<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Zehra Begum</title>
    <description>The latest articles on DEV Community by Zehra Begum (@zehra_begum_5b8656de724aa).</description>
    <link>https://dev.to/zehra_begum_5b8656de724aa</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4148352%2F106f503e-d3e2-4aff-a4a4-a0ef0ab21385.png</url>
      <title>DEV Community: Zehra Begum</title>
      <link>https://dev.to/zehra_begum_5b8656de724aa</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zehra_begum_5b8656de724aa"/>
    <language>en</language>
    <item>
      <title>Ox2A Security Blog</title>
      <dc:creator>Zehra Begum</dc:creator>
      <pubDate>Tue, 29 Sep 2026 02:57:30 +0000</pubDate>
      <link>https://dev.to/zehra_begum_5b8656de724aa/ox2a-security-blog-4i1h</link>
      <guid>https://dev.to/zehra_begum_5b8656de724aa/ox2a-security-blog-4i1h</guid>
      <description>&lt;p&gt;Testing Windows Defender and Wazuh with Atomic Red Team&lt;br&gt;
Posted on septemper, 28 by Zehra Begum&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Introduction &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Building my first SIEM deployment  hands-on  cybersecurity journey with log aggregation, network visibility, and threat detection. I cover how I stood up and modified a baseline SIEM environment, encountered a few real-world misconfigurations along the way, and ran attack commands using Atomic Red Team (ART) to see how those activities surfaced in our logs.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Whoami&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;My name is a Zehra Begum, and i am field to specialize in network security and threat detection. This post represents my very first contribution to the cybersecurity community—I hope sharing my process, mistakes, and findings helps other aspiring analysts on a similar path!&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Setup &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Configured log shipping agents and adjusted system files (e.g., modifying &lt;code&gt;/etc/rsyslog.conf&lt;/code&gt; or agent config files) to capture enhanced host and network telemetry.&lt;/p&gt;




&lt;ol&gt;
&lt;li&gt;Experiment time! &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Experiment #1 T1053.005:Scheduled Task&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Test SIEM detection against persistence techniques T1053.005. Running command Atomic tests on Ad01 verifies events trigger expected alert rules in Wazuh.&lt;/p&gt;

&lt;p&gt;![[Pasted image 20260928221650.png]]&lt;/p&gt;

&lt;p&gt;Experiment #2 T1027: Obfuscated Files or Information&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Registry modification detection (Sysmon Event ID 1 &amp;amp; Event ID 13 When altering Windows registry keys.&lt;/p&gt;

&lt;p&gt;Experiment #3 T1078: Valid Account&lt;br&gt;
  Test SIEM detection against persistence and privilege abuse techniques using T1078 (Valid Accounts). This experiment verifies whether administrative or newly created account logons, privilege escalations, or account modifications trigger the expected detection rules and alerts in Wazuh.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Conclusion &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Running these experiments highlighted the direct connection between endpoint configuration and SIEM visibility: without proper log verbosity, critical attack vectors remain invisible.&lt;/p&gt;

&lt;p&gt;To avoid similar issues:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Always validate configuration syntax and service status before testing log ingestion.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Ensure host-level auditing policies (such as Auditd or Sysmon) are properly enabled to capture process execution and command-line arguments.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Final thoughts 
&lt;strong&gt;Coolest Thing Learned:&lt;/strong&gt; Seeing raw adversary actions executed via Atomic Red Team instantly transform into structured alerts and structured log fields inside the SIEM dashboard.
Don't panic when logs don't show up immediately. Systematically isolate the path from event creation $\rightarrow$ local agent capture $\rightarrow$ network transport $\rightarrow$ SIEM ingestion.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;6.Refrences&lt;br&gt;
 Wazuh Documentation&lt;br&gt;
 Atomic RED Team Work Station&lt;br&gt;
 MITRE ATT&amp;amp;CK Techique Reference&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
  </channel>
</rss>
