Writing & analysis

The reasoning behind the systems.

Longer-form writing about operational trade-offs, lessons from implementation, and the decisions that make systems easier to trust.

Filter by category

Scan Dependency CVEs with Syft and Grype in GitHub Actions

Use SBOM-based scanning to identify vulnerable dependencies before running code locally or building images in CI.

Software Supply ChainSBOMGitHub ActionsSyft
Open article →

Wazuh Ansible Series

A Wazuh-by-Ansible series covering deployment, SAML, configuration, rule tuning, malware detection, backups, and Zeek telemetry.

SecurityAnsibleWazuh
Open article →

Integrate Zeek Network Telemetry with Wazuh (Part 11)

How to install Zeek on selected hosts, collect JSON logs with the Wazuh agent, and promote them into custom network-security rules.

WazuhCloud SecurityAnsibleDevOps
Open article →

Automate Wazuh Indexer Backups to Google Cloud Storage (Part 10)

How I backed up Wazuh index data to Google Cloud Storage, kept snapshots for 9 days, and trimmed live index data to 7 days with three small moves.

WazuhAnsibleDevOpsGoogle Cloud Platform
Open article →

Scheduled YARA Malware Detection with Wazuh (Part 9)

Build scheduled YARA malware scanning with Wazuh and Ansible to detect custom file signatures beyond traditional antivirus coverage.

WazuhDevOpsYara RulesCloud Security
Open article →

Scheduled Malware Scanning with ClamAV and Wazuh (Part 8)

How I added recurring ClamAV scans as a reporting layer on top of on-access protection, with clean Wazuh alerts and per-directory audit visibility.

AnsibleWazuhDevOpsCloud Security
Open article →

Page 1 / 6 · 31 articles