Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityLernen Sie Linux-Befehle mit Webminal direkt im Browser(24.09.2026 um 08:00 Uhr)
Sicherheitslücken (CVE)USN-8811-1: urllib3 vulnerability(24.09.2026 um 03:39 Uhr)
Sichere ProgrammierungYour Agent Has Observability. It Doesn't Have Evals.(24.09.2026 um 07:43 Uhr)
Sichere ProgrammierungProtocol Upgrade Compatibility Review: Robinhood(24.09.2026 um 07:45 Uhr)
Sichere ProgrammierungYour tests share your blind spots. Readers don't.(24.09.2026 um 07:52 Uhr)
Sichere ProgrammierungYour AI agent has more permissions than your users(24.09.2026 um 07:54 Uhr)
Windows Tipps & SecurityLernen Sie Linux-Befehle mit Webminal direkt im Browser(24.09.2026 um 08:00 Uhr)
Sicherheitslücken (CVE)USN-8811-1: urllib3 vulnerability(24.09.2026 um 03:39 Uhr)
Sichere ProgrammierungYour Agent Has Observability. It Doesn't Have Evals.(24.09.2026 um 07:43 Uhr)
Sichere ProgrammierungProtocol Upgrade Compatibility Review: Robinhood(24.09.2026 um 07:45 Uhr)
Sichere ProgrammierungYour tests share your blind spots. Readers don't.(24.09.2026 um 07:52 Uhr)
Sichere ProgrammierungYour AI agent has more permissions than your users(24.09.2026 um 07:54 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Using Graphify to turn Incident Data into a Knowledge Graph

A few days ago Andrej Karpathy said we should build LLM powered knowledge bases. Within 48 hours someone made Graphify, a tool that turns raw data into a semantic knowledge graph with a single command. But what if we applied this idea to…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

A few days ago Andrej Karpathy said we should build LLM powered knowledge bases. Within 48 hours someone made Graphify, a tool that turns raw data into a semantic knowledge graph with a single command.



But what if we applied this idea to incident management?









The Problem with Incident Data



Most incident management tools tell you what just happened:




  • Incident created

  • Alerts triggered

  • Timeline recorded



But during an actual incident, that’s not what you need. What you really need is:




  • What happened last time this service broke?

  • Who responded?

  • What fixed it?

  • What’s likely to break next?



That information exists but is buried across Slack threads, postmortems, dashboards, and logs. It’s not connected.









From Logs to Graph



We took incident data (services, alerts, responders, teams, timelines) and fed it into Graphify. Instead of treating incidents as isolated logs, they become part of a semantic graph:



Nodes: services, incidents, alerts, responders

Edges: relationships between them (co-occurrence, ownership, causality)



Now instead of querying logs, you’re querying relationships.









What This Unlocks



1. Instant Incident Memory

When a new incident fires, you can query:




What happened last time this service broke?




And immediately get:




  • similar incidents

  • who handled them

  • what actions resolved them



No more Slack archaeology.



2. Blast Radius Prediction

If Service X goes down, the graph can tell you:




Services Y and Z usually fail shortly after.




Because it has learned co-failure patterns over time.



3. Smarter Onboarding

Instead of asking a new SRE to read 200 past incidents:




Here’s the graph. These are the hot spots, these teams own these systems, this is how everything connects.




It’s a map of your infrastructure reality across time, not a boring and unconnected documentation.



4. Team Load Visibility

You can connect:




  • incident volume

  • team ownership

  • responder activity



And suddenly see which teams absorbed the most load relative to their size? This is where things like burnout start to become visible in the data.



5. Alert Signal vs Noise

Because alerts are tied to actual incidents in the graph, you can rank:




  • alerts that frequently lead to real incidents

  • alerts that never matter



This gives you a way to tune or delete alerts backed by evidence



6. Surfacing Dependencies

Some services consistently fail together, even if no one documented the dependency.

The graph reveals what actually depends on what based on real incidents, team and alert data.









Where This Gets Really Interesting



Once you have this graph, it becomes a foundation for:




  • Slack bots that auto-post relevant context during incidents

  • AI SREs with memory

  • Querying your system like a knowledge base instead of dashboards
    This gives the power for on-call teams to not only rediscover solutions but build accumulated knowledge.



This shifts on-call teams from repeatedly rediscovering solutions to building accumulated knowledge over time.






Small Plug (If You Use Rootly)



If you’re using Rootly, I built a small plugin to explore your incident data with Graphify:



rootly-graphify-importer

https://github.com/Rootly-AI-Labs/rootly-graphify-importer









Final Thoughts



Incident management data is already rich. It's full of signals across alerts, incidents, and responses but rarely captures how things relate.



Graphify flips that, turning logs to knowledge, building connections across events, and turning history into memory.



Once you see your system as a graph that turns scattered data into something you can filter, query, and explore, it’s hard to go back.

SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - Using Graphify to turn Incident Data into a Knowledge Graph
id: 57ddaaab-c83f-4f30-9e49-0649c79da06c
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "Using Graphify to turn Inciden" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Using Graphify to turn Incident Data int.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Using Graphify to turn Incident Data into a Knowledge Graph

Thematisch verwandte Begriffe: Using, Graphify, turn, Incident · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96676 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impa…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick