Following up on my latest post, Christmas Wrappers - Part 1, we’ll be looking at how to expand our wrapper script in Powershell. In the last post we created a wrapper script for the MISP API. In this post we’ll be adding functionality to the wrapper script.
[Read More]
Christmas Wrappers - Part 1
How to create a wrapper script in Powershell
One of my earliest posts was “Building a function”. It was my attempt at teaching people to build a function in Powershell. It’s a bit outdated now, but I still think it’s a decent read - however, the time has come to revisit the topic of Powershell-functions. This time, in...
[Read More]
Share your work!
How to get started sharing what you create and a book-review, of sorts.
Early on in my career I had this weird aversion for people who wrote blogs. I’m pretty sure at least part of it was a result of the nordic phenomenon called the Law of Jante, which can be summarized as a code of conduct used colloquially to denote a social...
[Read More]
Security Monitoring - Developing Use Cases
Some thoughts on developing use cases and the importance of detection engineering
In this blog post I’ll be writing about developing use cases for security monitoring. I’ll be using Microsoft Sentinel as an example, but the same principles apply to any SIEM or security monitoring platform.
[Read More]
Figuring out MISP2Sentinel Event Filters
How they work, how to use them and some (hopefully not horrible) examples.
MISP is becoming a popular open source option for managing threat intelligence at the operational level by sharing indicators of compromise (IOCs) and contextualizing them with other data. It can, however, be a bit daunting to figure out how to use the event filters. In this post I’ll go through...
[Read More]