Vedran Dojčinović

Writing

Posts

2 posts, newest first. Browse by ATT&CK technique or by tag below.

blue-team 2detection-engineering 2wazuh 2active-directory 1cdsa 1hack-the-box 1kerberos 1mitre-attack 1soc 1splunk 1

What the SOC Analyst path actually taught me — running my own SIEM alongside it

Going through HTB's SOC Analyst path while running a purple team lab changed what stuck. The detections aren't the point. Seeing where they break is.

Detecting Kerberoasting with Wazuh

The rule is six lines of XML. The part that actually mattered was a query I ran before writing any of it.