Gabriel Odusanya | CyberSecurity◽ Profile picture
Security Engineer | SOC & Blue Team Daily alert triage • SIEM rules • Incident response (remote role) TryHackMe Top 1% • Open to new SOC opportunities
Mar 12 6 tweets 1 min read
5 SIEM rules I actually use every day in production (and why they work)

I triage 200+ alerts daily in my remote SOC role.
These 5 rules have cut my false positives by ~40% and caught real threats.

Thread 👇 #SOC #BlueTeam #SIEM Rule 1: “Failed logins from new country + new device in <5 min”

Trigger: Okta + endpoint logs show login from Nigeria + brand-new laptop.

Action: Auto-create ticket + notify user.
9/10 times it’s just a VPN change… but the 1/10 is credential stuffing.

Saved us twice last month.