Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Niclas

@niclas@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

#sysadmin #devops #devsecops #cybersecurity #honeypot #privacy #homelab #firewall #monitoring #selfhosting #logs #metrics #securityengineering

16 Followers
35 Following
14 Posts
Joined July 29, 2025
GitLab:
https://gitlab.com/niclasheinz
GitHub:
https://github.com/niclasheinz
Website:
https://nheinz.eu
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

After quite some time, I finally have all the pieces in place. Over the last 30 minutes, I’ve set up one of my servers from scratch. Here are some key changes:
- Reverse Proxy: Nginx with Modsecurity (WAF)
- Container Isolation: Every container runs in a seperate linux user
- Podman Quadlet: I rewrote all my compose stacks into quadlet files - now all containers are starting probably after reboot 🥳
- Grafana: Grafana's configuration is no managed by Opentofu which provitions at the moment the datasources (Grafana Loki and Prometheus) as well as the dashboards.
- Server hardening: Improved ssh configuration, firewall, permissions in general on this host
- Ansible: Everything is powered by ansible
- Certbot: Use wildcard certificates for my domains / subdomains for easier renew process
- Backups: All those services have proper backups configured which are timed with systemd timer and are replicated into my local homelab.
- Services that are running at the moment
- Grafana
- Prometheus
- Grafana Loki
- Grafana Alloy
- GitLab Runner
- some other services that I wanna migrate to this server

#homelab #sysadmin #linux #ansible #automation #devsecops #selfhosting #declarative #gitops #monitoring

infosec.exchange

Infosec Exchange

7
0
2
0
Open post
Niclas @niclas@infosec.exchange
· 2mo ago
Since March 2026, I have been running honeypots on the internet to collect data and analyze attack patterns. The amount of data stored in the log database has steadily increased over the past few months and has now reached 70 GB of raw logs. I may need to consider a better archiving strategy, especially since I am thinking about adding a T-Pot instance, which would significantly increase the load on the current database setup. #honeypot #postgresql #sysadmin #cybersecurity #blueteam
1
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

Now I get notified when my certificates are expiring before everything breaks.

#monitoring #observability #certificates #grafana #selfhosting #sysadmin

infosec.exchange
4
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 3mo ago
What are you using as a Web Application Firewall in Kubernetes Environments with a traefik ingress controller? #kubernetes #traefik #selfhost #homelab #waf #webapplicationfirewall
1
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 3mo ago

I’ve been running honeypots on the internet for about four months. I’ve looked in detail at the mdrfckr botnet (Outlaw) and written a blog post about it.

https://nheinz.dev/blog/2026/06/mdrfckr---a-almost-decade-old-botnet/

#honeypot #botnet #cybersecurity #threathunting #threatintel

nheinz.dev
1
0
1
0
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

Decided to switch from VMware Workstation 17 to QEMU + Virtual Machine Manager today and spent two hours debugging networking. Turned out the VM couldn't reach the internet and my host couldn't ping the VM due to two conflicting routes for the same subnet. Removed the old VM network route and everything started working - finally 🥳 .

#networking #sysadmin #dumb #qemu #vmware

infosec.exchange

Infosec Exchange

2
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 4mo ago

Does anyone know if there's an equivalent to "GitLab Components" in Forgejo?

#forgejo #Gitlab #CICD #Devops #Devsecops

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 6mo ago

The most interesting supply chain attack I've ever seen: #trivy

The attack is really bizarre. I learned a lot about GitHub Actions and how the attack was performed.

- https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
- https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
- https://ramimac.me/trivy-teampcp/#timeline
- https://snyk.io/articles/trivy-github-actions-supply-chain-compromise/

#cybersecurity #supplychain #github #glassworm #githubactions #attack #TeamPCP #c2

infosec.exchange
1
0
3
0
Open post
Niclas @niclas@infosec.exchange
· 8mo ago

With this structure, the variables in “host_vars” and “group_vars” are not loaded. This is because the inventory file is not in the root directory. Is there a way to have the inventory file in an inventory folder?

#ansible #sysadmin #devops #gitops #automation

infosec.exchange

Infosec Exchange

1
1
1
0
Open post
Niclas @niclas@infosec.exchange
· 3mo ago

Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

#Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

infosec.exchange
0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 5mo ago

@nwcs@mastodon.social

That does sound interesting. Especially for those who are currently in the process of moving away from VMware Workstation and don't want to have to rebuild and reconfigure all their VMs. Migrating from VMware to Qemu gives me the chance to sort through my roughly 40 VMs and figure out which ones I actually still need (I'll probably delete 30 of them). And I can quickly rebuild the rest using backups and Ansible and get them back up and running.

0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 8mo ago

Please give me a reason, why #ec2 on #aws has less than 5GB tmp and 0 SWAP space? Sooner or later, you'll run into problems😞 .

#sysadmin #linux #cloud

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 1mo ago
A new blog post from me: https://nheinz.eu/blog/2026/08/redtails-long-runner/ #cybersecurity #honeypot #c2 #redtail #botnet
Niclas Heinz - Redtail
nheinz.eu

Niclas Heinz - Redtail

Personal Website of Niclas Heinz

0
0
0
0
Open post
Niclas @niclas@infosec.exchange
· 8mo ago
Replying to

@appsinet@phpc.social Interesting. Are your playbooks also located in a subfolder and not in the inventoryfolder? Because for me, those vars are not loaded when executing the playbook with ansible-playbook -i inventory/inventory.yml playbooks/infra.yml

0
4
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:39:42 UTC