From Zero Visibility to a Measurable Security Baseline

From Zero Visibility to a Measurable Security Baseline

1 2 7
calendar_today agoschedule1 min read
— Originally published at temikara.dev

Every security team has a “Day Zero” the moment before security tooling, visibility, and processes are in place. You can't confidently answer questions like:

• What devices are on the network?
• Which systems are vulnerable?
• Are our endpoints patched?
• Would we detect a compromise?

That was the starting point for this security lab. The environment had no vulnerability scanning history, no centralized patch management, no endpoint detection, and exposed Windows machines with open RDP. So I approached the problem from the ground up.

1️⃣ Discover Before You Defend
I started with network discovery using Wireshark to identify the devices actually connected to the environment.

2️⃣ Secure the Network With Tailscale
Instead of exposing more management services to the public internet, I established a private Tailscale network.

3️⃣ Establish a Vulnerability Baseline With Wazuh
Next, I deployed Wazuh agents across the endpoints with:
• Vulnerability detection
• File Integrity Monitoring
• MITRE ATT&CK mapping
• CIS Security Configuration Assessment (SCA)

4️⃣ Centralize Patch Management With Action1
Visibility alone isn't enough. Vulnerabilities need to be remediated. I deployed Action1 to centralize patch visibility and deployment while deliberately keeping its findings separate from Wazuh's.

5️⃣ Turn Security Into a Process
I also established severity-based remediation SLAs, critical vulnerabilities were also configured for automated patch deployment and auto-approval.

🔐 Key Lessons
• Discover before you defend.
You need an accurate asset inventory before “coverage” means anything.

• Secure connectivity before expanding management access.
Reduce unnecessary network exposure wherever possible.

• Baseline before remediating.
You need measurable evidence to demonstrate improvement.

• Understand what your security tools actually measure.
Different tools can legitimately produce different results.

• Automate security policies.
A policy sitting in a document doesn't enforce itself.

• Report verified outcomes, not just completed activities.
“Patch deployed” and “vulnerability confirmed remediated” are not the same thing.

👉 Read the full blog post here:

2 Comments

1 vote
1
🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

The Zero-Net-Loss Fleet & The Mercenary Squad: A Live AI Economy

DEVPlank - Aug 4

Cisco's Amy Chang: A Model's "Passport" Doesn't Tell You Where It Actually Came From

Tom Smithverified - Aug 27

Beyond the Crisis: Why Engineering Your Personal Health Baseline Matters

Huifer - Jan 24

I’m a Senior Dev and I’ve Forgotten How to Think Without a Prompt

Karol Modelski - Mar 19

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14
chevron_left
181 Points10 Badges
2Posts
2Comments
2Connections
I'm a Full Stack / DevSecOps Engineer.

Related Jobs

View all jobs →

Commenters (This Week)

5 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!