Chapter 8: Blue Team – Correlate
This chapter is the last one regarding blue team infrastructure. In this chapter, we will discuss security information and event management (SIEM). We will try to understand the philosophy of different SIEM solutions, their pros and cons, and how they can help us in our blue and purple teaming activities.
The second part of this chapter will demonstrate how to leverage Splunk's Search Processing Language (SPL) with specific functions we may not be aware of that help us perform any kind of advanced detections, such as recurring frequency, dynamic comma-separated values (CSV) push/pull, and alerts based on the Least Frequency of Occurrence (LFO). Finally, we will introduce the Kusto Query Language (KQL) used in Microsoft Defender for Endpoint (formerly known as Defender ATP) for hunting, and show practical queries useful for any investigations that could also be implemented to create specific detection rules.
We'll cover the following...