Today we take a look at some tools that provide "Detection Posture Management", which is the fanciest way I found to describe it. These tools provide content for SIEMS, a Management Platform, data validation, and make SIEM engineering easier. We take a look at three vendors, do some comparison and contrasting, and discuss the overall capabilities of these tools.
Vendor 1 - Cardinal Ops
Vendor 2 - SOC Prime
Vendor 3 - Anvilogic
Supporting Links:
Hype Cycle for Security Operations, 2023
Can We Have “Detection as Code”?
Detection as Code: How To Embed Threat Detection into Code
If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!
In this episode we discuss the Purple Team. What is it, and why is it David's favorite color? Supporting Articles:The Difference Between Red, Blue,...
This week we take a look at the Picus Security Blue Report, and provide some analysis of the statements. Interesting findings here. The report...
In this episode, we reviewed some recent news articles that caught our eye, including how to choose your MSP, will the UK ban default...