I purchased a mini PC from Amazon and installed OPNsense on it. Enabled a massive geo-ip block firewall rule (fuck Russia, China, DPRK, and all ITAR restricted countries), downloaded several hosts blocks that Unbound can use as a DNS sinkhole and force every device i own to use that mini PC as the DNS as well as the IPS/IDS of my entire network by sitting between my wifi router and modm to intercept all network activity. I have also installed SecurityOnion on another PC that acts as a log aggregate for every device on my network and use it as a SIEM to track malware and possible malicious pivoting based on MITRE att&ck framework and finally I have Wazuh agents installed on any host that allows it to track any malware that wants to enable command & control of any of my devices.
this post was submitted on 01 Feb 2024
15 points (100.0% liked)
No Stupid Questions (Developer Edition)
14 readers
1 users here now
This is a place where you can ask any programming / topic related to the instance questions you want!
For a more general version of this concept check out !nostupidquestions@lemmy.world
Icon base by Lorc under CC BY 3.0 with modifications to add a gradient
founded 1 year ago
MODERATORS