Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “Sigma”
4 publicationsTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysis
Testing Sigma detections before a backend change
Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.
Detection & response · SigmaHQ · By Cloud Security DeskThe telemetry collector is part of the evidence boundary
Review sender identity, tenant routing, processing and export as separate trust boundaries before treating collected telemetry as dependable evidence.
Detection & response · OpenTelemetry · By Cloud Security DeskCloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Detection & response · MITRE · By Cloud Security DeskChoose the S3 object events your investigation will need
CloudTrail event history is not an object-access ledger. Build selectors around the questions an investigation must answer, then test the exclusions.
Detection & response · AWS · By Cloud Security Desk