User loginNavigation |
archivesNew DSL for secueityHello,thought I’d share a new DSL by endgame life querying security logs : https://www.endgame.com/blog/technical-blog/introducing-event-query-language It is meant to help reason about security events. Best illustrated in this example: What files were created by non-system users, first ran as a non-system process, and later ran as a system-level process within an hour? I think that there is a lot of improvement that can be had in. languages that help reason about (time) series and it’s a welcome addition to the DSL family. By True Konrads at 2018-06-05 23:31 | LtU Forum | login or register to post comments | other blogs | 2675 reads
|
Browse archivesActive forum topics |
Recent comments
22 weeks 4 days ago
22 weeks 4 days ago
22 weeks 4 days ago
44 weeks 5 days ago
49 weeks 9 hours ago
50 weeks 4 days ago
50 weeks 4 days ago
1 year 1 week ago
1 year 5 weeks ago
1 year 5 weeks ago