This is the personal blog of Zane Gittins, focusing on cybersecurity, blue team operations, and digital forensics.
Posts
-
Provenance Graphs from LimaCharlie Telemetry
The provenance graph in Bifract v0.0.3 runs on whatever endpoint telemetry you normalize to the correct fields, and LimaCharlie is a natural fit: a single lightwe...
-
Bifract v0.0.3 Release
I’ve been looking forward to putting this one out for a while. Bifract is an open source log management, detection, and collaboration platform built on ClickHouse...
-
Introducing Bifract
I’ve always wanted a log management platform that was fast, easy to deploy, and built with collaboration in mind. I started looking for solutions when building my...
-
Linux Monitoring with eBPF and Velociraptor
eBPF makes capturing container activity trivial. Making sense of it? That’s where most tools fall short. Most modern Linux monitoring tools capture container acti...
-
Honeyfiles
When an attacker gains initial access in a victim environment, one of the first things they look for are opportunities to escalate their privileges and move later...
-
Enriching Sysmon with Velociraptor
The cornerstone of effective security monitoring is having the right context at the right time. Using Velociraptor we can enrich logs before they are sent to the ...