselines, conditional access policies, data loss prevention, audit logging, and compliance configurations...

  • HOWTOFeb 3, 2026

    Conditional Access Policies: Zero Trust with Entra ID

    Implement Zero Trust security with Microsoft Entra ID Conditional Access. Covers named locations, device compliance, risk-based policies, and...

  • HOWTOFeb 3, 2026

    Enterprise BitLocker Automation with PowerShell

    Deploy and manage BitLocker encryption at scale using PowerShell, with automatic TPM validation, recovery key backup to Azure AD and NinjaRMM, and...

  • HOWTOFeb 3, 2026

    FortiGate Firewall Policy Management with PowerShell

    Automate FortiGate firewall policy creation, backup, and auditing using PowerShell and the FortiOS REST API. Includes bulk rule deployment, change...

  • HOWTOFeb 3, 2026

    Kubernetes Secrets Management with External Secrets Operator

    Securely manage Kubernetes secrets using External Secrets Operator. Covers ESO installation, SecretStore configuration, syncing from Azure Key Vault and...

  • HOWTOFeb 3, 2026

    SentinelOne Agent Deployment: EDR Installation Guide

    Deploy and manage SentinelOne EDR agents across your environment. Covers manual installation, verification, troubleshooting, and best practices.

  • HOWTOFeb 3, 2026

    SentinelOne Threat Hunting Recipes: Practical Deep

    A practical recipe book of Deep Visibility hunts — encoded PowerShell, LOLBin abuse, lateral movement, persistence mechanisms. Each recipe is a copy-paste S1QL.

  • ProjectFeb 3, 2026

    Azure Landing Zone with Terraform

    Deploy enterprise-ready Azure environment with hub-spoke network, Azure Firewall, Log Analytics, Defender for Cloud following Microsoft CAF best practices.

  • ProjectFeb 3, 2026

    CI/CD Pipeline with GitHub Actions and Azure

    Build a secure CI/CD pipeline with GitHub Actions deploying to Azure. Covers build, test, security scanning (SAST/DAST), and deployment with OIDC...

  • NewsletterFeb 3, 2026

    Security Roundup & FortiGate Deep Dive - Issue #2

    This week: FortiGate SD-WAN deployment, new CVEs affecting critical infrastructure, and Azure Sentinel implementation tips.

  • HOWTOFeb 2, 2026

    Building a Secure Homelab in 2026: Complete Guide

    Learn how to set up a production-grade homelab with proper network segmentation, monitoring, and security controls. Perfect for IT professionals and...

  • HOWTOJan 28, 2026

    SSH Hardening Best Practices

    Secure your SSH servers with essential hardening techniques including key-based authentication, fail2ban configuration, and advanced security measures.

  • HOWTOJan 28, 2026

    WireGuard VPN Setup: Secure Remote Access

    Deploy a modern, high-performance VPN using WireGuard. Covers server setup, client configuration, and security best practices for secure remote access.

  • NewsletterJan 27, 2026

    Welcome to CosmicBytez Labs - Issue #1

    Welcome to the first issue of the CosmicBytez Labs newsletter! This week: major security vulnerabilities, Kubernetes best practices, and cloud...

  • HOWTOJan 26, 2026

    Linux Server Hardening: Complete Security Checklist

    Comprehensive guide to hardening Linux servers covering user management, service configuration, kernel security, and ongoing maintenance for production systems.

  • HOWTOJan 25, 2026

    Docker Security Fundamentals: Protecting Your Containers

    Learn essential Docker security practices including image scanning, runtime protection, network isolation, and secrets management for production environments.

  • HOWTOJan 25, 2026

    Windows Security Baseline Audit: CIS Benchmark Compliance

    Automate Windows security baseline checks using PowerShell. Validate configurations against CIS benchmarks for password policies, audit settings, and...

  • HOWTOJan 24, 2026

    Windows Security Event Log Analysis: Detect Threats and

    Learn to analyze Windows Security Event Logs to detect brute force attacks, lateral movement, privilege escalation, and other security threats using PowerShell.

  • HOWTOJan 22, 2026

    Pi-hole DNS Security: Block Ads, Trackers, and Malware

    Deploy Pi-hole for network-wide ad blocking and DNS security. Includes setup, configuration, upstream DNS options, and integration with encrypted DNS.

  • HOWTOJan 20, 2026

    Implementing a Robust Backup Strategy: The 3-2-1 Rule

    Design and implement a comprehensive backup strategy using the 3-2-1 rule. Covers backup types, automation, encryption, and disaster recovery testing.

  • ProjectJan 18, 2026

    Build a Centralized Log Management System with Loki and

    Deploy a scalable log management solution using Grafana Loki. Learn to aggregate, search, and alert on logs from your entire infrastructure.

  • HOWTOJan 15, 2026

    Network Monitoring Basics: Detect Threats Before They Spread

    Learn how to set up effective network monitoring using open-source tools. Covers traffic analysis, alerting, and common indicators of compromise.

  • HOWTOJan 10, 2026

    Self-Hosting a Password Manager: Vaultwarden Setup Guide

    Deploy your own password manager with Vaultwarden (Bitwarden-compatible). Includes secure configuration, SSL setup, and backup procedures.