Blog Entries

14. 03. 2025 Daniel Degasperi Blue Team, Log-SIEM, SEC4U

A Practical Approach to Detect Suspicious Activity in MS SQL Server

This article gives an overview and offers a practical tips to detecting some suspicious activities in Microsoft SQL Server, from configuring audit policies to leveraging Elastic for effective monitoring and threat detection. Introduction Microsoft SQL Server is one of the most widely used relational databases in the enterprise landscape, managing critical data and supporting essential…

Read More
12. 03. 2025 Alessandro Mizzaro Bug Fixes, NetEye

NetEye 4 – Security Advisory

Important: GeoMap update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic An update for the package icingaweb2-module-geomap is now available for NetEye 4. Security Fix for NetEye 4.40 CVSSv3.1: 7.3(High) – CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N For a detailed overview of the security issue(s), including the impact, CVSS score, acknowledgments, and other relevant information, please…

Read More
10. 03. 2025 Alessandro Mizzaro Bug Fixes, NetEye

NetEye 4 – Security Advisory

Important: Elastic Stack security update (installed with SIEM) Type/Severity NetEye Product Security has rated this update as having a Critical security impact. Topic An update for the package kibana is now available for NetEye 4. Security Fix for NetEye 4.40 CVSSv3.1: 9.9(Critical) – CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H For a detailed overview of the security issue(s), including the impact, CVSS score, acknowledgments,…

Read More
04. 03. 2025 Alessandro Valentini Automation, DevOps, Service Management

Group-aware Reboot with Ansible

Use Case During NetEye Cloud updates we typically have to handle 25+ nodes, updating both OS and Firmware and subsequently rebooting all servers, all without causing downtime. We can of course reboot one node a time, but this would be really time-consuming. The main constraints on reboot are PCS nodes and Elastic layers. In particular…

Read More
28. 02. 2025 Charles Callaway Documentation

Explaining Your Content with Complex Animations, Part 3

Welcome back! Last time we looked at some concrete examples of animations where you can use math to animate large numbers of objects, field-like effects, or complex behavior. Today let’s look at the principal barrier to using an animation you make (if it’s not a filled rectangle and if you want to put it in…

Read More
26. 02. 2025 Alessandro Taufer Bug Fixes, NetEye

Bug Fixes for NetEye 4.40

Fix for icinga2 satellites zone validation Fixed an issue with the icinga2 satellites zone validation that caused the neteye satellite config create to fail if one of the icinga2-zone is a sub-string of the others List of updated packages To solve the issue, the following packages have been updated

Read More
26. 02. 2025 Alessandro Mizzaro Bug Fixes, NetEye

Bug Fixes for NetEye 4.40,4.39 and 4.38

Remove “Drop non-existing group during Sync” on LDAP user federations Remove flag “Drop non-existing group during Sync” on LDAP user federations List of updated packages To solve the issue, the following packages have been updated: keycloak, keycloak-autosetup, keycloak-configurator, keycloak-python, to versions:

Read More
22. 02. 2025 Simone Ragonesi Automation, DDoS, Offensive Security, Red Team

Building a Distributed DDoS Infrastructure for Red Teaming Campaigns

⚠️ Warning: This article is intended for educational and ethical purposes only ⚠️ Red teamers don’t often engage in DDoS campaigns or stress testing against client systems, mainly for two reasons: However, there are cases where clients explicitly request such activities. When that happens, the red team must be thoroughly prepared; both legally, to clearly…

Read More
22. 02. 2025 Alessandro Mizzaro Bug Fixes, NetEye

NetEye 4 – Security Advisory

Important: IcingWeb2 Module Analytics security update Type/Severity NetEye Product Security has rated this update as having a Medium security impact. Topic An update for the package icingaweb2-module-analytics is now available for NetEye 4. Security Fix for NetEye 4.40 CVSS: 6.3 (medium): CVSS3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N For a detailed overview of the security issue(s), including the impact, CVSS score, acknowledgments, and other…

Read More
20. 02. 2025 Alessandro Mizzaro Bug Fixes, NetEye

NetEye 4 – Security Advisory

Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a security impact of High Topic An update for the package glpi is now available for NetEye 4. Security Fix for NetEye 4.40 For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…

Read More
18. 02. 2025 Alessandro Mizzaro Bug Fixes, NetEye

Bug Fixes for NetEye 4.40

Fix for after-login redirect in IcingaWeb2 Fixed an issue with the post-login redirect that, in cases of session expiration, would cause navigation to an incorrect page after re-authentication. List of updated packages To solve the issue, the following packages have been updated

Read More
17. 02. 2025 Franco Federico Unified Monitoring

Monitoring Printer Logs

A customer recently asked me to monitor printer logs. His use case was to check which users were doing the printing, and what they were printing on the company’s printers, including their page numbers. The printers in question had SNMP available, but didn’t provide this particular information. In addition, the printers didn’t have an API…

Read More
13. 02. 2025 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.40

Renewed Elastic Enterprise License We renewed the Elastic Enterprise license, which was originally scheduled to expire on February 28, 2025. The new expiration date is now February 28, 2026. If your NetEye version is older than 4.39 and you wish to utilize the Elastic Enterprise license, you will need to upgrade to at least NetEye…

Read More
13. 02. 2025 Damiano Chini Bug Fixes, NetEye

Bug Fixes for NetEye 4.39

Renewed Elastic Enterprise License We renewed the Elastic Enterprise license, which was originally scheduled to expire on February 28, 2025. The new expiration date is now February 28, 2026. If your NetEye version is older than 4.39 and you wish to utilize the Elastic Enterprise license, you will need to upgrade to at least NetEye…

Read More
11. 02. 2025 Mattia Codato Development, Events, NetEye

Podman Quadlet: Simplifying Container Management with systemd

Just like last year, we had the wonderful opportunity to attend FOSDEM, the most important open source conference in Europe. This year was no exception, and among the many exciting talks, one that particularly caught my attention was Alex Stefanini’s presentation on Podman Quadlet. Integrated with Podman since version 4.4, Quadlet has emerged as a…

Read More

Archive