I use LogRhythm, and I keep documentation on use cases, false positives, tuning etc inside the tool itself so it's where I need it. "Crafting The InfoSec Playbook" has a decent chapter on formaling SIEM rule/use case documentation too
-
-
-
Thanks for the book recommendation!
Kraj razgovora
Novi razgovor -
-
-
Current SIEM doesn't support this but hoping to use Git and SharePoint in tandem. Git for the actual bones of the rules - hopefully some in SIGMA format, and SharePoint for the knowledge around the rules (what they look for, false positives etc.
-
You just made me think: Why DON’T most SIEMs support rule versioning natively? It would be great to just revert to a rule to an earlier draft within the SIEM itself. Lots of people must have this problem.
- Još 9 drugih odgovora
Novi razgovor -
-
-
Documentation? Nah. AI handles everything!

-
This sounds like “Who needs comments? Just read the code.”pic.twitter.com/F4LdzO4Bit
Kraj razgovora
Novi razgovor -
-
-
We host use case workshops monthly and track by I’d
-
Great point! It’s the use case review that really causes the need for version control. I prefer bi-monthly review with the SOC (to understand the use cases causing them the most pain & false-positives).
Kraj razgovora
Novi razgovor -
-
-
lol
- Još 4 druga odgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.