<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Wazuh on plumy devlog</title>
    <link>https://plumy.me/tags/wazuh/</link>
    <description>Recent content in Wazuh on plumy devlog</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <lastBuildDate>Tue, 02 Jun 2026 00:00:00 +0300</lastBuildDate>
    <atom:link href="https://plumy.me/tags/wazuh/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Homelab Part 11: Final pfSense Firewall Rules and Segmentation Hardening</title>
      <link>https://plumy.me/homelab/part-11/</link>
      <pubDate>Tue, 02 Jun 2026 00:00:00 +0300</pubDate>
      <guid>https://plumy.me/homelab/part-11/</guid>
      <description>I replace build-phase allow-any rules with explicit pfSense firewall policy for malware isolation, Windows clients, containers, honeypots, pentest access, and management paths.</description>
    </item>
    <item>
      <title>Homelab Part 7: Snort IDS and T-Pot Honeypot Telemetry</title>
      <link>https://plumy.me/homelab/part-7/</link>
      <pubDate>Thu, 28 May 2026 12:00:00 +0300</pubDate>
      <guid>https://plumy.me/homelab/part-7/</guid>
      <description>I add Snort IDS on pfSense, deploy T-Pot in the honeypot VLAN, forward honeypot logs into Wazuh, and fix decoder and query problems.</description>
    </item>
    <item>
      <title>Homelab Part 6: Wazuh SIEM Foundation</title>
      <link>https://plumy.me/homelab/part-6/</link>
      <pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate>
      <guid>https://plumy.me/homelab/part-6/</guid>
      <description>I stand up Wazuh in the SIEM VLAN, add the Docker host agent, enable Docker telemetry, and forward pfSense logs over syslog.</description>
    </item>
  </channel>
</rss>
