Standard Post with Image

ตี 3.47 น.: เบื้องหลังเหตุการณ์จริงที่ถูกจับได้โดย SOC Stack แบบโอเพนซอร์ส

บทความเกี่ยวกับ SOC ส่วนใหญ่มักอธิบายสถาปัตยกรรม แต่บทความนี้จะพาไปดูเหตุการณ์จริงทีละ alert บน stack ที่ใช้งานจริงกับลูกค้าองค์กรขนาดกลาง — Wazuh สำหรับตรวจจับ, DFIR-IRIS สำหรับบริหารเคส และ integrator แบบ FastAPI ที่พัฒนาเองเชื่อมทั้งสองระบบเข้าด้วยกัน ไม่มีค่าไลเซนส์ SaaS ไม่มีค่า cloud SIEM ทุกส่วนเป็นโอเพนซอร์สหรือพัฒนาขึ้นเอง

Read More
Standard Post with Image

3:47 AM: Inside a Real Incident Caught by an Open-Source SOC Stack

Most SOC content explains architecture. This one walks through an actual incident, alert by alert, on a production stack running for a mid-sized enterprise client — Wazuh for detection, DFIR-IRIS for case management, and a custom FastAPI integrator holding the two together. No SaaS licenses. No cloud SIEM bill. Every component either open-source or built […]

Read More
Standard Post with Image

为什么工厂车间是您网络中最薄弱的目标

我接触的大多数安全团队都具备合理的IT卫生:端点部署了EDR、SIEM接入Windows事件日志,有时Web应用前还有WAF。但当我问到工厂车间在运行什么时,答案通常是"西门子S7、三菱SCADA,说实话我们也不完全清楚还有什么"。

Read More
Standard Post with Image

なぜ工場フロアはネットワーク上で最も脆弱な標的なのか

私が話をするセキュリティチームの多くは、それなりのITハイジーンを持っています。エンドポイントにEDR、WindowsイベントログをインジェストするSIEM、WebアプリケーションにWAF。ところが、工場フロアで何が稼働しているかを聞くと、返ってくる答えはたいてい「Siemens S7と三菱のSCADA、あとは正直よく分からない」というものです。

Read More
Standard Post with Image

ทำไม Floor โรงงานของคุณถึงเป็นจุดอ่อนที่สุดในเครือข่าย

ทีม Security ส่วนใหญ่ที่ผมคุยด้วยมี IT Hygiene ที่ดีพอสมควร: EDR บน Endpoint, SIEM ที่รับ Windows Event Log, บางทีมี WAF หน้า Web App ด้วย แต่พอถามว่าในสาย Production มีอะไรรันอยู่บ้าง คำตอบมักออกมาในแนว "Siemens S7, Mitsubishi SCADA แล้วก็… ไม่แน่ใจว่ามีอะไรอีก"

Read More
Standard Post with Image

Why Your Factory Floor Is the Softest Target in Your Network

Most security teams I talk to have reasonable IT hygiene: EDR on endpoints, a SIEM ingesting Windows event logs, maybe a WAF in front of the web apps. Then I ask them what’s running on the factory floor and the answer is usually some variation of "Siemens S7s, a Mitsubishi SCADA, and honestly we’re not […]

Read More
Standard Post with Image

你的员工有24个密码,你的企业就有24个攻击面

大多数企业不会意识到自身存在身份管理问题——直到安全事故发生之后。 离职员工的账户仍在三个系统中保持活跃,因为没有人更新离职操作清单。某外包人员能够访问财务门户,因为六个月前申请了"临时"访问权限,工单从未关闭。一次网络钓鱼攻击得逞——不是因为安全防护薄弱,而是因为团队在管理24套独立的登录系统,没有人注意到其中一个根本没有启用MFA。

Read More
Standard Post with Image

社員が24個のパスワードを持つ会社には、24個の攻撃経路がある

ほとんどの企業は、セキュリティ侵害が起きるまで自社のアイデンティティ問題に気づきません。

Read More
Standard Post with Image

พนักงานของคุณมี 24 รหัสผ่าน ธุรกิจของคุณมี 24 ช่องโหว่

บริษัทส่วนใหญ่ไม่รู้ว่าตัวเองมีปัญหาด้านการจัดการตัวตนดิจิทัล — จนกว่าจะเกิดเหตุ บัญชีพนักงานที่ลาออกยังค้างอยู่ในสามระบบ เพราะไม่มีใครอัปเดต Checklist การปิดบัญชี ผู้รับเหมาได้สิทธิ์เข้าถึง Portal ฝ่ายการเงิน เพราะต้องการสิทธิ์ "ชั่วคราว" เมื่อหกเดือนก่อนและไม่มีใครปิดใบงาน การโจมตี Phishing สำเร็จ — ไม่ใช่เพราะระบบรักษาความปลอดภัยบกพร่อง แต่เพราะทีมไอทีต้องดูแลระบบล็อกอิน 24 ระบบแยกกัน และไม่มีใครสังเกตว่าระบบหนึ่งไม่มี MFA

Read More
Standard Post with Image

Your Staff Have 24 Passwords. Your Business Has 24 Attack Surfaces.

Most companies don’t discover their identity problem until after the breach. A departing employee’s account stays active in three systems because nobody updated the offboarding checklist. A contractor gets access to the finance portal because they needed "temporary" access six months ago and the ticket was never closed. A phishing attack succeeds not because your […]

Read More