<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>root security.eu - CyberSecurity Notebook</title><description>root-security.eu is a blog dedicated to cybersecurity and technology. It features articles, tutorials, and resources for enthusiasts and professionals alike.</description><link>https://root-security.eu</link><language>en-US</language><lastBuildDate>Tue, 10 Mar 2026 03:50:03 GMT</lastBuildDate><ttl>60</ttl><image><url>https://root-security.eu/ogImage.png</url><title>root security.eu</title><link>https://root-security.eu</link></image><item><title>Building Audit Trails for Zoho Mail: Real-Time Admin Monitoring with Wazuh</title><link>https://root-security.eu/notebook/audit-trails-zoho-mail-admin-wazuh</link><guid isPermaLink="true">https://root-security.eu/notebook/audit-trails-zoho-mail-admin-wazuh</guid><description>A guide to integrating Zoho Mail administrative audit logs with Wazuh SIEM using Logstash, creating custom decoders and detection rules, and mapping events to ISO 27001 compliance controls.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate><language>en-US</language><lastBuildDate>Tue, 10 Mar 2026 03:50:03 GMT</lastBuildDate><category>wazuh</category><category>zoho</category><category>siem</category><category>security monitoring</category><category>compliance</category><category>iso27001</category><category>email security</category><category>audit</category><author>Denis-Florin Rendler</author></item><item><title>Integrating Keeper Security Event Logs with Wazuh SIEM</title><link>https://root-security.eu/notebook/integrating-keeper-logs-with-wazuh</link><guid isPermaLink="true">https://root-security.eu/notebook/integrating-keeper-logs-with-wazuh</guid><description>A guide to forwarding Keeper enterprise suite audit logs to Wazuh for centralized security monitoring, creating custom decoders to parse authentication, vault access, and privileged session events, and building detection rules for suspicious activity.</description><pubDate>Tue, 28 Oct 2025 00:00:00 GMT</pubDate><language>en-US</language><lastBuildDate>Tue, 10 Mar 2026 03:50:03 GMT</lastBuildDate><category>wazuh</category><category>keeper</category><category>siem</category><category>security monitoring</category><category>audit</category><category>enterprise security</category><author>Denis-Florin Rendler</author></item><item><title>Managed privileged access: implementing a KeeperPAM POC</title><link>https://root-security.eu/notebook/managed-privileged-access-with-keeper-pam</link><guid isPermaLink="true">https://root-security.eu/notebook/managed-privileged-access-with-keeper-pam</guid><description>From deployment to first connection: A step-by-step proof of concept showing how KeeperPAM delivers agentless privileged access management with just-in-time identity creation and secure session recording.</description><pubDate>Mon, 06 Oct 2025 00:00:00 GMT</pubDate><language>en-US</language><lastBuildDate>Tue, 10 Mar 2026 03:50:03 GMT</lastBuildDate><category>privileged access management</category><category>pam</category><category>keeper</category><category>zero-trust security</category><author>Denis-Florin Rendler</author></item><item><title>Monitoring MikroTik RouterOS with Wazuh</title><link>https://root-security.eu/notebook/monitoring-mikrotik-with-wazuh</link><guid isPermaLink="true">https://root-security.eu/notebook/monitoring-mikrotik-with-wazuh</guid><description>A walk-through guide of the process of configuring MikroTik RouterOS to send its logs to a Wazuh server, then create custom decoders and rules to make sense of that data and get alerts that the security teams can act on.</description><pubDate>Sun, 21 Sep 2025 00:00:00 GMT</pubDate><language>en-US</language><lastBuildDate>Tue, 10 Mar 2026 03:50:03 GMT</lastBuildDate><category>wazuh</category><category>mikrotik</category><category>siem</category><category>security</category><category>routeros</category><author>Denis-Florin Rendler</author></item></channel></rss>