Peter Czanik · @PCzanik
299 followers · 538 posts · Server fosstodon.org

Recently I was asked if rules are supported by :

github.com/SigmaHQ/sigma

syslog-ng has message parsing, filtering, can be used for alerting. But I'm not aware of a tool turning Sigma rules into PatternDB and syslog-ng.conf

Syslog-ng can send logs to , stack, @OpenSearchProj, @Graylog, all which already have rules integrations.

Of course many users use/abuse syslog-ng as a kind of -lite.

If you already use syslog-ng with rules: let me know!

#sigma #syslog_ng #splunk #elastic #siem

Last updated 1 year ago

A few weeks ago I setup as per 's video. So far it's been pretty interesting to see what's going on in and outside of my network. Definitely completely SILENCED a massive ginormous ssh attack that I didn't even notice and hadn't secured against (rip) good thing my passwords are stupid long. Much more fun to do!

#wazuh #networkchuck #youtube #cybersecurity #Tech #siem #security #IT #hacking

Last updated 1 year ago

What is Security Onion, an Intrusion Detection System Tool 👇️💡️

cybersecuritynews.com/security

#opensource #ids #cybersecurity #siem #logs #monitoring

Last updated 1 year ago

ChiefGyk3D · @chiefgyk3d
1493 followers · 1471 posts · Server social.chiefgyk3d.com

I’m about $300 away from my goal of purchasing a new firewall. Once I transfer everything to the new firewall I will try and do a stream setting up a firewall from scratch using my cell backup internet. Then once I run through that for y’all I will wipe it clean and make the current box a @grafana and box using probably.

So if you want to help out please tip me in my links or subscribe on or twitch

#pfsense #twitch #siem #wazuh #TikTok #streamer #linux #opensource #cybersecurity #InfoSec

Last updated 1 year ago

Secureworks · @Secureworks
20 followers · 33 posts · Server ioc.exchange

"EDR is to NGAV, what XDR is to SIEM"

Secureworks Chief Product Officer shares insight on the advanced correlation and stitching of data that XDR allows for, as it widely replaces SIEM investments.

Watch the full video: youtu.be/UuT_T1DiIkY

#siem #xdr #cybersecurity

Last updated 1 year ago

Dimitar Grozdanov · @grozdanovd
24 followers · 37 posts · Server masto.ai
Bitwarden · @bitwarden
13236 followers · 844 posts · Server fosstodon.org

Did you know Bitwarden has an official Splunk app? Use it to add protection to Bitwarden accounts and the credentials within! bitwarden.com/blog/using-splun

#siem #cybersecurity #security #passwordsecurity #passwordmanager

Last updated 1 year ago

Nightfighter · @Optimus
35 followers · 1359 posts · Server social.tchncs.de

Hat jemand schon mal , , und miteinander verheiratet?
Das sind geniale Opensource Projekte für ein SIEM / SOC Konzept.
Würde mich über einen Know-How Austausch freuen.

#linux #opensource #security #malware #siem #soc #misp #cortex #thehive #wazuh

Last updated 1 year ago

WhatDoesKmean · @seercle
1 followers · 16 posts · Server red.niboe.info

By the end of this article, you will have the knowledge and skills needed to make updates to your Sumo Logic collectors programmatically.

I hope that helps! 😊

loggar.hashnode.dev/updating-a

#soc #blueteam #infosec #cybersecurity #siem #logmonitoring #sumologic

Last updated 2 years ago

WhatDoesKmean · @seercle
1 followers · 15 posts · Server red.niboe.info

Today in our redux, we present @ctudball, who takes us on a tour of how the#InfoSec landscape has changed, the move to , efforts, and the advent of - a standard for representing events, and the platform-agnostic @opentelemetry.

youtube.com/watch?v=6o6YlTE-Pz

#everythingopen #zerotrust #openstandards #OCSF #taxonomy #siem

Last updated 2 years ago

Michael Starks, Logsta🪵 · @libr8r
153 followers · 241 posts · Server noc.social

How would you explain the problem of running multiple different solutions to executives? Give me some good analogies they can understand.

#siem

Last updated 2 years ago

Sebastien Stormacq · @sebsto
338 followers · 219 posts · Server awscommunity.social

Un nouveau blog post 📝 AWS en français 🇫🇷 utiliser Amazon OpenSearch pour SIEM

aws.amazon.com/fr/blogs/france

#security #Cloud #aws #siem

Last updated 2 years ago

Jesse Harris · @elforesto
261 followers · 1106 posts · Server infosec.exchange

When you explain that every is basically just with parsing engines and alerts.

#siem #syslog

Last updated 2 years ago

Donavan · @Excalibur_DND
5 followers · 37 posts · Server infosec.exchange

Anyone else read a lot of in here? also makes me think that they may have had a very open model and that is why was able to take them down. - I still need to read the hack lesson learned. I mean all I read here is a was introduced. spacenews.com/viasat-deploying

#marketing #buzzwords #zerotust #russia #caveat #viasat #siem

Last updated 2 years ago

Cyentia Institute · @cyentiainst
90 followers · 125 posts · Server infosec.exchange

"Creating and maintaining 'good' policies will allow your organization to see the most impact on adjudicating concerning violations, while dismissing the non-concerning alerts. What data source an event comes from and how it’s monitored affect the quality of the signal. Having the broad knowledge base of a cloud-based NextGeneration Security information and event management (Next-Gen ) can reveal more than trying to work in isolation. Read the report:
securonix.com/resources/quanti

#siem #infosecurity #cybersecurity

Last updated 2 years ago

Cyentia Institute · @cyentiainst
89 followers · 122 posts · Server infosec.exchange

"What is surprising about this chart is not necessarily the fact that as an organization adds more data sources that it deploys more policies, but rather that the number of those policies grows exponentially." Download the Report: lnkd.in/e4ruMfwr

#infosec #cybersecurity #siem

Last updated 2 years ago

Xavier Ashe :donor: · @Xavier
799 followers · 1109 posts · Server infosec.exchange

OMG, @datadoghq wins at blogging. They are naming names! @anton_chuvakin, you'll like this.

audit-logs.tax/

"A list of vendors that don’t prioritize high-quality, widely-available audit logs for security and operations teams."

#siem #datadog #infosec #audit #auditlogs

Last updated 2 years ago

Anton Chuvakin · @anton_chuvakin
1289 followers · 55 posts · Server infosec.exchange

"Debating in 2023, Part 1" medium.com/anton-on-security/d <- a discussion of SIEM relevance in 2023, its challenges, use cases and other fun stuff (ducks? lakes?)

#siem

Last updated 2 years ago

Anton Chuvakin · @anton_chuvakin
1287 followers · 52 posts · Server infosec.exchange

Do you want to read a relatively fun blog about ? Probably not, but here it is anyway: medium.com/anton-on-security/d :-)

#siem

Last updated 2 years ago