The evolution of SIEM correlation rules
We regularly create new SIEM rules, but behind the scenes lies a more fundamental process —the evolution of the correlation rules themselves.
91 articles
We regularly create new SIEM rules, but behind the scenes lies a more fundamental process —the evolution of the correlation rules themselves.
Detecting attacks related to compromised accounts with AI and other updates in Kaspersky SIEM.
Using anomalies in the behavior of users, devices, applications, and other entities to detect cyberthreats.
While open-source projects let you build almost any infosec solution, it’s crucial to realistically assess your team’s resources and the time it would take to achieve your goals.
How to estimate what and how much hardware will be needed for a SIEM system to assess the costs before deployment?
Rules for detecting atypical behavior in container infrastructure at the data collection stage, and other updates to our SIEM system.
Detection of techniques for disabling or modifying a local firewall, and other enhancements to the Kaspersky Unified Monitoring and Analysis Platform.
Medium-sized businesses increasingly find themselves on the receiving end of targeted attacks. What tools does one need when basic security proves inadequate?
We’re expanding the capabilities of the Kaspersky Unified Monitoring and Analysis SIEM system by adding new normalizers and correlation rules.
What’s new in Kaspersky Unified Monitoring and Analysis Platform 3.0.3.
How a threat-intelligence platform helps SOC analysts.
Using the Machine-Readable Threat Intelligence Platform fits well with our general position on security: multilayeredness everywhere.
An analysis of key characteristics of AI agent-driven cyberattacks, why open-source models are sufficient to execute them, and what measures can help defend an organization.
We analyze the first-ever real-world incidents where attackers targeted AI agents deployed in corporate environments.
How attackers gain access to corporate services without stealing passwords or cookies: we’re analyzing the Shadow Token via Remote Debug technique used in ToddyCat APT attacks.
We break down the core challenges and potential solutions for building a fully autonomous security operations center.
Approaches to solving cybersecurity challenges in autonomous transportation systems.
Attempts at hijacking AI resources are now taking place on an industrial scale. How is AI infrastructure being targeted, and what defensive measures should you implement?
How the AirSnitch vulnerability family threatens corporate networks, and what changes you need to make to your network architecture and settings to stay protected.