fbpx

Documentation

Blumira Configuration
  • Blumira Getting Started Guide

  • Create a Blumira Sensor

  • Blumira Sensor Outbound Allowlist

  • Reinstalling or Updating a Blumira Sensor

  • Security Findings

  • Role-Based Administration

  • Dynamic Blocklists and Threat Feeds

  • Deploy a Blumira Honeypot

  • Build a Sensor on Ubuntu

Cloud Services
  • KnowBe4 – PhishER

    KnowBe4 – PhishER

  • Infoblox

    Infoblox

  • Microsoft Defender for Endpoint

    Microsoft Defender for Endpoint

  • Microsoft Defender for Office 365

    Microsoft Defender for Office 365

  • Azure AD

    Azure AD

  • Okta

    Okta

  • Cisco Umbrella

    Cisco Umbrella

  • Google G Suite

    Google G Suite

  • Duo Security

    Duo Security

  • Microsoft Office 365

    Microsoft Office 365

  • Microsoft Cloud App Security

    Microsoft Cloud App Security

  • Microsoft Azure Event Hub

    Microsoft Azure Event Hub

AWS
  • AWS: Getting Started Guide

    AWS: Getting Started Guide

  • AWS: Kinesis Data Stream and IAM

    AWS: Kinesis Data Stream and IAM

  • AWS: CloudTrail

    AWS: CloudTrail

  • AWS: CloudWatch

    AWS: CloudWatch

  • AWS: VPC Flow Logs

    AWS: VPC Flow Logs

  • AWS: GuardDuty

    AWS: GuardDuty

Endpoint
  • Malwarebytes Nebula

    Malwarebytes Nebula

  • Symantec Endpoint Security

    Symantec Endpoint Security

  • Trend Micro Apex One

    Trend Micro Apex One

  • Microsoft Defender for Endpoint

    Microsoft Defender for Endpoint

  • Microsoft Windows Defender

    Microsoft Windows Defender

  • Blackberry Cylance

    Blackberry Cylance

  • Sophos Central

    Sophos Central

  • ESET Endpoint Protection

    ESET Endpoint Protection

  • Malwarebytes

    Malwarebytes

  • VMware Carbon Black Managed Defense

    VMware Carbon Black Managed Defense

  • VMware Carbon Black Endpoint Protection

    VMware Carbon Black Endpoint Protection

  • VMware Carbon Black Response

    VMware Carbon Black Response

  • CrowdStrike Falcon Endpoint Protection

    CrowdStrike Falcon Endpoint Protection

Microsoft Server
  • Advanced Microsoft Logging (GPO Template)

    Advanced Microsoft Logging (GPO Template)

  • Microsoft Windows Defender

    Microsoft Windows Defender

  • Microsoft Windows Firewall

    Microsoft Windows Firewall

  • Microsoft Windows DNS

    Microsoft Windows DNS

  • Microsoft Windows PowerShell

    Microsoft Windows PowerShell

  • Microsoft Windows IIS

    Microsoft Windows IIS

  • Microsoft Active Directory

    Microsoft Active Directory

  • Microsoft Windows Server

    Microsoft Windows Server

Microsoft Cloud
  • Microsoft Security Modules

  • Microsoft Defender for Endpoint

    Microsoft Defender for Endpoint

  • Microsoft Defender for Office 365

    Microsoft Defender for Office 365

  • Azure AD

    Azure AD

  • Microsoft Office 365

    Microsoft Office 365

  • Microsoft Cloud App Security

    Microsoft Cloud App Security

  • Microsoft Azure Event Hub

    Microsoft Azure Event Hub

Identity
  • LastPass

    LastPass

  • Okta

    Okta

  • Microsoft Active Directory

    Microsoft Active Directory

  • Duo Security

    Duo Security

Firewall
  • Citrix Netscaler ADC

    Citrix Netscaler ADC

  • WatchGuard Firebox Firewall

    WatchGuard Firebox Firewall

  • F5 Big-IP

    F5 Big-IP

  • Palo Alto Next-Gen Firewall

    Palo Alto Next-Gen Firewall

  • Fortinet Fortigate Firewall

    Fortinet Fortigate Firewall

  • Cisco Meraki Firewall

    Cisco Meraki Firewall

  • SonicWall Next-Gen Firewall

    SonicWall Next-Gen Firewall

  • Sophos XG Firewall

    Sophos XG Firewall

  • Cisco FTD FirePower Threat Defense

    Cisco FTD FirePower Threat Defense

  • Cisco ASA Firewall

    Cisco ASA Firewall

  • Check Point Next-Gen Firewall

    Check Point Next-Gen Firewall

Other
  • Forescout

    Forescout

  • WinLogBeat Forwarding

    WinLogBeat Forwarding

  • Apache Web Server

    Apache Web Server

  • Linux Auditd File Integrity Monitoring

    Linux Auditd File Integrity Monitoring

  • Linux Journald

    Linux Journald

  • Nginx Web Server

    Nginx Web Server

  • VMware ESXi

    VMware ESXi

  • Cisco Umbrella

    Cisco Umbrella

  • Sophos Central

    Sophos Central

  • Apple Mac OS

    Apple Mac OS

  • Linux Servers

    Linux Servers

  • Proofpoint Advanced Threat Protection

    Proofpoint Advanced Threat Protection

  • Palo Alto Networks Panorama

    Palo Alto Networks Panorama

Security Guides
  • How to Image Machines for Forensic Use

    How to Image Machines for Forensic Use

  • How to Disable Null Session in Windows

    How to Disable Null Session in Windows

  • How to Disable LLMNR, Netbios, WPAD, & LM Hash

    How to Disable LLMNR, Netbios, WPAD, & LM Hash

  • How to Configure SMB Signing

    How to Configure SMB Signing

Detection Tests
  • Office365 Inbox Rule Creation

    Office365 Inbox Rule Creation

  • Deletion of Windows Event Log Detection Test

    Deletion of Windows Event Log Detection Test

  • PowerShell Execution Policy Bypass

    PowerShell Execution Policy Bypass

  • How To Test a Honeypot

    How To Test a Honeypot

  • Domain Administrator Account Creation

    Domain Administrator Account Creation

  • Password Spraying

    Password Spraying

Threat Feeds
  • Threat Feed: Abuse.ch SSL Blocklist

    Threat Feed: Abuse.ch SSL Blocklist

  • Threat Feed: Abuse.ch Feodo Tracker

    Threat Feed: Abuse.ch Feodo Tracker

  • Blumira Feeds: An Overview

    Blumira Feeds: An Overview