#siem

2025-12-31

AI in a SOC shouldn’t be “push button, solve security.” It’s better as a force multiplier: faster triage, cleaner investigations, safer automation, and way less copy/paste misery.

I also get into the guardrails that actually matter (evidence-first summaries, human-in-the-loop, prompt injection, least privilege).

Read it here: kylereddoch.me/blog/putting-ai

#cybersecurity #SOC #SecurityOperations #AI #IncidentResponse #SIEM #SOAR

2025-12-31

Are you using your #SIEM to detect #security threats in the most efficient and effective ways possible❓🤔 When you implement and fine-tune SIEM detections, you strengthen your security posture and become better able to strategically aligning with your business objectives.

Fine-tuning your SIEM detections specifically allows you to:
💡 Improve threat detection with smarter correlation
⬆️ Accelerate incident response
👀 Gain comprehensive visibility into your environment
☑️ Enable compliance and audit readiness
😌 Reduce alert fatigue

Read on, to learn about 6 specific steps you can take that will help you build fine-tuned detections and high-fidelity alerts.👇

graylog.org/post/6-steps-for-u #ThreatDetection #IncidentResponse #TDIR #CyberSecurity

2025-12-30

Как интегрировать аудит-логи с SIEM: от теории к практике на Wazuh и RuSIEM

Недавно мы в Selectel запустили систему аудит-логов . Она предназначена для централизованного сбора и анализа событий, возникающих при работе сервисов Selectel. А также — обеспечивает единый доступ к операционным и административным действиям, фиксирует различные события с ресурсами аккаунта и помогает отслеживать потенциально подозрительные активности. Важным фактором для удобства расследований и анализа является формат самих аудит-логов. Он должен быть структурированным и единообразным вне зависимости от части системы, где происходит события. При этом — достаточно информативным, чтобы можно было установить обстоятельства события. При должном подходе аудит-логи — не просто набор технических сообщений, а инструмент, который помогает как предотвращаь проблемы, так и эффективно расследовать их при необходимости. Но чтобы начать анализировать события, которые происходят в системе, нужно сначала эти события получить и передать анализатору — SIEM-системе. Этому и будет посвящена данная статья.

habr.com/ru/companies/selectel

#selectel #siem #информационная_безопасность

2025-12-30

Как интегрировать аудит-логи с SIEM: от теории к практике на Wazuh и RuSIEM

Недавно мы в Selectel запустили

habr.com/ru/companies/selectel

#selectel #siem #информационная_безопасность

2025-12-30

❄️ Winter break is the perfect time to brush up on your Sigma rules! ❄️ With Sigma Specification 2.0 rules, #security teams can create vendor-agnostic detections without being limited by proprietary log formats. 🙌

So, security teams now have:
✅ New fields and modifiers that improve how security teams use the rules
✅ Correlation specifications to extend rules to more sophisticated detections
✅ Filters that reduce false positives
#JSON schema to allow automation

Learn more about the key changes in Sigma v.2.0 and supporting Sigma v2.0 mapped to MITRE ATT&CK framework.

graylog.org/post/sigma-specifi #SigmaRules #CyberSecurity #SIEM #InfoSec

Linux Solutionslinuxsolutions
2025-12-28

🔍 Wazuh: A Solução SIEM Ideal para sua Empresa! 🛡️

O Wazuh é uma plataforma open source que oferece monitoramento de segurança robusto e resposta a incidentes. Com funcionalidades de SIEM e XDR, ele garante proteção em tempo real para ambientes on-premise e na nuvem, ajudando sua empresa a detectar e reagir rapidamente a ameaças.

👉 Descubra como o Wazuh pode fortalecer sua segurança: Wazuh: O SIEM Certo para sua Empresa

2025-12-27

💡 As you build out your #security program, you should know some of the more critical #Windows Event IDs to monitor and what they mean. Read on to get a list of critical Event IDs for:

👉 Logon events
👉 Privilege use
👉 Windows Server
👉 Microsoft Defender Antivirus

Plus, learn how you can build a single source of log information that enables observability and visibility across your environment. 🙌

graylog.org/post/25-linux-logs #CyberSecurity #SIEM #InfoSec #GraylogLabs

2025-12-24

#siem —Map all your data models from sourcetype. Using #org files for all documentation. #knowyourdata. #emacs #doomemacs.

Negative PID Inc.negativepid
2025-12-24

Here's a case that prompted a massive advance in cybersecurity measures in the United States. The Target data breach prompted the use of pin-and-chip cards and the adoption of SIEM. Here's how this incident sparked such a massive change in payment data protection.

negativepid.blog/the-target-da
negativepid.blog/the-target-da

Mohamed ROMDANERomdane
2025-12-23

Is your business ready to handle today's cyber threats alone?

If not 1: You need an MSSP for Operational Support for filling the talent gap.
If not 2: You need an MSSP for Operational Support for managing the noise.
If not 3: You need an MSSP for Governance & Compliance (ensuring you meet legal standards).
If not 4: You need an MSSP for Strategic Maturity (moving from "fighting fires" to proactive protection).

linktr.ee/formafastconsulting

Tedi Heriyantotedi@infosec.exchange
2025-12-22

Series: Managing SIEM Log Collectors at Scale with Ansible and GitHub Actions

- Part 1: blog.nviso.eu/series/siem-log-

#siem #logcollection #ansible #githubactions

Linux Solutionslinuxsolutions
2025-12-20

🔍 Wazuh: A Solução SIEM Ideal para sua Empresa! 🛡️

O Wazuh é uma plataforma open source que oferece monitoramento de segurança robusto e resposta a incidentes. Com funcionalidades de SIEM e XDR, ele garante proteção em tempo real para ambientes on-premise e na nuvem, ajudando sua empresa a detectar e reagir rapidamente a ameaças.

👉 Descubra como o Wazuh pode fortalecer sua segurança: Wazuh: O SIEM Certo para sua Empresa

2025-12-20

Curious what the top SOC trends were in 2025? Take a look. 👀👇

🤖 AI outpaced oversight
📊 Dashboards expanded while context thinned
⛅ Cloud costs quietly dictated security decisions
🔃 Process, not skill, slowed investigations
❗ API exposure grew faster than tracking

And there are more! See all of the top SOC trends from 2025 plus our top prediction for the SOC in 2026, in our latest blog.

graylog.org/post/2025-security #SecurityOperations #SIEM #CyberSecurity #InfoSec

2025-12-18

There's a new look to modern day #ransomware attacks (no) thanks to the Ransomware-as-a-Service (#RaaS) ecosystem. As attackers continue to automate spear #phishing and other processes, identifying and mitigating these email threats becomes both more important and more challenging. 😓 So, let's talk about how your team can improve their risk mitigation strategies.

In this article we review:
🎣 Phishing, spear phishing, and whaling
📧 Why ransomware email threats are so successful
🛡️ Best practices for mitigating these threats

Dig into the details of implementing email security, centralizing security data, integrating threat intelligence, identifying very attacked persons (VAPs), and more.

graylog.org/post/understanding #SpearPhishing #ThreatIntel #SIEM #CyberSecurity

2025-12-18
You came to a split in the road….

…and the Apsara-crew took the road less travelled, because they make all the difference.

To manage, develop and maintain the vast human cultural treasure of the Angkor Park, the Apsara Authority was established back in 1995.

It has ha monumental task, literally speaking, taking care of the approximately 420 km2 area of the main Angkor Archaeological Park. It contains more than 70 larger temple sites, and over 1000 smaller sites and remains.

Important task and employer
Easy recognisable with their green uniforms, the Apsara Maintenance staff are making the visit into the Angkor Archaeological Park and sites possible, safe and accessible. It is a highly respected and important effort on behalf of Cambodia’s long and proud history, civilisation and culture. And of course, the common human historic value as a World Cultural Heritage site for the rest of us.

With over 3 000 employees, the Apsara Authority is the largest single employer in the Siem Reap province.

#angkorwat #angkor #pond #sunrise #wat #temple #food #asiangirl #asian #villagelife #morning #AngkorWat #Apsara #ancient #art #architecture #sculpture #archive #worldculturalheritage #hinduism #khmer #empire #buddhism #greentourism #takeonlyphotos #leaveonlyfootprints #Cambodia #citylife #countryside #daytrip #history #imperial #biking #Site #statetemple #Apsara #maintenance #crew #staff #lunch #tiffin #carrier #Chanshrak #tiffincarrier #Nikon #D300 #NikonD300 #Nikkor #14_24mm #f2_8 #2011CE #Siem #Reap #siemreap #southeastasia #visitsiemreap #visitcambodia
Photo shows a green turf with two tracks; one main horizontally track where two persons in leisure clothing is walking right bound. Then there is a diagonal, less used track where two people wearing the green long sleeved polo shirt of the Apsara Maintenance crew is walking with tools and a and an empty garbage bag. Both tracks lead to different parts of the large temple complex of Angkor Wat outside to the right in this photo. In the background there is a low stone fence in Angkor High Imperial architectural style. Behind the fence, on a lower level is a small lake. It is known as one of two mirror lakes flanking the main west entrance to Angkor Wat temple. Around and behind the mirror lake green turf and some trees are stretching out to one of the gates in the main wall around Angkor Wat. It is early morning on an overcast day. Cambodia is as safe, comfortable and kind as ever. Angkor and Siem Reap warmly welcomes visitors as the home of several cultural world heritage sites.
2025-12-18

Wondering how #DevOps, development, and AI-powered #dev tools will evolve and impact the industry in 2026? Several experts offer thoughtful, insightful, and even some controversial predictions — in this DevOps Digest article. ⬇️

🎤 Hear from several industry luminaries on the topic of AI-powered SDLC, including:
🔹 Sunil Senan, Infosys
🔹 Ensar Seker, SOCRadar
🔹 Rishi Chohan, GFT Technologies
🔹 Lee McClendon, Tricentis
🔹 Jithin Bhasker, ServiceNow
🔹 Emilio Salvador, GitLab
🔹 Greg Ingino, Litera
🔹 Nuha Hashem, Cozmo AI
🔹 Rohan Gupta, R Systems
🔹 Robert Rea, Graylog, Inc.
🔹 Ian Livingstone, Keycard

"In 2026, DevOps culture will be defined by systems that coach, correct, and collaborate alongside engineers." — Robert Rea CTO, #Graylog

devopsdigest.com/2026-devops-p #CyberSecurity #InfoSec #SIEM #AI

2025-12-16

Got questions about the National Security Division (NSD) of the U.S. Department of Justice's (DOJ) Data Security Program (DSP)? It was first implemented on Apr. 8, 2025, and the section focused on due diligence and audit requirements became enforceable as of Oct. 6, 2025.👮👀 Do your current compliance programs and data sharing activities need additional controls or processes to comply? 🤔

The DSP establishes export controls that seek to prevent access to bulk genomic, geolocation, biometric, health, financial, and other sensitive personal data by foreign adversaries and those subject to their control, jurisdiction, ownership, and direction. Read on to learn more about what's required of you with this new DSP, including:

❓ The type of data that falls within the DSP
🚫 How the DSP defines covered transactions and prohibited transactions
📋 The specific requirements for a compliance DSP program
✅ How to implement best practices for implementing and monitoring compliance with DSP #security requirements

It's possible to streamline your compliance processes while improving your overall security posture. See how. 👇

graylog.org/post/understanding #CyberSecurity #InfoSec #SIEM

2025-12-16
Bringing food for mommy

A memory from my first visit to Angkor Wat. This couple, I guess brother and sister, had their priority and duty clear this early fall day in the green season of 2011CE.

It was bringing lunch to mommy, one of the Apsara maintenance staffers at Angkor Wat. Making sure the maintenance and operation of the 8th Wonder of the World was smoothly and efficient.

State Temple, tomb, now Wat
Angkor Wat was original a royal state temple built in honour of the Hindu god Vishnu in the mid-12th Century CE. It is a tomb for the God King Suryavarman II too.
As a usurper, he needed to show his right to the throne by building this enormous religious building. It is still the largest and probably the most famous religious buildings in our common human cultural heritage.

Later it was converted to a Buddhist temple and monastery for religious worship and learning, a “Wat”.

Classic combination
Angkor Wat represents two architectural styles for Hindu temples. We have the temple mountain as a reminder of the 5 sacred Meru mountain, home of the Hindu gods. And the later galleried temple.

The galleries are even more interesting than usual. In addition to honour the gods and religious rites, it is the history of the reign of a powerful emperor.

This is one of the temples in Angkor Park where it is highly advisable to have a guide on your first visit. The size is easier to understand when you have some knowledgeable to show the important highlights and the best photo spots.

#angkorwat #angkor #pond #sunrise #wat #temple #food #asiangirl #asian #boy #villagelife #morning #AngkorWat #Apsara #ancient #art #architecture #sculpture #archive #worldculturalheritage #hinduism #khmer #empire #buddhism #greentourism #Cambodia #citylife #countryside #daytrip #history #imperial #biking #Site #statetemple #khmerchildren #lunch #tiffin #carrier #Chanshrak #tiffincarrier #Nikon #D300 #NikonD300 #Nikkor #2011CE #Siem #Reap #siemreap #southeastasia #visitsiemreap #visitcambodia
Photo shows two young children with their back to the photographer walking a stone bridge towards a temple wall of towers and gates in Angkor High Imperial architectural style. The stone bridge is built over an area of mostly green turf, with a couple of trees growing just to the right. They are carrying a Tiffin food carrier, or Chan Shrak, a levelled carrier where different types of food are separated into a tower of containers. Together these containers make for a typical meal of soup, fish/meat and veggies, and steamed rice. There are two buildings flanking each side of the bridge, libraries in this design. It is early morning on an overcast day. Cambodia is as safe, comfortable and kind as ever. Angkor and Siem Reap warmly welcomes visitors as the home of several cultural world heritage sites.
Linux Solutionslinuxsolutions
2025-12-13

🔍 Wazuh: A Solução SIEM Ideal para sua Empresa! 🛡️

O Wazuh é uma plataforma open source que oferece monitoramento de segurança robusto e resposta a incidentes. Com funcionalidades de SIEM e XDR, ele garante proteção em tempo real para ambientes on-premise e na nuvem, ajudando sua empresa a detectar e reagir rapidamente a ameaças.

👉 Descubra como o Wazuh pode fortalecer sua segurança: Wazuh: O SIEM Certo para sua Empresa

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst