{
  "id": 10592987,
  "title": "Ox2A Security Blog",
  "url": "https://urgent.news/2026/09/29/ox2a-security-blog",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T02:57:30.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/zehra_begum_5b8656de724aa/ox2a-security-blog-4i1h"
  },
  "original_language": "en",
  "account": "Zehra Begum, a cybersecurity specialist in network security and threat detection, shared her first contribution to the cybersecurity community in her testing of Windows Defender and Wazuh with Atomic Red Team. The post focused on how she built and modified a baseline SIEM environment, encountered misconfigurations, and ran attack commands using ART to observe the results in logs.\n\nIn the setup, Zehra configured log shipping agents and adjusted system files to capture enhanced host and network telemetry. The experiments included testing SIEM detection against various persistence techniques, such as scheduled tasks (T1053.005), obfuscated files or information registry modifications (T1027), and valid accounts (T1078).\n\nThe experiments revealed the direct link between endpoint configuration and SIEM visibility, emphasizing the importance of proper log verbosity. To prevent similar issues, Zehra advised validating configuration syntax and service status, ensuring host-level auditing policies are correctly enabled for process execution and command-line arguments.\n\nZehra concluded that the most valuable lesson was observing raw adversary actions executed via Atomic Red Team, instantly transforming into structured alerts and log fields inside the SIEM dashboard. She encouraged aspiring analysts not to panic if logs don't appear immediately, and to systematically isolate the path from event creation to SIEM ingestion.",
  "summary": "Testing Windows Defender and Wazuh with Atomic Red Team Posted on septemper, 28 by Zehra Begum Introduction Building my first SIEM deployment hands-on cybersecurity journey with log aggregation, network visibility, and threat detection. I cover how I stood up and modified a baseline SIEM environment, encountered a few real-world misconfigurations along the way, and ran attack commands using…",
  "key_points": [
    "Zehra Begum tested Windows Defender and Wazuh with Atomic Red Team.",
    "Configured SIEM environment to capture enhanced host and network telemetry.",
    "Observed raw adversary actions transforming into structured alerts in SIEM."
  ],
  "editors_take": "This experiment highlights the crucial role of proper endpoint configuration and log verbosity in enhancing SIEM visibility, and underscores the importance of validating configuration syntax to ensure effective threat detection.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}