Skip to main content

Two Part Series Blog: Detecting Impossible Travel

  • August 9, 2024
  • 1 reply
  • 22 views

matthewnichols
Community Manager
Forum|alt.badge.img+16

Hey SecOps SIEM enthusiasts. We just published a part 1 of two part series blog about detecting impossible travel using SecOps SIEM. It dives into implementing detection methods using custom YARA-L Detection rule, leveraging GeoSpatial and GeoIP enrichment. Check it out here.

Part 2 SecOps SOAR coming next week.

1 reply

matthewnichols
Community Manager
Forum|alt.badge.img+16
  • Author
  • Community Manager
  • August 23, 2024

If you haven't seen it already, we just released the Part 2 blog in this series, where we take the next step and focus on building an associated SecOps SOAR Playbook to provide security analysts with an actionable alert. Check it out here