Security & Pentesting
-
How to Set Up Falco for Container Runtime Security Monitoring
Falco fills exactly that gap, watching container behavior in real time and alerting on suspicious activity that configuration hardening alone can’t catc…
-
How to Set Up Authelia for Single Sign-On Across Your Home Lab
After following this series, you’re likely logging into a genuinely long list of separate services individually — Gitea, Uptime Kuma, Grafana, Fresh…
-
How to Detect and Prevent ARP Spoofing on Your Home Network
Firewalls, VLANs, and intrusion detection covered throughout this series largely assume attacks come from outside your network boundary or target specif…
-
How to Audit and Rotate SSH Keys Across Your Home Lab
Regular SSH key rotation and auditing brings that back under control, ensuring only keys you actually recognize and still need retain access.
-
How to Harden Docker Containers: Security Best Practices
Docker container security hardening closes those gaps without sacrificing the convenience that made you choose containers in the first place.
-
How to Detect and Respond to a Compromised Server
Every security tool covered elsewhere in this series Fail2Ban, UFW, Suricata, Wazuh — exists to prevent a compromise from happening in the first place.
-
CrowdSec vs Fail2Ban: A Modern Alternative Worth Considering
CrowdSec vs Fail2Ban highlights a genuinely different approach: crowdsourced threat intelligence that benefits from attack patterns observed across thou…
-
Where to Practice Ethical Hacking Legally
Learning tools like Nmap, Suricata, and Kali Linux is only half the picture — without somewhere legal to actually practice against, that knowledge sta…
-
How to Set Up Wazuh for Security Monitoring in Your Home Lab
Setting up Wazuh as a SIEM for your home lab brings all of that together, centralizing security event logs, alerts, and file integrity monitoring from e…
-
How to Audit Your Linux Server’s Security with Lynis
After hardening SSH, setting up a firewall, and configuring Fail2Ban, it’s easy to wonder what else might still be misconfigured or overlooked.









