Today we take a look at some tools that provide "Detection Posture Management", which is the fanciest way I found to describe it. These tools provide content for SIEMS, a Management Platform, data validation, and make SIEM engineering easier. We take a look at three vendors, do some comparison and contrasting, and discuss the overall capabilities of these tools.
Vendor 1 - Cardinal Ops
Vendor 2 - SOC Prime
Vendor 3 - Anvilogic
Supporting Links:
Hype Cycle for Security Operations, 2023
Can We Have “Detection as Code”?
Detection as Code: How To Embed Threat Detection into Code
If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
In this episode, we anxiously pore through the 2022 DBIR, looking for nuggets of wisdom we can apply to our defenses... only to find...
This week we discuss Avogadro Corp - The Singularity is Closer Than You Think. This book, written in 2011, was very prescient, and predicted...
This week we discussed XDR. What is it? How much of it is marketing speak? How much should you care? Here are some links...