by Eric Ooi | Aug 22, 2019 | cool tools, featured, how-to, incident response, information security, network security monitoring
Zeek is my favorite network security monitoring platform, and I’ve used it throughout my career. It generates rich network metadata that’s incredibly valuable for incident response, forensics, and general troubleshooting. For most people, the main challenge with...
by Eric Ooi | Oct 12, 2018 | cool tools, how-to, incident response, information security, network security monitoring
This is part of the Zeekurity Zen Zeries on building a Zeek (formerly Bro) network sensor. Overview This guide assumes you’ll be installing Zeek on Ubuntu 22.04 LTS. However, the guide should work for any reasonably recent versions of Ubuntu. Kicking things...
by Eric Ooi | Feb 14, 2016 | cool tools, incident response, information security, network security monitoring
Introduction I’ve spent most of my career defending environments of all sizes. What I’ve found is that the job of a defender is much less flashier and thankless as compared to an “ethical hacker.” While there are volumes of articles, guides,...
by Eric Ooi | Jul 26, 2015 | cool tools, how-to, information security
The Fun Stuff: Privilege Escalation, Exfiltration, and Persistence This is part of a series of posts that walk through an attack. To start from the beginning, click here. In the last post, we successfully exploited our Victim using a client-side attack targeting an...
by Eric Ooi | Jan 15, 2015 | cool tools, information security, scripting, vulnerability management
Last year, I wrote a couple articles on how to integrate Tripwire IP360 data into Splunk. These turned out to be very popular, with a number of folks reaching out to me for a copy of my IP360 Tools script that made all the magic happen. I hesitated to give the...
by Eric Ooi | Oct 12, 2014 | cool tools, how-to, information security
Seeing Red This is part of a series of posts that walk through an attack. In an ideal world, information security teams are comprised of both a dedicated Red Team (attackers or offensive side) and a Blue Team (incident responders or defensive side). I’ve never...