Positive Technologies Releases MaxPatrol SIEM 28.0 with Major Resource Optimizations and AI Enhancements
Positive Technologies has released MaxPatrol SIEM 28.0, offering SOC teams the ability to extract more value from existing servers. According to the vendor’s internal tests, the updated system consumes up to 26% less CPU resources and up to 52% less RAM than the previous version, potentially allowing organizations to postpone hardware purchases.
Developers focused on optimizing the components responsible for security event processing and data storage. In the example provided by the company, the version 27.6 component processed 20,000 events per second, while the updated version handles 40,000 events per second on comparable hardware resources.
The architecture has also been revised. When MaxPatrol SIEM operates separately from other platform products such as MaxPatrol VM, unnecessary roles can be excluded during installation, freeing additional resources by reducing the number of installed components.
The behavioral analysis module MaxPatrol BAD received a significant update. The new HackTracker component detects attackers based on behavioral patterns rather than solely on the tools they use. The module now analyzes events from Unix nodes and links them into chains of suspicious activity.
Configuration of the AI assistant PT Naira has been simplified. The assistant helps write normalization rules, explains events, and searches documentation. The developer states that the assistant can reduce investigation time by up to 50% and the effort required to create rules by up to 90%. Updates to the assistant will be released independently of SIEM version releases.
Analysts received additional context in the cards of standard correlation rules, quick navigation to relevant sections, and a native dark theme that does not affect server load but improves usability during night shifts.
Version 28.0 is already available for independent installation. The main focus of the release remains increasing processing capacity without mandatory acquisition of new servers.
Related articles
Hash Functions Part 1: Core Properties, Security Requirements and Practical Applications
The article provides a detailed introduction to hash functions, explaining how they map arbitrary-length input to fixed-length output while satisfying three fundamental security properties. It covers preimage resistance, second preimage resistance, and collision resistance, along with the avalanche effect that makes even minor input changes produce unrecognizable output. The text explains why a 256-bit digest is required to achieve 128-bit collision resistance, referencing the birthday paradox and its implications for MD5 and SHA-1. Practical guidance includes using OpenSSL for hashing, applying hashes in commitment schemes, enforcing subresource integrity on web pages, and securely storing passwords with Argon2 and bcrypt. The post emphasizes that hash functions alone do not guarantee integrity without proper transmission of the digest and announces a follow-up on SHA-2 and SHA-3 internals.
Digital Twins Enable Pre-Deployment Testing and Post-Change Control in Complex Multi-Vendor Networks
UserGate and Hadal Project experts presented a joint approach at Saint HighLoad++ that combines physical labs, emulation, and simulation into a single lifecycle for validating network changes. The method addresses recurring failures such as IPsec tunnel outages after routine software updates that pass vendor checks yet break branch connectivity. Three complexity sources—multi-vendor environments, historical configuration debt, and continuous dynamic updates—are mitigated by maintaining an always-current network model. Physical laboratories provide hardware-level accuracy for critical devices, while uInfraTwin emulation allows rapid, repeatable testing of configuration scenarios with traffic generators. Simulation tools including Batfish, Hadal, Forward Networks, and IP Fabric deliver end-to-end reachability analysis across tens of thousands of nodes without sending test traffic on production networks. The integrated digital twin continuously updates from live infrastructure, feeds selected segments into safe test environments, and verifies policy compliance after deployment.
macOS User Investigates Claude Regional Block via Logs and Restores Work Site Access with Targeted WireGuard Routes
A detailed case study describes how a macOS user analyzed Claude application logs after experiencing regional unavailability errors while using WireGuard VPN. The investigation covered ~/Library/Logs/Claude/ files containing markers like app-unavailable-in-region and region_unavailable, cross-referenced with tunnel activity dates from August to October 2026. No direct evidence linked the VPN to the account block, as tunnel logs were overwritten and system journals returned Operation not permitted errors. The user then addressed a secondary issue where WireGuard blocked access to work services including amoCRM, TGBooster, and Geekjob. Custom host routes were added via route add commands to direct specific IPv4 addresses through the local gateway while keeping Claude traffic in the tunnel. A launchd-based PF kill switch was tested for tunnel failure protection but caused a full internet outage on October 5 due to anchor and hook conflicts, leading to its rollback. By October 8, work sites functioned under VPN with verified routes, though persistent kill switch protection remained unresolved.
Publishing Internal APIs from DMZ Without Direct LAN Connections: Five Tested Architectures
When an API gateway resides in the DMZ but security policies forbid outbound connections into the LAN, organizations must adopt alternative patterns to expose internal services synchronously. The article examines five production-ready approaches built on the NEOMSA APIM platform, ranging from custom request-reply logic over Kafka to zero-code solutions using ActiveMQ Artemis and experimental reverse HTTP in HAProxy. Each pattern is evaluated against criteria such as the need for DMZ-to-LAN firewall rules, volume of custom code, support for streaming responses, and measured performance. Load tests on the Artemis-based bridge reached 50 requests per second with a 95th percentile latency of approximately 100 ms, while the Kafka implementation required roughly 2,500 lines of Java to emulate missing reply semantics. The analysis highlights trade-offs in operational complexity, vendor support implications, and security posture, particularly the benefit of preventing any outbound initiation from the DMZ.