Writing & analysis

The reasoning behind the systems.

Longer-form writing about operational trade-offs, lessons from implementation, and the decisions that make systems easier to trust.

Filter by category

Real-Time Malware Blocking with ClamAV On-Access (Part 7)

How I set up ClamAV on-access scanning with clamonacc, clamd, AppArmor, and Wazuh, then narrowed the protection scope so it stays stable on real hosts.

DevOpsAnsibleWazuhSecurity
Open article →

Build a ClamAV Database Mirror with Ansible (Part 6)

How I built an internal ClamAV mirror using Nginx to serve virus definitions, cutting 7.2GB/day of redundant egress traffic.

DevOpsSecurityAnsibleWazuh
Open article →

Wazuh Custom Rules for Alert Suppression (Part 5)

How I wrote Wazuh suppression rules that silenced 300+ noise alerts per hour after four failed approaches.

WazuhAnsibleSecurityDevOps
Open article →

Manage Wazuh Agent Profiles with Ansible (Part 4)

How I managed different Wazuh agent ossec.conf profiles using inventory-owned files, host variables, and Ansible deployment roles.

WazuhAnsibleDevOpsInfrastructure
Open article →

Manage Wazuh Manager Configuration with Ansible (Part 3)

How I managed Wazuh manager ossec.conf using inventory-owned files, local wrapper roles, and a controlled restart flow.

WazuhAnsibleDevOpsSecurity
Open article →

Wazuh SAML Authentication with Keycloak (Part 2)

How I integrated Wazuh with Keycloak using SAML, group-based access, and Wazuh RBAC mapping.

WazuhAnsibleSecurityDevOps
Open article →

Page 2 / 6 · 31 articles