Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT Security NachrichtenIP Fabric 8.1 adds application-aware mapping and cloud-native data model(24.09.2026 um 19:52 Uhr)
•
IT Security NachrichtenExposed GitLab project email addresses let attackers push code(24.09.2026 um 19:47 Uhr)
•
IT Security NachrichtenIntegration von Luft- und Flüssigkeitskühlung - Netzpalaver(24.09.2026 um 14:20 Uhr)
••
IT Security NachrichtenNeu: Saferinternet.at-Seite für Schulen - Onlinesicherheit(24.09.2026 um 15:08 Uhr)
•
IT Security NachrichtenWarum jeder KI-Agent als privilegierter Nutzer gelten muss - it-daily(24.09.2026 um 15:24 Uhr)
••
IT Security NachrichtenDie Cybersicherheit der Schweiz durch Kooperation stärken(24.09.2026 um 17:10 Uhr)
••
IT Security NachrichtenAlert Fatigue - Wenn der Alarm zur Gewohnheit wird(24.09.2026 um 17:23 Uhr)
•
IT Security NachrichtenIP Fabric 8.1 adds application-aware mapping and cloud-native data model(24.09.2026 um 19:52 Uhr)
•
IT Security NachrichtenExposed GitLab project email addresses let attackers push code(24.09.2026 um 19:47 Uhr)
•
IT Security NachrichtenIntegration von Luft- und Flüssigkeitskühlung - Netzpalaver(24.09.2026 um 14:20 Uhr)
••
IT Security NachrichtenNeu: Saferinternet.at-Seite für Schulen - Onlinesicherheit(24.09.2026 um 15:08 Uhr)
•
IT Security NachrichtenWarum jeder KI-Agent als privilegierter Nutzer gelten muss - it-daily(24.09.2026 um 15:24 Uhr)
••
IT Security NachrichtenDie Cybersicherheit der Schweiz durch Kooperation stärken(24.09.2026 um 17:10 Uhr)
••
IT Security NachrichtenAlert Fatigue - Wenn der Alarm zur Gewohnheit wird(24.09.2026 um 17:23 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Blue Watch, Day 4-6: From Alerts to a Story

If you've been following along, Blue Watch is my mini-SIEM: parse logs, detect suspicious patterns, generate alerts, all config-first. Day 1-3 got me a parser, a rules file, and a detector that fires four correct alerts on my test attack…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

If you've been following along, Blue Watch is my mini-SIEM: parse logs, detect suspicious patterns, generate alerts, all config-first. Day 1-3 got me a parser, a rules file, and a detector that fires four correct alerts on my test attack scenario with zero false positives.



Four alerts is nice. But four alerts sitting in a list still isn't an incident. That's what the last three days were about: turning raw alerts into a score, and a score into a story.



*The problem: one attacker, four disguises

*


My test scenario has a single attacker brute-forcing admin, spinning up a backdoor user shelly, and reading /etc/shadow. But the alerts that come out of the detector don't know they're all the same person. One alert is tagged by IP. Another is tagged by username. Without something to unify them, my "incident" looks like four unrelated blips instead of one attacker's full campaign.



That's the job of scorer.py.



build_ip_to_user_map() and get_entity()



First step: figure out which IPs and users actually belong together. build_ip_to_user_map() walks the event stream and links every IP to the users who logged in from it.



Then get_entity() decides who an alert really "belongs to," in priority order:



first_user if the alert carries one (this covers privilege-escalation alerts, where the original attacker identity matters more than whoever they became)

user, if present

otherwise, the IP mapped back to a user via the map from step one



That fallback chain is the whole trick. It's the difference between four disconnected alerts and one entity with four alerts against its name.



Scoring severity into a single number



Once every alert has an owner, score_alerts() sums up severity points per entity:



low: 20

medium: 50

high: 70

critical: 100



Then score_to_level() converts the total back into a human label: LOW, MEDIUM, HIGH, or CRITICAL. Simple, but it's the layer that turns "a pile of alerts" into "a number a human can triage against."



The output layer



Two ways to see the result:



save_alerts_json() writes a structured output/alerts.json — machine-readable, ready to feed into whatever comes next.

print_report_table() renders the same data as a clean terminal table, for when I just want to glance at it.



Run against the test scenario, everything unifies the way it should: admin → 290 points → CRITICAL, with all four alerts correctly attributed to one entity. Exactly what four separate, disguised alerts should have added up to.



Day 6: the timeline



Scoring answers "how bad is this?" The last piece answers "what actually happened, in order?"



timeline.py is deliberately small:



build_timeline() sorts every event chronologically. The nice trick here: ISO 8601 timestamps sort correctly as plain strings, so there's no datetime parsing needed — just a string sort.

print_timeline() renders the play-by-play with generic field display, meaning it doesn't need special-case logic for each event type. Any event shape that comes out of the parser just... prints.



The payoff is the full 12-event story, in order, with luna's ordinary login sitting exactly where it should — mid-sequence, clearly harmless noise next to the actual attack. That's the detail I was hoping for: a good detector doesn't just catch the bad stuff, it also stays quiet about the normal stuff sitting right next to it.

SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - Blue Watch, Day 4-6: From Alerts to a Story
id: 52f1bdda-fa3c-4ee0-bbb6-aa238063eb88
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "Blue Watch, Day 4-6: From Aler" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Blue Watch, Day 4-6: From Alerts to a St.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Modul-Fehler (similar): Das Modul konnte nicht geladen werden.
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-79764 | Termix is a web-based server management platform with SSH terminal, tunn…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle