<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Home on wriotsec</title><link>https://www.wriotsecurity.com/</link><description>Recent content in Home on wriotsec</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Tue, 31 Jan 2023 22:12:00 +0000</lastBuildDate><atom:link href="https://www.wriotsecurity.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Exploring Windows Event Logs and Elastic Security for Incident Response</title><link>https://www.wriotsecurity.com/posts/exploring-windows-event-logs-for-incident-response/</link><pubDate>Tue, 31 Jan 2023 22:12:00 +0000</pubDate><guid>https://www.wriotsecurity.com/posts/exploring-windows-event-logs-for-incident-response/</guid><description>
&lt;p&gt;Elastic Security is incredibly useful for threat hunting especially with the success of tools like RockNSM and the HELK project. But what about hunting through old logs aided by detection tools that threat hunters use? How feasible is it to use Elastic Security if just want to stand it up the tool and throw some data at it? In this blog we we will explore how to take advantage of Elastic Security and the open source detection rules that are bundled in each release.&lt;/p&gt;</description></item><item><title>Setting up WSL, Ansible, and Packer for DevOps</title><link>https://www.wriotsecurity.com/posts/setting-up-wsl-ansible-and-packer-for-devops/</link><pubDate>Fri, 31 Dec 2021 22:48:24 -0600</pubDate><guid>https://www.wriotsecurity.com/posts/setting-up-wsl-ansible-and-packer-for-devops/</guid><description>
&lt;p&gt;WSL stands for Windows Subsystem for Linux. It allows Windows to run a lightweight Linux environment for running Linux binaries on Windows. I have not set it up from scratch by myself but have used it in the past with lab VM's like the one associated with &lt;a href="https://www.antisyphontraining.com/pay-what-you-can/"&gt;Black Hills Information Security's Pay What You Can&lt;/a&gt; courses. However, over the holidays I got myself an upgraded laptop and so I thought I would give it a try!&lt;/p&gt;</description></item></channel></rss>