Elasticsearch is the only 3rd party grounding source on Vertex AI today #GoogleCloudNEXT
* Answer with private data — see the difference for "how to patch a drywall"
* Keyword, semantic & hybrid search
* Search templates to personalize
* Via Vertex API / SDK or UI
– PK (@xeraa)
Implementar un Centro de Operaciones de Seguridad (SOC) utilizando Kali Linux en AWS
OPNsense Firewall
Kali Linux Purple
Cyberchef
Elasticsearch SIEM
GVM vulnerability scanner
TheHive incident response
Malcolm
Suricata IDS
Zeek IDS
https://t.co/0FRoWzYgKo
🚨Data Breach Alert - IBM
The threat actor "888" claims to have accessed 17,500 rows of data belonging to IBM in October 2024.
The compromised data, managed by a third-party provider, includes sensitive information of current and former IBM employees, specifically first names, full names, mobile numbers, and country codes.
Next up in our Elastic Snackable Series 🎬 @xeraa is discussing Playground. Find out its importance and how you can use it to explore the future of search in the full video here: https://t.co/n1FaPIdk7X
#GenerativeAI
Elastic accelerates logs onboarding with Automatic Import powered by Search AI. Migrate legacy logs to AI-driven log analytics in record time by automating custom data integrations. Get the details here: https://t.co/tQkwlGSpyF
Faster detection. Real-time insights. Unparalleled efficiencies.
Join our upcoming webinar on Sept 12 with @Azure to see how #SRE teams are supercharging #observability by integrating LLMs and AI assistants into their workflows. Get the details → https://t.co/bLr1VZBzPw
A good read by @ateixei that you should check out https://t.co/57bt2jnxAp
Just wanted to add a small take and perhaps expand on an idea that was highlighted in the article.
Before even reading, the answer should be obvious. EDR and Sysmon share only 2 basic things in common, which are they're both on the endpoint and they both generate telemetry. That's where the comparison ends.
If you're looking for both Detection and Response (the rest of the acronym) and 20 other features including managing deployments, alerts, incidents, etc. The answer was never ambiguous - GET AN EDR, ALWAYS.
So why do people even argue this (sometimes?). Its because not all EDRs are equal in telemetry.
Sysmon is simply a telemetry generation tool, one could even argue the security auditing that we enable with group policy is also another telemetry "tool" (that is even harder to manage). But some "mature" teams do it anyway. Why?
The answer is "custom use cases". Your uses cases will never be "all" covered by EDR built-in detections that's why custom detection exists. But, what if you want to detect something so crucial but no telemetry is provided by your EDR. You turn around to extra telemetry tooling (aka sysmon, security auditing or other shenanigans).
Is it worth it? You be the judge, but it does have its merit.
Raymond #Poulidor trône désormais sur la montée du Pla d’Adet après une célébration empreinte d’émotion #cyclisme#mémoire#Pyrénées https://t.co/A1uxfja2p4