Getting to Know Google SecOps: Introducing Outcomes in a Single Event Rule
Today, we are going to introduce the outcome section of a YARA-L rule and demonstrate how we can additional co...
•
Today, we are going to introduce the outcome section of a YARA-L rule and demonstrate how we can additional co...
Today, we are going to build a multi event rule in SecOps SIEM, but this time we will use a sliding window ver...
In this post, we’re going to build a multi event rule in SecOps SIEM with a focus on joining multiple fields a...
In this post, we’re going to build a multi event rule in SecOps SIEM with a focus on ordering events to trigge...
In this post, I demonstrate how to integrate Chrome Enterprise Management with Google SecOps to gain comprehen...
In this post, we’re going to build a multi event rule in SecOps SIEM that can be used to join disparate events...
In this post, we’re going to build a single event rule in SecOps SIEM using string matching, which will serve ...
In this post, we’re going to get to know SecOps SIEM with a focus on the various options available in the rule...
In this post, we’re going to get to know SecOps SIEM with a focus on navigating the Rules Editor, which will s...
In our previous post, we covered how SecOps SIEM can aggregate events into a single detection and alert within...
In our previous post, we covered building a single event rule in SecOps SIEM using a regular expression. In th...
In our previous post, we covered using event operators and modifiers that demonstrate the flexibility in build...
In our previous post, we covered an introduction to SecOps SIEM with a focus on using variables in YARA-L to b...
In our previous post, we provided an introduction to SecOps SIEM with a focus on YARA-L basics and how detecti...
YARA-L is a language used to create rules for searching through your enterprise log data (hence the “L”) as it...
Today, most SOC managers and CISOs are using metrics to track the security posture and measure their SOC’s per...
Hello everyone, I’ve seen various questions around the slack channel about the OVA deployment, so I’m writing ...
Have you ever noticed trees that are marked with spray paint? Now, I’m no tree spray paint marking expert, but...
Our judges were impressed by the clever use of Siemplify technology and the logic behind his block. Jason Cros...
After you implement Dor's enrichment block, we want to introduce you to Cyrus's 24/7 block, which won 2nd plac...
As promised, we are sending you the winning blocks from the Community Challenge. So, we’ll start with the 3rd ...
Someone asked this in the Siemplify Community Slack, so I thought it might be helpful to document it here as w...
This will be broken up into multiple posts due to post length requirements. One of our SOC workstreams is to r...
Tier 1 Analysis PlaybookThe Tier 1 analyst uses enrichment and instruction to perform the initial analysis and...
Security teams are no strangers to the overload of alerts. Be it via new SIEM rules, a preponderance of detect...
The Tools Power Up is a set of utility actions developed by Siemplify Professional Services for the Siemplify ...
If you haven't read the "How to use Template Engine to Render Complex Templates - Part 1" post, start off ther...
I have recently created Template Engine, an integration available to the Community which utilizes Jinja2 to re...
Hi Community, with the new capability released in the latest community edition which enables our community mem...
In an ideal world, every analyst in your security operations center would always be able to investigate and re...