F0rm4t · @F0rm4t
25 followers · 29 posts · Server infosec.exchange

A Recon integration for is now available on the App Exchange.

Integrating Randori Recon with QRadar SOAR empowers analysts with bi-directional synchronization between solutions, enabling queries of Randori Targets and the ability to create and update corresponding cases in QRadar SOAR.

community.ibm.com/community/us

#Randori #qradar #soar #ibm #cybersecurity #infosec #ibmsecurity

Last updated 2 years ago

Mark Hunt · @thefreehunter
4 followers · 3 posts · Server infosec.exchange

Might as well do an . My name is Mark Hunt, I've been in since 2011. Historically I've worked mostly with (, ) as a former Security consultant, now working in , , and . I collect hobbies, mostly , , and .

#introduction #infosec #siem #qradar #spunk #ibm #redteam #pentesting #incidentresponse #programming #music #digitalart

Last updated 2 years ago

Mark Hunt · @thefreehunter
20 followers · 23 posts · Server infosec.exchange

Might as well do an . My name is Mark Hunt, I've been in since 2011. Historically I've worked mostly with (, ) as a former Security consultant, now working in , , and . I collect hobbies, mostly , , and .

#splunk #introduction #infosec #siem #qradar #ibm #redteam #pentesting #incidentresponse #programming #music #digitalart

Last updated 2 years ago

Jason "JK" Keirstead · @BlueTeamJK
15 followers · 39 posts · Server infosec.exchange

News on AWS Security Lake, leveraging the Open Cybersecurity Schema Framework () is making the rounds. Proud that not only is IBM Security a launch partner, but was one of the very few products name-dropped in the launch keynote.

aws.amazon.com/blogs/aws/previ

Note that we have also added support for Security Lake to the Open Cybersecurity Alliance Shifter and projects - you can query and threat-hunt across AWS *and ~ 30 other products and clouds* all from one place, and apply out-of-the box ML and analytics... check it out if you have not.

opencybersecurityalliance.org/

#ocsf #qradar #aws #STIX #kestrel

Last updated 2 years ago

Jason "JK" Keirstead · @BlueTeamJK
15 followers · 39 posts · Server infosec.exchange

@dcdb I am obviously biased, but have you looked at :) PS - if you have not looked at it in the past 3 years, it is very different.

Only comment on Elastic - and anything Elastic based, which a lot are - beware of scaling challenges. Works great for low volumes. As you scale up, Elastic infrastructure cost balloons. It is a fundamental issue with Apache Lucene base architecture of Elastic.

#qradar

Last updated 2 years ago

DJ Kenneth A · @djkennetha
12 followers · 16 posts · Server home.social

I see lots of people doing introductions and I just realized I never did one. So hello Mastodon! It’s nice to meet you. I’m DJ Kenneth A. More / than DJ. (I’m also a senior engineer for my day job.) I’ve remixed and worked with some super awesome people (Queen, Andy Hunter, various bootlegs ), and have been fortunate to have some in documentaries, sporting events and tv. I mostly write music for fun, but also because if I stop I’ll explode. (Which is messy)

#producer #remixer #qradar #music

Last updated 2 years ago

infosec-jobs.com · @infosec_jobs
760 followers · 14040 posts · Server mastodon.social
HCS ▋ · @superruserr
1273 followers · 2875 posts · Server infosec.exchange

While it's on IBM ibm.com/support/knowledgecente they provide a useful and simple matrix mapping out log source types with the MITRE ATT&CK Framework.
I have in mind, hopefully end of this year, to refine this matrix and specifically point out some modules (ie that is open source/CE edition)

#qradar

Last updated 5 years ago

How do corps justify the cost of pretty steep if you really want to ingest all the relevant data

#splunk #arcsight #qradar #siem #bizcase

Last updated 6 years ago