SIEM Hyper Queries: atomic alerts, correlation and other hard truths (part II/II)

Alright, it’s been more than a year after publishing the first part of this article, so time to remove it from drafts.

In case you haven’t checked the first part entirely, let's start with a quick recap on what a SIEM Hyper Query is about if you want to take it from here.

Hyper Query ⁉️

Hyper is a prefix from Greek meaning “over,” usually implying excess or exaggeration (hyperbole).

--

--

Blueteamer. Love logz. Threat Detection Engineering & Security Analytics. Independent contractor. Opstune.com #followback

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Alex Teixeira

Blueteamer. Love logz. Threat Detection Engineering & Security Analytics. Independent contractor. Opstune.com #followback