<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Wazuh on Pratik’s Localhost</title><link>https://pratikdabhi.in/tags/wazuh/</link><description>Recent content in Wazuh on Pratik’s Localhost</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>pratik.dabhi.4u@gmail.com (Pratik)</managingEditor><webMaster>pratik.dabhi.4u@gmail.com (Pratik)</webMaster><lastBuildDate>Sun, 13 Sep 2026 17:00:00 +0530</lastBuildDate><atom:link href="https://pratikdabhi.in/tags/wazuh/index.xml" rel="self" type="application/rss+xml"/><item><title>Protecting GitLab as a Crown Jewel: Security Logs, Dashboards, and Alerts with Wazuh</title><link>https://pratikdabhi.in/posts/gitlab-authentication-wazuh/</link><pubDate>Sun, 13 Sep 2026 17:00:00 +0530</pubDate><author>pratik.dabhi.4u@gmail.com (Pratik)</author><guid>https://pratikdabhi.in/posts/gitlab-authentication-wazuh/</guid><description>&lt;p&gt;For an organization that builds software, GitLab can be one of its crown jewels. It may hold proprietary source code, internal architecture, deployment configuration, and customer information in issues, attachments, or repository files. Depending on permissions and how delivery is configured, access to GitLab can also provide a way to change what the organization builds and deploys.&lt;/p&gt;</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://pratikdabhi.in/posts/gitlab-authentication-wazuh/featured.png"/></item><item><title>From IOC Lists to Firewall Blocks: Building a Threat Feed Pipeline Without a Paid Subscription — Part 2</title><link>https://pratikdabhi.in/posts/threat-feed-indicators-part-2/</link><pubDate>Sat, 08 Aug 2026 00:00:00 +0530</pubDate><author>pratik.dabhi.4u@gmail.com (Pratik)</author><guid>https://pratikdabhi.in/posts/threat-feed-indicators-part-2/</guid><description>&lt;div class="lead text-neutral-500 dark:text-neutral-400 !mb-9 text-xl"&gt;
 &lt;p&gt;The first post ended with a blind spot.&lt;/p&gt;
&lt;p&gt;Pramaan, an Argusoft SaaS application, was publishing the feed.
Sophos was consuming it.
The firewall was dropping known-bad traffic on the paths where threat-feed evaluation actually applied.&lt;/p&gt;</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://pratikdabhi.in/posts/threat-feed-indicators-part-2/featured.png"/></item></channel></rss>