TI in your ETL :: Shellcromancer
Mature Security Operations (SecOps) programs have a good handle on ingesting the right security telemetry for their organization and make good use of it in threat detection and incident response processes. As these SecOps teams mature their use of telemetry, a common project is surfacing externally known threats that are present in their environment by matching on Indicators of Compromise (IOCs). Common types of IOCs are IP addresses, file hash values, domains, and URLs. Using IOCs is less useful than detecting adversary TTPs because they are easier for adversaries to update compared to learning new techniques, but that doesn’t mean IOC detection isn’t useful - adversaries get lazy and IOC detections can find them just the same. All of the data sources (identity, EDR, Network, Cloud logs, application logs) in a team environment have a new perspective on the happenings of the network, and they communicate it with their schema. One of the (many) problems that distinct schemas for telemet
TI in your ETL Mature Security Operations (SecOps) programs have a good handle on ingesting the right security telemetry for their organization and make good use of it in threat detection and incident response processes. As these SecOps teams mature their use of telemetry, a common project is surfacing externally known threats that are present in their environment by matching on Indicators of Compromise (IOCs). Common types of IOCs are IP addresses, file hash values, domains, and URLs. Using IOCs is less useful than detecting adversary TTPs because they are easier for adversaries to update com
Explore this link on the map →related reading
- Security incident disclosure — July 2026huggingface.co
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Security Data Pipelines for AI-Powered SIEM | SentinelOneobservo.ai
- Security Data Pipelines for AI-Powered SIEM | SentinelOneobservo.ai
- A guide to threat hunting and monitoring in Snowflake | Datadog Security Labssecuritylabs.datadoghq.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com
- Security Data Pipelines for AI-Powered SIEM | SentinelOneobservo.ai
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- New IDR Log Search Enhancements | Rapid7 Blograpid7.com