R-Vision SIEM Debuts at Standoff 17 Cyber Battle and Processes 8.8 Million Correlation Events
R-Vision has published a detailed account of its first participation with R-Vision SIEM at the Standoff 17 cyber battle. The system was deployed for the akPots defender team to monitor a telecom-operator infrastructure, detect attacks and investigate incidents under conditions that closely resemble a real SOC environment.
Preparation began two weeks before the event. Approximately 80 percent of the event sources used in the Standoff infrastructure were already supported natively. The remaining 20 percent required the addition of two new sources, normalization adjustments for four sources, four new correlation rules and modifications to fifteen existing rules.
During the four-day exercise the system triggered 46 correlation rules, producing more than 8.8 million correlation events and 40 thousand alerts. The most frequent detections involved behavioral analysis from PT NAD, PT Container Security events, privilege-escalation attempts, web attacks and vulnerability exploitation.
Analysts actively used the platform, creating 13 custom widgets, 14 quick filters and running more than 9,000 search queries. Average query execution time was 1.5 seconds, with the heaviest query completing in four seconds while consuming 1.58 GB of ClickHouse memory.
The deployment was sized for an expected maximum of 3,000 events per second. Actual resource usage stayed modest: the collector averaged 0.7 CPU cores and 1.9 GB RAM, never exceeding 2.9 CPU cores and 3.5 GB RAM at peak. Team members gave the product scores of 4 or 5 out of 5 and indicated they would recommend it to colleagues, citing raw-text search, the RQL query language and event-grouping capabilities as the most valuable features.
Related articles
From Security Champion to Engineering Security Culture: MTS Web Services Transforms DevSecOps Approach
MTS Web Services has shifted from a single Security Champion per team model to a broader engineering security culture that distributes responsibility across multiple specialists. The previous approach created overload for appointed champions, offered insufficient training, and failed to motivate appointed participants to grow their skills. The new strategy emphasizes voluntary participation, professional development through dedicated tracks, and integration of security practices into daily workflows and onboarding. Key changes include forming a DevSecOps guild, running regular workshops and Q&A sessions, embedding vulnerability scan results into team metrics, and adding competency maps with role-specific learning paths. The company now recognizes security heroes and high-performing teams while linking basic security training completion to performance indicators. Results show organic growth in engagement, with event numbers rising from a handful in 2023 to 18 in 2025 and product teams independently adopting secure development practices.
Security Vision SIEM Adds Monitoring for Missing Logs, Correlation Quality, and SOC SLA Compliance
Security Vision has released a major update to its SIEM platform that extends monitoring beyond external threats to the health of the data collection pipeline itself. The new release introduces continuous checks for source stability, allowing administrators to define acceptable event flow deviations and receive alerts when logs suddenly stop arriving. A dedicated dashboard now evaluates correlation rule performance through testing on simulated events and supports import/export in Sigma format for easier detection sharing across platforms. The StatAnalyser service applies statistical models to flag atypical behavior with special markers, while the incident card gains automated retrospective process-chain reconstruction that links parent processes, user sessions, and host movements. Additional oversight features track analyst SLA adherence and let managers drill from team-wide statistics into individual performance metrics. Overall, the platform aims to close the loop from data ingestion through detection, investigation, and response within a single managed workflow.
ManticoreSearch Publishes Detailed Checklist for Enabling Authentication in Production
ManticoreSearch has released an extensive checklist for safely enabling authentication in production deployments. The guide covers standalone nodes, distributed tables with remote agents, and replication clusters, stressing the need for thorough inventory of clients and nodes before changes. It details procedures for creating users with minimal privileges, testing in staging environments, and performing controlled rollouts during maintenance windows. Special attention is given to handling Bearer tokens, protecting auth.json files, and ensuring consistent authentication data across cluster nodes. The document also explains differences between RT-mode and plain-mode configurations and provides commands for initializing the first administrator and reloading authentication settings.
WhatsApp Web Gains Native Audio and Video Calling with Screen Sharing and Device Switching
WhatsApp, owned by Meta, is rolling out audio and video calling directly in its web version, eliminating the previous need for a separate desktop application. The update introduces a Calls tab with call history and favorite contacts, along with screen sharing and reactions that match most desktop app capabilities. Calls can now seamlessly transfer between devices without disconnection, allowing users to start a conversation in a browser and continue it on a smartphone. Group calls gain waiting rooms where the link creator can require manual approval for entry, useful for professional meetings. Additional improvements include background noise suppression, faster transition to HD video quality, and the ability to call users via usernames across platforms without sharing phone numbers.