Talk With an Expert

Consolidating Relevant Events Logs and Alerts

Consolidating Relevant Events Logs and Alerts (PDF, 2.91MB)Last updated: 24 Jul, 2025
Presented by:
Ezz Tahoun
Ezz Tahoun

In modern cybersecurity, the ability to connect isolated security alerts into coherent, actionable attack chains is essential. However, traditional detection methods often struggle to contextualize vast amounts of security data, leaving slow and stealthy attacks undetected within a sea of noise and false positives. This talk introduces a novel approach using open-source AI models to map, cluster, and correlate security alerts in order to uncover coordinated attacks. Through clustering, knowledge graphs, and AI-driven correlation, this approach offers significant improvements in SOC (Security Operations Center) efficiency and effectiveness. We detail the methodology, open source tools, and results of this approach across diverse environments, including cloud, telecom, and industrial control systems.

SANS DFIR Summit 2025