Building a Minimal Open Source Security Stack for Infrastructure Protection
Full protection of corporate infrastructure today is difficult to achieve without commercial security tools. However, startups, small organizations, and budget-constrained companies often turn to open source solutions as a compromise. This guide focuses on building a minimal security stack that addresses core information security tasks using freely available tools.
A basic stack must cover several key areas: protection of endpoints to detect malware and workstation compromise, network perimeter defense and traffic control, centralized collection and analysis of security events, and user access management through proper authentication and rights separation. The recommendations are intended as a starting point for small infrastructures rather than a complete substitute for enterprise products.
Antivirus Protection
ClamAV is one of the best-known open source antivirus engines with cross-platform support for Linux, Windows, and macOS. On Windows, the graphical frontend ClamWin is available. It is frequently used to scan mail traffic and file repositories in addition to endpoint protection. Other options include the OpenAntiVirus Project and KicomAV.
Installation on Linux uses the commands: apt-get update followed by apt-get install clamav clamav-daemon. Services clamav-freshclam and clamav-daemon handle signature updates and scanning. On Windows, the standard installer is used, and recursive scans are performed with clamscan --recursive.
Network Perimeter Protection
Popular open source firewalls include pfSense, built on FreeBSD with the PF packet filter, its fork OPNsense, and the proxy server Squid. pfSense supports installation of Snort and Suricata for intrusion detection and prevention, as well as Squid for web traffic filtering. Key features encompass multi-WAN load balancing, VPN servers (IPsec, OpenVPN, L2TP, TINC), DHCP services, HAProxy publishing, captive portal support, and log forwarding to external SIEM systems.
Rules for Snort or Suricata can be loaded from ET Open or official VRT feeds. The system can operate in IDS mode for logging only or IPS mode for active blocking. Logs are forwarded via the Status → System Log → Settings section.
Security Event Collection and Analysis
The ELK Stack (Elasticsearch, Logstash, Kibana) enables custom SIEM construction. Logstash and Ingest Pipelines normalize events, while threshold and EQL rules support correlation of authentication failures or suspicious sequences. Wazuh offers a more integrated platform with built-in vulnerability scanning, file integrity monitoring, EDR-like capabilities, and direct mapping to the MITRE ATT&CK framework for threat hunting and IOC enrichment.
Access Management and Authentication
Keycloak provides single sign-on using OAuth2, OIDC, and SAML standards. It authenticates users, issues JWT tokens, and supports integration with LDAP or Telegram. Configuration involves creating an OpenID Connect client, setting valid redirect URIs, and mapping roles in the target application such as Kibana.
These open source components together form a functional baseline for small environments, but they must be tuned to the specific infrastructure, kept updated, and sourced only from active, reputable projects.
Related articles
Google Testing Optional Google Account Unlock for Forgotten Android PINs
Google is developing a backup unlock method that lets Android users regain access to their devices through a linked Google Account instead of performing a full factory reset. The feature, discovered in Android 17 QPR2 Beta 5, appears under the name Unlock with Google Account and would be disabled by default. Users would need to enable it manually in the Device unlock settings before forgetting their PIN, password, or pattern. The change aims to prevent permanent loss of local data such as photos and documents that lack cloud backups. The mechanism revives a capability removed after Android 4.4, when forgotten patterns could be cleared using Google Account credentials. Factory Reset Protection would remain in place after any reset. The code reference is not yet functional, carries no official announcement, and may be altered or dropped before release.
Implementing 2FA Kubernetes Access via Gateway API, Dex and MULTIDIRECTORY
A Russian cybersecurity company replaced static kubeconfig files with corporate accounts and mandatory 2FA for its Talos Linux Kubernetes clusters. The solution routes all authentication through a single FQDN using NGINX Gateway Fabric, Dex as an OIDC provider connected to MULTIDIRECTORY via LDAP, and kube-oidc-proxy for token validation and impersonation. Groups stored in the directory are passed directly into RBAC bindings, eliminating manual certificate management. A lightweight Python service dynamically generates kubeconfig files that contain no secrets. The team documented several Gateway API migration pitfalls including namespace route restrictions and BackendTLSPolicy hostname validation. The approach keeps the entire configuration in Git and avoids modifying kube-apiserver flags.
Windows File System Tunneling Preserves Old File Metadata for Legacy Compatibility
Microsoft has clarified that Windows sometimes assigns creation dates from deleted files to new ones due to a long-standing mechanism called File System Tunneling. The feature keeps metadata in a short-term cache for about 15 seconds after a file is deleted or renamed. If a new file with the same name is created quickly in the same folder, it inherits the previous file's timestamps and short-to-long name mappings. This behavior exists to support safe saving patterns used by many applications and to maintain compatibility with old DOS-era 8.3 filename formats. The actual file content is never restored, only the metadata. The cache is temporary and clears over time, so the effect does not occur with files deleted long ago. The explanation came after users noticed unexpected dates in Windows Explorer and questioned whether it was a bug.
Amazon Confirms Irrecoverable Data Loss in UAE and Bahrain Data Centers After Drone Attacks
Amazon Web Services has officially confirmed that data stored in specific availability zones within its Middle East regions was permanently destroyed following physical attacks on data centers in the UAE and Bahrain. The incidents began on March 1 and continued through April and July, damaging infrastructure tied to AI development projects. In the UAE region mec1, only zone mec1-az2 was completely destroyed with no external backups, while mec1-az3 suffered severe damage and mec1-az1 remained operational but overloaded. All three zones in the Bahrain region me-south-1 were rendered inoperable. AWS had spent six months attempting recovery before issuing the final statement on September 15, 2026, and has advised customers to migrate workloads to unaffected regions. The event highlights growing risks to data from physical-world attacks beyond traditional network threats.