User loginNavigation |
archivesNew DSL for secueityHello,thought I’d share a new DSL by endgame life querying security logs : https://www.endgame.com/blog/technical-blog/introducing-event-query-language It is meant to help reason about security events. Best illustrated in this example: What files were created by non-system users, first ran as a non-system process, and later ran as a system-level process within an hour? I think that there is a lot of improvement that can be had in. languages that help reason about (time) series and it’s a welcome addition to the DSL family. By True Konrads at 2018-06-05 23:31 | LtU Forum | login or register to post comments | other blogs | 3029 reads
|
Browse archivesActive forum topics |
Recent comments
3 weeks 2 days ago
3 weeks 3 days ago
15 weeks 4 days ago
15 weeks 4 days ago
15 weeks 6 days ago
15 weeks 6 days ago
16 weeks 4 days ago
16 weeks 4 days ago
16 weeks 4 days ago
19 weeks 4 days ago