Stack
The software we will run. Named, including the exception.
This is the chosen set. It is not running for a client today. The first install is internal: our own mail, our own laptops, a restore test, then a client. We are not affiliated with or endorsed by these projects.
Three limits that stay on this page
Windows blocking antivirus is Microsoft Defender
We manage Defender on Windows endpoints in the order. No open-source product is standing in for a blocking antivirus. Defender is Microsoft software, on the firm’s Microsoft license. If that license cannot do what we need, we say so before we pretend it can.
Microsoft 365 detection is not instant
Audit logs can lag 60 to 90 minutes. We do not promise to see an account takeover the moment it happens. Automatic response means: when the log shows a takeover, revoke the session and remove the malicious inbox rule. It does not rewind the lag, and it does not disable every account we feel uneasy about. Broader containment still follows the responsibility matrix. Google Workspace does not get that automatic pair of actions until we have built it.
Scanners, decoys, and tests stay inside a scope
OpenVAS, Nuclei, OpenCanary, and Atomic Red Team can look like an attack if they are pointed at the wrong place. Atomic Red Team stays in our lab unless a written test window says otherwise. Scans and decoys happen only where the order allows them.
Endpoint, logs, and detections
Wazuh
Endpoint monitoring and the SIEM. The index is OpenSearch-based, the one Wazuh ships.
Before any client. On our own machines first.
Vector
The pipeline that carries logs into that index. Endpoint agents are not the only way data arrives.
With the first log source that is not the Wazuh agent.
Sigma and YARA-X
Detections we maintain: Sigma for log behavior, YARA-X for files and malware we choose to name.
Tested in the lab before they page a client.
Microsoft Defender
The blocking antivirus on Windows. We manage it. It is not open source. We will not pretend an open-source AV does this job.
On every Windows machine in the order, using the Microsoft license the firm already has.
Velociraptor
Investigation and response on a specific machine: collect, hunt, and contain when the case needs more than the alert.
Server ready early. Used when a case calls for it.
Cases, automation, and intel
DFIR-IRIS
Case management. What we saw, what ran automatically, what a person did, and who authorized it.
Before the first client, because the first alert needs a file.
Shuffle
Automation for steps we have already decided, including the Microsoft 365 responses below. If Shuffle is down, a person still owns the case.
With the Microsoft 365 response, not as a toy workflow.
MISP
Threat intelligence we actually use. An empty intel server is not something we advertise.
After real indicators are worth keeping.
Identity and posture
Microsoft 365 account takeover
Detection of a mailbox takeover, then an automatic response: revoke the session and remove a malicious inbox rule. Microsoft audit logs can lag 60–90 minutes, so this is not instant. The same automatic actions are not promised on Google Workspace until we have built and tested them.
With Managed ITDR, and only if the order leaves this authority in place.
ScubaGear and Maester
Microsoft 365 and Entra posture checks. They are baselines and tests, not a certification.
With the M365 posture review.
Prowler
Cloud posture, and the Google Workspace side of the review. ScubaGear does not cover Google.
When the firm has Google Workspace or a cloud account in scope.
Exposure
Greenbone OpenVAS and Nuclei
Vulnerability scanning inside a written scope. Not part of the free assessment, and not a surprise scan.
After the scanners work in the lab, on the cadence the order names.
Falco
Runtime detection for Linux and cloud workloads the firm actually runs. A Windows-only office does not get a pretend Falco deployment.
Only where those workloads exist.
OpenCanary
Decoys placed with the firm: something that should never be touched, and that opens a case when it is.
When the firm agrees to a place to put one.
CrowdSec
Reputation and blocking on paths we operate, starting with our own edge.
With the first public host we run.
AdGuard Home
DNS filtering where the firm’s DNS actually points at us. We cannot filter a resolver we do not sit on.
Only when the order moves DNS.
Coraza and OWASP CRS
A web application firewall on traffic that passes through something we operate. A site hosted entirely at someone else’s vendor is not behind this WAF unless we are placed there.
Only when we are in that path.
Practice
GoPhish fork
Phishing training on a fork we maintain, on its own host and sending domain. Upstream GoPhish has not endorsed us.
Before the first simulation. Never on the detection servers.
CISO Assistant
Compliance-oriented reports from findings we actually have. A report is not a certification, and it does not make the firm compliant.
When the monthly letter needs that shape. Not before we have findings.
Atomic Red Team
How we test our own detections in a lab. Not an unscheduled attack on a client.
In the lab, before those detections are trusted.
The stack is not the contract.
An assessment names what the firm already has. The order names which of these tools actually get installed, and which authorities we do not have.
Book an assessment