Skip to content
ottolukacs.comottolukacs.com
Home SOC Lab Series Blog About me
Explore my work. 🐸

Detecting User Creation and Privilege Escalation on Windows

In this part, we implement detection and alerting for user creation and privilege assignment activities on Windows systems …
March 19, 2026 / otto.lukacs

Agent Onboarding on Linux with Bash

This simple Bash script helps deploy Wazuh agents on Linux systems …
March 18, 2026 / otto.lukacs

Investigation of User Creation and Privilege Escalation on Linux

Let’s see how to configure the SIEM to detect and alert on user creation and privilege assignment activities on Linux systems …
February 25, 2026 / otto.lukacs

Detecting Suspicious Office 365 Emails with Wazuh

In this scenario, I demonstrate my approach for alerting on suspicious emails received in the Office 365 email ecosystem using Wazuh. The alerting logic is based on SPF/DKIM/DMARC DNS records configured on the sender’s domain …
February 19, 2026 / otto.lukacs

Featured Posts

Automated File Integrity Monitoring Deployment Using Ansible on Wazuh

This solution provides a fast, structured, and repeatable way to configure file integrity monitoring across multiple Wazuh agents …
Read

Services

Phishing Email Investigation

I analyze suspicious emails to determine whether they are legitimate, phishing attempts, or potentially malicious, and provide clear, actionable insights …
Read

SOC Lab Series

Hands-on detection engineering and security monitoring with Wazuh

  • Investigation of User Creation and Privilege Escalation on Linux
  • Detecting User Creation and Privilege Escalation on Windows
  • Agent Onboarding on Linux with Bash

Blog

Collection of articles focused on my best practices

  • Wazuh Upgrade Automation Script
  • Automated File Integrity Monitoring Deployment Using Ansible on Wazuh
  • Detecting Suspicious Office 365 Emails with Wazuh
  • Blocks-lab: Introduction
  • Setting the Stage: Create Ubuntu Lab on AWS with Terraform

Services

  • Phishing Email Investigation

Latest Insights

Agent Onboarding on Linux with Bash
by u/ottolukacs in u_ottolukacs
ottolukacs.com – Documenting Cybersecurity Through Custom Labs
by u/ottolukacs in u_ottolukacs

© 2026 ottolukacs.com