Staff
Since ‎02-12-2024
2 weeks ago

My Stats

  • 24 Posts
  • 1 Solutions
  • 14 Likes given
  • 25 Likes received

Clement_pgx's Bio

Badges ScottieJ Earned

View all badges

Recent Activity

Turns out that the Grok Pattern "GREEDYDATA" not that all that greedy...hopefully this will save someone some time. I needed to write a parser extension for a multi line Windows event formatted in XML. I not so quickly discovered that Grok patterns m...
Many MSV deployments include multiple on-premise actors and one or two Mandiant cloud hosted actors. Many use cases like data extraction or malicious file transfers (MFT) will require that the on-premise actors can communicate with the cloud hosted a...
The MSV Report Builder is a powerful analytics tool. It is easy to get carried away with all the widgets available after running a campaign of attack simulations and emulations when crafting an Executive Debrief Report . A Debrief should be "brief" b...
Just like pilots, who have to complete a rigorous set of safety checks before every departure, security teams should also routinely evaluate security controls to help keep their organization safe. The Advanced Environmental Drift Analysis feature in ...
Many of the MSV Integrations especially in the SIEM category utilize field mappings to associate data to variables used by MSV to attribute log or alert events to Actions. Typical mappings include: source IP, destination IP, host name, user, source P...