Skip to main content

Recently Updated Pages

Use it or Lose it - AI and the Atrophy of Skill

Use it or Lose it - AI and the Atrophy ...

Forward Years ago I managed a small team of talented developers where writing SQL was a large par...

Updated 3 weeks ago by Chris Landis

7. Threat Detection and Response

TheDen Home Network Runbook

7.1 Overview TheDen Home Network employs a layered approach to threat detection, focusing on vis...

Updated 1 month ago by Chris Landis

4. Firewall and Routing

TheDen Home Network Runbook

4.1 Overview The OPNsense firewall on the FW6D serves as the central routing, filtering, and NAT...

Updated 1 month ago by Chris Landis

2.1 Authentication (passwords, MFA, passkeys, biometrics)

Privacy and Security Runbook 2. Accounts and Identity

Core Concepts: Protect Yourself, Protect Your Data When you log into a computer or website with ...

Updated 1 month ago by Chris Landis

Configuring a Flask app (build-it-yourself pattern)

SSO For Small Ecosystems

Pattern: build it yourself. Discourse and BookStack are someone else's applications where you con...

Updated 1 month ago by Chris Landis

Configuring Discourse (identity-only pattern)

SSO For Small Ecosystems

Pattern: identity only. Discourse authenticates users through Keycloak but does no group or role ...

Updated 1 month ago by Chris Landis

Deploying Keycloak

SSO For Small Ecosystems

Everything else in this book assumes a working Keycloak that applications can reach over HTTPS an...

Updated 1 month ago by Chris Landis

Alerting and Scheduling

Homebrew SIEM

Pattern: getting signals to a human, on a cadence. Analysis produces signals, this stage runs the...

Updated 2 months ago by Chris Landis

Lessons Learned

Homebrew SIEM

The lessons I've learned from building basic security monitoring without a SIEM product. You don'...

Updated 2 months ago by Chris Landis

Operations

Homebrew SIEM

A monitoring system that is installed and never tended decays into either noise you ignore or sil...

Updated 2 months ago by Chris Landis

Collection

Homebrew SIEM

Pattern: getting logs off every host and into one place. This is the plumbing, getting this stage...

Updated 2 months ago by Chris Landis

Analysis

Homebrew SIEM

Pattern: turning collected logs into signals. Collection gathers raw logs, analysis reduces them ...

Updated 2 months ago by Chris Landis

What to Monitor

Homebrew SIEM

Pattern: deciding what is worth watching. This is the judgment page, and it is deliberately gener...

Updated 2 months ago by Chris Landis

Architecture

Homebrew SIEM

The whole system is four stages in a line: collect, centralize, analyze, alert. Every later page ...

Updated 2 months ago by Chris Landis

Concepts

Homebrew SIEM

Meaningful security monitoring without a SIEM product, and how to reason about what to watch. Thi...

Updated 2 months ago by Chris Landis

Lessons Learned

WAF for Small Ecosystems

The lessons I've learned from running a single-edge WAF in a self-hosted environment. Run learnin...

Updated 2 months ago by Chris Landis

Operating It

WAF for Small Ecosystems

A WAF is not a set-and-forget install. It is a control you have to be able to see working, tune w...

Updated 2 months ago by Chris Landis

Forward

SSO For Small Ecosystems

One identity provider, every service, and the configuration that makes it work. This book is a wo...

Updated 2 months ago by Chris Landis

Adding Inspection

WAF for Small Ecosystems

Attaching application-layer inspection to the reverse proxy. Standing up the edge gave you a prox...

Updated 2 months ago by Chris Landis

Standing Up the Edge

WAF for Small Ecosystems

The reverse proxy and public TLS, before any inspection is added. This is the baseline every publ...

Updated 2 months ago by Chris Landis