Recently Updated Pages
Use it or Lose it - AI and the Atrophy of Skill
Forward Years ago I managed a small team of talented developers where writing SQL was a large par...
7. Threat Detection and Response
7.1 Overview TheDen Home Network employs a layered approach to threat detection, focusing on vis...
4. Firewall and Routing
4.1 Overview The OPNsense firewall on the FW6D serves as the central routing, filtering, and NAT...
2.1 Authentication (passwords, MFA, passkeys, biometrics)
Core Concepts: Protect Yourself, Protect Your Data When you log into a computer or website with ...
Configuring a Flask app (build-it-yourself pattern)
Pattern: build it yourself. Discourse and BookStack are someone else's applications where you con...
Configuring Discourse (identity-only pattern)
Pattern: identity only. Discourse authenticates users through Keycloak but does no group or role ...
Deploying Keycloak
Everything else in this book assumes a working Keycloak that applications can reach over HTTPS an...
Alerting and Scheduling
Pattern: getting signals to a human, on a cadence. Analysis produces signals, this stage runs the...
Lessons Learned
The lessons I've learned from building basic security monitoring without a SIEM product. You don'...
Operations
A monitoring system that is installed and never tended decays into either noise you ignore or sil...
Collection
Pattern: getting logs off every host and into one place. This is the plumbing, getting this stage...
Analysis
Pattern: turning collected logs into signals. Collection gathers raw logs, analysis reduces them ...
What to Monitor
Pattern: deciding what is worth watching. This is the judgment page, and it is deliberately gener...
Architecture
The whole system is four stages in a line: collect, centralize, analyze, alert. Every later page ...
Concepts
Meaningful security monitoring without a SIEM product, and how to reason about what to watch. Thi...
Lessons Learned
The lessons I've learned from running a single-edge WAF in a self-hosted environment. Run learnin...
Operating It
A WAF is not a set-and-forget install. It is a control you have to be able to see working, tune w...
Forward
One identity provider, every service, and the configuration that makes it work. This book is a wo...
Adding Inspection
Attaching application-layer inspection to the reverse proxy. Standing up the edge gave you a prox...
Standing Up the Edge
The reverse proxy and public TLS, before any inspection is added. This is the baseline every publ...