Skip to content
Header Image

Threat Intelligence

  • Alerts
  • Downloads
  • Links
  • IOC Feeds

Category: sentinel

AI sentinel SentinelOne siem

A long way to go for AI implementations in SIEM platforms

September 6, 2025September 6, 2025

Trend Agentic AI SIEM Microsoft Sentinel Security CoPilot   SentinelOne Purple AI Purple AI supports a variety of data sources…

Nifi Groovyscript to convert JSON table array to key value JSON format
Nifi sentinel SentinelOne siem

Nifi Groovyscript to convert JSON table array to key value JSON format

August 4, 2025August 27, 2025

If you have data in a nested table array you can convert it to the standard key:value JSONpair by using…

Credential stuffing attacks against Azure Portal from Set User Agent and Device
sentinel Threat Intelligence

Credential stuffing attacks against Azure Portal from Set User Agent and Device

December 17, 2024December 17, 2024

We have recently identified a persistent credential stuffing attack against some of our customers. Credential stuffing is a cyberattack method in which…

Pushing Bulk Indicators to Multiple Sentinel Instances for a MSSP
Nifi sentinel Threat Intelligence

Pushing Bulk Indicators to Multiple Sentinel Instances for a MSSP

November 29, 2024November 29, 2024

Problem We manage a MISP instance which receives over 130,000 IOCs every day from multiple sources which we need to…

SIEM Log Ingestion – To filter or to deduplicate
logstash sentinel siem

SIEM Log Ingestion – To filter or to deduplicate

April 24, 2024April 24, 2024

Why Should You Manage Your Log Ingestion? Cost Implications SIEM tools operate under a licensing model that typically charges based…

Sentinel Parsing Data at Ingestion or at Query time
sentinel siem

Sentinel Parsing Data at Ingestion or at Query time

April 1, 2024December 10, 2024

There are different options for parsing data in Microsoft Sentinel.  Query time parsing when the parsing is done when an…

Why is the Sentinel Threat Intelligence Indicator API so full of bugs
sentinel siem Threat Intelligence

Why is the Sentinel Threat Intelligence Indicator API so full of bugs

March 14, 2024December 17, 2024

Microsoft have an API to add IOCs to the threat intelligence module in sentinel which can you read about here.…

Filebeat write: failed to publish events / connection reset by peer
filebeat logstash sentinel

Filebeat write: failed to publish events / connection reset by peer

January 18, 2024January 18, 2024

I was using filebeat to listen on port 514 to accept rsyslog messages from AIX servers with the aim of…

Microsoft Sentinel Watchlists and wildcard/partial/substring table joins in KQL
sentinel

Microsoft Sentinel Watchlists and wildcard/partial/substring table joins in KQL

January 12, 2024January 12, 2024

Watchlists are a great way to house data in a table format to be used for various purposes, be it…

Copyright © 2025 Threat Intelligence | Ace News by Ascendoor | Powered by WordPress.