Coder Social home page Coder Social logo

About Me

Hi there, my name is John - aka jberkers42

I'm a husband, father and Security Professional

My professional intersts include:

  • Security (which Security Professional is not interested in security?)
  • SIEM (Security Incident and Event Management)
  • DevOps/SecOps/DevSecOps (basically automating stuff)

Employment

I work at IPSec in Melbourne, Australia, having been there since the foundation of the company in late 2009, as a Senior Security Engineer, Architect and Consultant. I spend a lot of my time working with SIEM technologies, mostly LogRhythm, as well as a number of firewall and other security technologies.

My focus for the past couple of years has been to migrate more of our environment to the cloud, as well as increasing the level of automation for deployment and maintenance tasks.

Automation

There are two areas where I have focused on automation:

  • Infrastructure build and maintenance
  • Response from SIEM Alerts

For the former, most of the attention has been to implement automation and testing using Ansible to automate the implemtation and maintenance of our infrastructure. This has been achieved through the use of a combination of tools:

Infrastructure

GitLab repositories are used to hold the definition of the environment(s) as well as the instructions to build them. These are separated into functional layers:

  • Inventories
  • Roles
  • Playbooks

Ansible and AWX are used to execute the instructions against an appropriate inventory.

SIEM Response

One of the tents of a SOAR platform is to provide Automation and Response to an identified security incident. LogRhythm achieves this through the use of a SmartResponse™. SmartResponses are essentially a script wrapped with an XML file that tells LogRhyhtm how to execute it.

Most of my SmartResponse work has been in PowerShell.

Connect with me

jberkers42 BerkersJohn | Twitter jberkers | LinkedIn john.berkers | Instagram


Tools

Visual Studio Code SQL Git Ansible Azure AWS MarkDown LogRhythm GitLab PowerShell

John Berkers's Projects

awx-operator icon awx-operator

An Ansible AWX operator for Kubernetes built with Operator SDK and Ansible. 🤖

misp-warninglists icon misp-warninglists

Warning lists to inform users of MISP about potential false-positives or other information in indicators

sophos-central-siem-integration icon sophos-central-siem-integration

Simple integration script for 3rd party systems such as SIEMs. Offers command line, file or syslog output in CEF, JSON or key-value pair formats.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.