Skip to main content

Hi, I’d like to ask where the alert data on SecOps is sourced from. Additionally, is this data available for further research and use in developing tools related to alert analysis?

Are you talking about the data from the alerts and IOC page? 


If so, that data is ultimately sourced from your Security Technologies and then ran through the rules engine.  Yes that can be used for SOAR cases, etc. 


Can you clarify the ask here?


Reply