Skip to content

Category

Hardening

26 publications

Network Segmentation and Microsegmentation: A Defensive Strategy

Network Segmentation and Microsegmentation: A Defensive Strategy

How defenders use network segmentation and microsegmentation to stop lateral movement: zone design, enforcement, detection, and a safe rollout.

Read →
Database Hardening: PostgreSQL and MySQL in Production

Database Hardening: PostgreSQL and MySQL in Production

A defender's guide to hardening PostgreSQL and MySQL in production: authentication, network isolation, least privilege, encryption, and detection.

Read →
Windows Server Security Baseline for 2026: A Defender's Guide

Windows Server Security Baseline for 2026: A Defender's Guide

Build and enforce a Windows Server security baseline for 2026: identity hardening, protocol cleanup, credential protection, and the detections that catch drift.

Read →
MFA and Passkeys: Rolling Out Phishing-Resistant Auth

MFA and Passkeys: Rolling Out Phishing-Resistant Auth

A blue-team guide to phishing-resistant auth: why shared-secret MFA fails, how passkeys and FIDO2 work, and a safe rollout without weak fallbacks.

Read →
Ransomware Resilience: Backups, Segmentation and Recovery

Ransomware Resilience: Backups, Segmentation and Recovery

A blue-team guide to surviving ransomware: the kill chain, network and identity segmentation, immutable isolated backups, and a recovery plan you rehearse.

Read →
Object Storage Security: Locking Down S3 and Buckets

Object Storage Security: Locking Down S3 and Buckets

Blue-team guide to hardening S3 and cloud buckets: how exposure happens, detection signals to watch, and mitigation from public-access blocks to backups.

Read →
Cloud IAM Least Privilege on AWS, Azure and GCP: A Defender's Guide

Cloud IAM Least Privilege on AWS, Azure and GCP: A Defender's Guide

Practical least-privilege for cloud IAM: how over-permissioning enables escalation, how to spot risky access, and a checklist for AWS, Azure and GCP.

Read →
DNS Security for Defenders: DNSSEC, DoH and Registrar Hardening

DNS Security for Defenders: DNSSEC, DoH and Registrar Hardening

How to defend the DNS layer: what DNSSEC and encrypted DNS actually protect, how to detect hijacking and cache poisoning, and a registrar hardening checklist.

Read →
Email Authentication Explained: SPF, DKIM and DMARC for Defenders

Email Authentication Explained: SPF, DKIM and DMARC for Defenders

A defender's guide to SPF, DKIM and DMARC: how each control works, how to detect spoofing in your reports, and a hardening checklist to lock down your domain.

Read →
Secrets Management with a Vault: Patterns and Pitfalls

Secrets Management with a Vault: Patterns and Pitfalls

A defender's guide to secrets management: what a vault provides, dynamic secrets, audit telemetry, rotation, and the pitfalls that quietly undo it.

Read →
TLS, PKI and Certificate Management Done Right

TLS, PKI and Certificate Management Done Right

How defenders can run TLS and PKI without outages or weak links: the chain of trust, lifecycle automation, detection signals, and a hardening checklist.

Read →
Zero Trust Network Architecture in Practice

Zero Trust Network Architecture in Practice

A defender's guide to Zero Trust: identity-first access, microsegmentation, the telemetry that proves it works, and a hardening checklist you can act on.

Read →
Active Directory Tiering and Privileged Access Design

Active Directory Tiering and Privileged Access Design

How Active Directory tiering and privileged access design contain lateral movement: the tier model, clean sources, PAWs, just-in-time access, detection.

Read →
Container and Docker Image Security End to End

Container and Docker Image Security End to End

Secure the whole container lifecycle: base images, builds, signing, scanning, registry and runtime controls, with detection signals and a defender checklist.

Read →
Kubernetes Security Hardening: A Practical Baseline

Kubernetes Security Hardening: A Practical Baseline

A practical Kubernetes hardening baseline for defenders: control plane, RBAC, workload and network controls, plus detection signals and a checklist.

Read →
AppSec Shift-Left: SAST, SCA and Secrets Scanning Without Slowing the Team

AppSec Shift-Left: SAST, SCA and Secrets Scanning Without Slowing the Team

How Basilisk OffSec rolls out AppSec gradually, measuring developer friction and avoiding the permanently red pipeline nobody bothers to read.

Read →
Windows Persistence: 10 Documented Techniques and Their Countermeasures

Windows Persistence: 10 Documented Techniques and Their Countermeasures

Defensive catalog of 10 Windows persistence mechanisms with ready-to-run KQL hunting queries and hardening measures any SOC can deploy this week.

Read →
Windows 11 Hardening for High-Risk Offensive Security Workstations

Windows 11 Hardening for High-Risk Offensive Security Workstations

Battle-tested Windows 11 hardening recipe with ASR, Credential Guard, AppLocker and WDAC deployed across Basilisk offensive analyst laptops.

Read →
Supply Chain Security: Sigstore Signing and Real SBOMs in CI/CD

Supply Chain Security: Sigstore Signing and Real SBOMs in CI/CD

How Basilisk ships cosign, SLSA, and CycloneDX across real pipelines to blunt SolarWinds-style attacks, XZ Utils backdoors, and dependency confusion.

Read →
Linux Server Hardening: Applying CIS Benchmark Without Breaking Production

Linux Server Hardening: Applying CIS Benchmark Without Breaking Production

How to apply the CIS Benchmark on production Debian and Ubuntu hosts by validating each control, measuring impact, and keeping SLA intact without an all-night rollback.

Read →
AMSI and ETW Bypass for Defensive Research: What Blue Teams Should Know

AMSI and ETW Bypass for Defensive Research: What Blue Teams Should Know

Honest technical breakdown of how public AMSI and ETW bypasses work, and how defenders can harden Windows telemetry without looking foolish.

Read →
Ethical OSINT: Investigating Your Own Digital Footprint with Maltego and Spiderfoot

Ethical OSINT: Investigating Your Own Digital Footprint with Maltego and Spiderfoot

Before a stalker, hostile recruiter, or data broker finds you, do the work yourself. Maltego and Spiderfoot turn public fragments into a personal attack map.

Read →
SELinux Without Fear: Custom Policies for Critical Services

SELinux Without Fear: Custom Policies for Critical Services

From audit2allow forensics to versioned policy modules running in production, without falling into permanent permissive mode.

Read →
SSH Hardening 2026: Algorithms, Certificates and Bastion Hosts

SSH Hardening 2026: Algorithms, Certificates and Bastion Hosts

Modern SSH configuration with an internal CA, resistant algorithms and auditable bastion hosts to shrink the attack surface in corporate environments.

Read →
Linux Application Sandboxing with Bubblewrap, Firejail and Flatpak

Linux Application Sandboxing with Bubblewrap, Firejail and Flatpak

How the Basilisk team isolates browsers, PDF readers and risky tools on Linux desktops using audited, reproducible sandbox profiles.

Read →
macOS Hardening: Lockdown Mode, MDM and Attack Surface Reduction

macOS Hardening: Lockdown Mode, MDM and Attack Surface Reduction

Defensive configurations on Apple Silicon for journalists, activists and researchers facing well-funded state or commercial adversaries.

Read →