frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Standardize on OCSF to run your own detection rules?

2•julian-datable•7mo ago
Anyone adopted OCSF as their canonical logging schema?

Hoping to cut parsing overhead and make detection rule writing easier. Currently mapping 20-odd sources.

Any lessons/red flags you can share?