Skip to content
 ottolukacs.com
About me
Explore my work. 🐸

SIEM Crafting

Detecting Suspicious Office 365 Emails with Wazuh

In this scenario, I demonstrate my approach for alerting on suspicious emails received in the Office 365 email ecosystem using Wazuh. The alerting logic is based on SPF/DKIM/DMARC DNS records …
Read

Automated File Integrity Monitoring Deployment Using Ansible on Wazuh

This solution provides a fast, structured, and repeatable way to configure file integrity monitoring across multiple Wazuh agents …
Read

Blocks lab

Ongoing documentation for blocks-lab

  • Setting the Stage: Create Ubuntu Lab on AWS with Terraform
  • Blocks-lab: Introduction

SIEM

Collection of articles focused on my best practices for configuring SIEM systems

  • Wazuh Upgrade Automation Script
  • Task Outline: Investigation of User Creation and Privilege Escalation
  • Automated File Integrity Monitoring Deployment Using Ansible on Wazuh
  • Detecting Suspicious Office 365 Emails with Wazuh

© 2026 ottolukacs.com