Thread Reader
Share this page!
×
Post
Share
Email
Enter URL or ID to Unroll
×
Unroll Thread
You can paste full URL like: https://x.com/threadreaderapp/status/1644127596119195649
or just the ID like: 1644127596119195649
How to get URL link on X (Twitter) App
On the Twitter thread, click on
or
icon on the bottom
Click again on
or
Share Via icon
Click on
Copy Link to Tweet
Paste it above and click "Unroll Thread"!
More info at
Twitter Help
Gabriel Odusanya | CyberSecurity◽
@gabbytech01
Security Engineer | SOC & Blue Team Daily alert triage • SIEM rules • Incident response (remote role) TryHackMe Top 1% • Open to new SOC opportunities
Subscribe
Save as PDF
Mar 12
•
6 tweets
•
1 min read
5 SIEM rules I actually use every day in production (and why they work)
I triage 200+ alerts daily in my remote SOC role.
These 5 rules have cut my false positives by ~40% and caught real threats.
Thread 👇 #SOC #BlueTeam #SIEM Rule 1: “Failed logins from new country + new device in <5 min”
Trigger: Okta + endpoint logs show login from Nigeria + brand-new laptop.
Action: Auto-create ticket + notify user.
9/10 times it’s just a VPN change… but the 1/10 is credential stuffing.
Saved us twice last month.