Dr. Maik Ro @maikroservice.com · 02/07/2026Anyone else’s Claude get a little too oldschool with agent names recently? 010
Dr. Maik Ro @maikroservice.com · 16/12/2025Love it! There is an issue with the email field though, made it hard(er) to sign up How do you do so many things at once btw? :D I feel like every month you publish a banger new project 110
Dr. Maik Ro @maikroservice.com · 03/12/2025It has an associated IP address, a username that should be used for the ssh connection and the private key needed to initiate the connection with that out of the way we can run the command from earlier: ansible -i hosts.yml infrastructure -a 'ping 192.168.188.1 -c 1' 110
Dr. Maik Ro @maikroservice.com · 03/12/2025WAIT - STOP - HOLD ON what is inside the hosts.yml and what is a yml in the first place? a .yml file is a yaml (Yet Another Markup Language) file 110
Dr. Maik Ro @maikroservice.com · 03/12/2025fear not - that is totally expected - your key is well “hidden” in the authorized keys - open that one and find out: aha - ok that looks like the correct key with the correct username at the end 😌 110
Dr. Maik Ro @maikroservice.com · 03/12/2025GREAT! can we check if the key is really there? sure! but um… this does not look like it is there? 110
Dr. Maik Ro @maikroservice.com · 03/12/2025you type: ssh-copy-id -i <location_of_your_ssh_key> username@controlled-machine press enter and then you need to enter the password for the controlled-machine user if all goes well you see something similar to the following image: 110
Dr. Maik Ro @maikroservice.com · 03/12/2025now generate a private key on your host machine with ssh-keygen -b 4096 make sure to enter the correct location and add a passkey if you care about security 🙏 110
Dr. Maik Ro @maikroservice.com · 03/12/2025cool cool cool - what now? now you need to identify how you can connect to the controlled machine - e.g. via ssh if it is linux that means ssh needs to run on the controlled machine - check via: systemctl status ssh 120
Dr. Maik Ro @maikroservice.com · 03/12/2025smash that y button and the enter key right afterwards and then wait until the install is finished ⏳ → ⌛️ 110
Dr. Maik Ro @maikroservice.com · 03/12/2025First, install ansible on your host machine via: sudo apt-get install ansible (if your host is debian/ubuntu based) 110
Dr. Maik Ro @maikroservice.com · 22/11/2025Look at that pretty face, anyone having a bad day just look into his eyes and get hypnotized 😍 150
Dr. Maik Ro @maikroservice.com · 29/07/2024Your new favorite Cheatsheet - Threat Hunting w/ Windows 🪟 + osquery osquery provides a powerful SQL interface that you can use to hunt adversaries in your network. Coupled with fleet management software like fleetdm / zentral, it allows you to query all your endpoints at once! 💜💜💜 #hacking 021
Dr. Maik Ro @maikroservice.com · 17/09/2023So what happens when we run klist now? We can see our TERMSRV ticket 💙 🎫 NOW THAT IS WHAT I AM TALKING ABOUT 🥳🥳🥳 100
Dr. Maik Ro @maikroservice.com · 17/09/2023All you need to do is open a powershell window - type: mstsc /remoteguard This will again open the RDP connection window, but when you connect it stops the login process on the remote machine. Plus, apparently it stops tickets from being forwarded - thx @powerpointken 100
Dr. Maik Ro @maikroservice.com · 17/09/2023When we run klist again we can see not one but two tickets! but ummm … this one is not for the TERMSRV?! Where is the TERMSRV Ticket?! That is a very good question. 100
Dr. Maik Ro @maikroservice.com · 17/09/2023Now you start the RDP tool, type away the computer and username you want to connect with and press that big “Connect” button at the bottom. What would you expect now? More tickets, right?! 100
Dr. Maik Ro @maikroservice.com · 17/09/2023The command “klist” lists all the tickets currently stored in memory (RAM) of the machine Before the RDP session is started there is only one ticket on my machine - this is asked for when you login with the domain account. 100
Dr. Maik Ro @maikroservice.com · 17/09/2023This is the so called TGT request and if all goes well we receive a TGT from the domain controller. That one in hand (well technically it is in memory 😅) we can now ask for a service ticket. The service we want to connect to is called “TERMSRV” or Terminal Server 100
Dr. Maik Ro @maikroservice.com · 17/09/2023When you click on the AS-REQ packet you can see that the computer I am currently on workstation02 sends a request to the domain controller dc01 with my username attached. 100
Dr. Maik Ro @maikroservice.com · 17/09/2023We first request a Ticket Granting Ticket (TGT) for the user we want to connect with - this is our Authentication Service Request (AS-REQ) We can see that in Wireshark when filtering for “kerberos” and looking at the “Info” column 100
Dr. Maik Ro @maikroservice.com · 17/09/2023Next you will be asked for your username and you need to use either domain\username or username@domain - if you don’t, this process uses NTLM and NOT kerberos. If you want to follow make sure to run wireshark at least on the domain controller to see the ticket workflows 100
Dr. Maik Ro @maikroservice.com · 17/09/2023We type the FQDN of the machine we want to connect to: workstation01.snackempire.home and push the Connect button. 🏎️💭 100
Dr. Maik Ro @maikroservice.com · 12/09/2023Once that is done you will see the something similar to the following screenshot. 🎈CONGRATULATIONS 🎈 You installed your Security Information and Event Management System in your HomeLab 🎉 You dont have any agents yet but we will walk through the setup in the next 🧵 100
Dr. Maik Ro @maikroservice.com · 12/09/2023After login wazuh will check for updates and do some sanity checks for your detection rules 100
Dr. Maik Ro @maikroservice.com · 12/09/2023Now comes the final step! In your browser - navigate to the IP of the VM and you should see this: 100
Dr. Maik Ro @maikroservice.com · 12/09/2023After the install process is finished you will see a password and username inside your terminal Save it to a secret location (password manager cough ) 100
Dr. Maik Ro @maikroservice.com · 12/09/2023After the login you visit in your browser Next, copy the installation command: paste it into our terminal, enter the sudo password and watch the magic happen 🦄🪄 100
Dr. Maik Ro @maikroservice.com · 12/09/2023Software - just skip it, we will install it later and now the install starts - once that is done reboot and login. 100
Dr. Maik Ro @maikroservice.com · 12/09/2023Now select the correct disk and select "use entire disk" - if you prefer to have encrypted disks also choose this option and type the password twice then continue and commit to the installation - you now need to enter your username etc. NEXT - openssh, you dont need it now 100
Dr. Maik Ro @maikroservice.com · 12/09/2023On the next screen you choose "Ubuntu Server" so that you can have a comfortable experience After that its time to select the correct network interface - hit that space key again! and then again for the proxy address (unless you have one) + mirror address 100
Dr. Maik Ro @maikroservice.com · 12/09/2023You select your favorite Language and come to this screen next - you select "Update to the new installer" with the arrow keys and click your "space" key to continue. Next up you choose the correct layout of your keyboard (you can use the "identify your keyboard" function) 100
Dr. Maik Ro @maikroservice.com · 12/09/2023Installation - You start your SIEM Journey with the Start Button of the VM press enter and let the adventure begin 🚀 100
Dr. Maik Ro @maikroservice.com · 12/09/2023Becoming a (better) SOC analyst 💙 How to build your own SIEM for your HomeLab: 120
Dr. Maik Ro @maikroservice.com · 30/08/2023How it started - one year ago I was at ~300 followers - each post had 10 likes max. Today - posts reach around 100k views and 3-4% engagement = 3k-4k!!! people interact with EACH post 🤯 Play the long game. It will pay off. Thanks 2 you! 000
Dr. Maik Ro @maikroservice.com · 28/08/2023Practical SOC Analyst 101 Roadmap💙 I talked to SOC Professionals which skills someone would need to be hired as a SOC Analyst and these skills made it onto the roadmap. It doubles as the outline for my SOC Analyst 101 course. Save your spot now at: academy.maikroservice.com/l/soc101 000
Dr. Maik Ro @maikroservice.com · 28/08/2023Security is always a tradeoff. There is a magical triangle in most of the world Quality Price Time You CANNOT choose all 3… 2 if you are lucky 🍀 but often only a SINGLE ONE 1️⃣ is a valid option 010
Dr. Maik Ro @maikroservice.com · 24/08/2023You will see (and can edit) all the attacks/checks that are performed: DOM Based XSS .htaccess information leak Forced Directory Browsing (#fuzz) ELMAH Information Leak Source Code Disclosure Buffer Overflow CRLF Injection SQL Injection and many more. 100
Dr. Maik Ro @maikroservice.com · 24/08/2023If you want to know what exactly the active scan does - you can look at the Scan Policy Manager (bottom left corner) Then select the Default Policy and click "Modify" 100
Dr. Maik Ro @maikroservice.com · 24/08/2023One thing to remember! DO NOT - I repeat DO NOT use this on websites that you do not either own or have permission to scan. In some countries this is illegal. Lucky for us, we are hosting the website ourself so we are on the legal side. 100
Dr. Maik Ro @maikroservice.com · 24/08/2023ZAP finds 84 links/sites and adds 63 nodes - you can see them on the left side under "Sites" New folders we did not know about before: admin comment core filter node profiles search sites themes user 100
Dr. Maik Ro @maikroservice.com · 24/08/2023Now "Start Scan" and watch it go BRRRRRRRRR (Your Starting Point URL might be different) 110
Dr. Maik Ro @maikroservice.com · 24/08/2023Now we hack - we right click the URL in the ZAP "Sites" and select "Attack -> Spider" 100
Dr. Maik Ro @maikroservice.com · 24/08/2023second - you will see the login screen of farmOS if all went well. use the default credentials, or a login you create and see the magic happen You are logged in and ZAP shows the login (POST:/()...) + the login check 100
Dr. Maik Ro @maikroservice.com · 22/08/2023Once that is done you will see the something similar to the following screenshot. 🎈CONGRATULATIONS 🎈 You installed your Security Information and Event Management System in your HomeLab 🎉 You dont have any agents yet but we will walk through the setup in the next 🧵 100