Monitoring Proxmox Hosts with Defender
Knowledge Required: Minimal Tools required: Defender for Endpoint, Proxmox Those who have come across my LinkedIn are aware that I’m a bit of a Proxmox fan. Proxmox typically runs on top of Debian and so this allows for plenty of tinkering… including installing Defender for Endpoint. While I would generally discourage this in a production environment without plenty of testing, there are some events in my homelab that I believe are useful to monitor. Using the below KQL, either as threat hunts or analytical rules, should provide some indication that somebody is performing a series of high-profile activities on your PVE environment. ...