Troubleshooting NSM Virtualization Problems With Linux And VirtualBox
8th Apr 2019 [16 days ago] from TaoSecurity
I spent a chunk of the day troubleshooting a network security monitoring (NSM) problem. I thought I would share the problem and my investigation in the hopes that it might help others. The specifics are probably less important than the...
Thoughts On OSSEC Con 2019
28th Mar 2019 [27 days ago] from TaoSecurity
Last week I attended my first OSSEC conference. I first blogged about OSSEC in 2007, and wrote other posts about it in the following years.OSSEC is a host-based intrusion detection and log analysis system with correlation and active response...
Thoughts On Cloud Security
14th Mar 2019 [one month ago] from TaoSecurity
Recently Ive been reading about cloud security and security with respect to DevOps. Ill say more about the excellent book Im reading, but I had a moment of déjà vu during one section.The book described how cloud security is a big change...
Ntopng On Security Onion
10th Feb 2019 [2 months ago] from TaoSecurity
so16@so16:~$ mkdir gitso16@so16:~$ cd gitso16@so16:~/git$ lsso16@so16:~/git$ wget --no-check-certificate https://github.com/branchnetconsulting/so-ntopng-installer/raw/master/install_ntopng_on_so_16--2019-02-11 02:48:02-- https://github.com/branchnetconsulting/so-ntopng-installer/raw/master/install_ntopng_on_so_16Resolving...
Forcing The Adversary To Pursue Insider Theft
9th Feb 2019 [2 months ago] from TaoSecurity
Jack Crookpointed me toward a story byChristopher Burgessabout intellectual property theft by "Hongjin Tan, a 35 year old Chinese national and U.S. legal permanent resident... [who] was arrested on December 20 and charged with theft of...
Fixing Virtualbox RDP Server With DetectionLab
29th Jan 2019 [3 months ago] from TaoSecurity
Yesterday I posted about DetectionLab, but noted that I was having trouble with the RDP servers offered by Virtualbox. If you remember, DetectionLab builds four virtual machines:root@LAPTOP-HT4TGVCP C:Users oot"c:Program FilesOracleVirtualBoxVBoxManage"...
Trying DetectionLab
28th Jan 2019 [3 months ago] from TaoSecurity
Many security professionals run personal labs. Trying to create an environment that includes fairly modern Windows systems can be a challenge. In the age of "infrastructure as code," there should be a simpler way to deploy systems in a...
Happy 16th Birthday TaoSecurity Blog
8th Jan 2019 [4 months ago] from TaoSecurity
Today, 8 January 2019, is TaoSecurity Blogs 16th birthday! This is also my 3,041st blog post.I wrote my first post on 8 January 2003 while working as an incident response consultant for Foundstone.Here are a few statistics on the blog....
Notes On Self-Publishing A Book
31st Dec 2018 [4 months ago] from TaoSecurity
In this post I would like to share a few thoughts on self-publishing a book, in case anyone is considering that option.As I mentioned in my post onburnout, one of my goals was to publish a book on a subject other than cyber security. A...
Managing Burnout
21st Dec 2018 [4 months ago] from TaoSecurity
This is not strictly an information security post, but the topic likely affects a decent proportion of my readership.Within the last few years I experienced a profound professional "burnout." Ive privately mentioned this to colleagues in...
