u/Traditional-Tech23 wanted to know how to auto block IPs from threat logs with log forwarding. I didn't even know this was possible! In this video, I walk through how to do this.
Original Reddit thread: / auto_blocking_ips_from_threat_logs_with_a_log
My LinkedIn post on the attack from 1[.]1[.]1[.]1: / cyberwes_did-anyone-else-notice-suspicious...
00:00 Introduction
01:20 Configuration
11:28 Wes Yaps During Commit
13:50 Validation
15:34 One Day Later
20:32 Conclusion