Summary
In this chapter, the correlation topic was addressed. We first introduced the different types of correlation that exist, as well as the SIEM solutions and their philosophy, specifically the difference between correlation and enrichment at ingestion or search/query.
We then introduced different query languages, such as SPL and KQL, with practical real-world situations on how we could leverage them to perform basic and advanced detections based on statistical analysis and frequency detections.
The series of blue team chapters ends here. In the next chapter, we will introduce the overall infrastructure needed to perform purple teaming, and we will explore different types of solutions dedicated to purple teaming. We will also see how the DevOps mindset can help us develop our capabilities.