Technical Writing

Series, essays, and implementation write-ups

Longer-form writing on security operations, Wazuh implementation, infrastructure automation, and lessons that deserve more than a short note.

Wazuh Ansible Series

A Wazuh-by-Ansible implementation track covering deployment, SAML, manager and agent configuration, rule tuning, ClamAV, YARA, index backup automation, and Zeek telemetry integration.

SecurityAnsibleWazuh
Wazuh Ansible Series Part 11: Zeek Network Telemetry into Wazuh

How to install Zeek on selected hosts, collect JSON logs with the Wazuh agent, and promote them into custom network-security rules.

WazuhCloud SecurityAnsibleDevOps
Wazuh Ansible Series Part 10: Automating Wazuh Indexer Backups to Google Cloud Storage

How I backed up Wazuh index data to Google Cloud Storage, kept snapshots for 9 days, and trimmed live index data to 7 days with three small moves.

WazuhAnsibleDevOpsGoogle Cloud Platform
Wazuh Ansible Series Part 9: Custom Malware Detection with YARA Scheduled Scanning

How I built a YARA scanning pipeline that catches what ClamAV misses.

WazuhDevOpsYara RulesCloud Security
Wazuh Ansible Series Part 8: Scheduled Malware Scanning with ClamAV and Wazuh

How I added recurring ClamAV scans as a reporting layer on top of on-access protection, with clean Wazuh alerts and per-directory audit visibility.

AnsibleWazuhDevOpsCloud Security
Wazuh Ansible Series Part 7: Real-Time Malware Blocking with ClamAV On-Access

How I set up ClamAV on-access scanning with clamonacc, clamd, AppArmor, and Wazuh, then narrowed the protection scope so it stays stable on real hosts.

DevOpsAnsibleWazuhSecurity

Page 1 / 5 · 30 articles