SecuritylabAugust 4, 2026🇷🇺Translated from Russian

Security Vision SIEM Tackles Alert Overload with Data Quality Monitoring and MITRE ATT&CK Coverage

In November 2013, a FireEye system costing 1.6 million dollars performed exactly as promised. It detected malware on Target point-of-sale terminals, generated multiple consecutive alerts, and even revealed intermediate servers receiving stolen data. The Bangalore shift noticed the signal and escalated it to Minneapolis, yet nothing further happened.

One month later the company disclosed the theft of 40 million payment cards and personal data of another 70 million people, with direct costs exceeding 200 million dollars. The automatic malware removal function had been manually disabled. Technology worked; process did not.

Since then much has changed, except the core issue. According to Vectra AI data for 2026, organizations receive an average of 2,992 alerts per day, and 63 percent of them remain uninvestigated. The Microsoft and Omdia SOC report adds further detail: 46 percent of alerts prove false positives. In the SANS 2025 survey, 73 percent of teams named false positives the primary detection problem. Analysts simultaneously juggle an average of 10.9 consoles.

Collecting logs is inexpensive and straightforward. Turning those logs into a managed process that reveals data quality, detection quality, and the full incident path is considerably harder.

What Security Vision SIEM Can Do

The product, built on the Russian Security Vision 5 Low-Code/No-Code platform, combines event collection and normalization, data quality control, attack detection, investigation, and basic response actions. Customers receive not an empty box with a promise to configure it themselves, but ready SOC expertise: more than 1,200 correlation rules, coverage of over 70 percent of MITRE ATT&CK techniques, mapping to FSTEC BDU threat implementation methods, and incident handling recommendations.

The July 2026 update introduced monitoring of collection stability and rule performance, SOC analyst SLA control, statistical anomaly detection, rule testing, Sigma rule exchange, and retrospective process chain reconstruction inside incidents.

Three Levels Where Everything Can Break

SIEM effectiveness rests on data completeness, detection quality, and response speed. Failure at any level nullifies the other two.

  • Level one: The SOC must be confident that required events actually arrive. Agents stop, administrators change logging settings for unrelated reasons, or hosts behind WEC or syslog aggregators silently drop out while the aggregator reports healthy status.
  • Level two: Detection rules must reflect real attack scenarios, infrastructure specifics, and temporal event relationships. Simple signatures rarely catch multi-stage attacks when events from different sources arrive delayed and interleaved.
  • Level three: Detection is only the start. Analysts must assess asset criticality, examine processes, accounts, network connections, lateral movement, confirm the incident, and act. Each manual tool switch adds minutes that accumulate into the 200 million dollar losses seen at Target.

Security Vision SIEM unites the entire chain: connect sources, verify data quality, detect suspicious activity, reconstruct attack context, and move to response.

Related articles

SecuritylabOther

Hashcat Password Cracking: Why Complex Passwords Like Summer2026! Often Fail First

Password cracking tools such as hashcat and John the Ripper exploit predictable human patterns when generating candidates, allowing structured passwords to be recovered faster than truly random strings. The process relies on comparing computed hashes against stored values without needing to reverse the one-way function. Modern password storage uses salted, computationally expensive algorithms including bcrypt, Argon2id, sha512crypt and yescrypt to increase the cost of each guess. Different formats require specific hashcat modes, and parameters such as cost factors or memory settings directly affect cracking speed. WordPress 6.8 introduced bcrypt with SHA-384 preprocessing while older phpass records remain supported. Audits must preserve full hash records, verify modes on test data, and combine dictionaries, rules, masks and statistical models to measure real risk. After testing, organizations should migrate to properly tuned Argon2id and enforce long unique passphrases managed by password managers.

HabrOther

Why HTTP to HTTPS Redirects Fall Short: Risks of Exposed Requests and the Role of HSTS Preload

A simple HTTP to HTTPS redirect satisfies basic audit requirements but leaves the initial request fully exposed in plaintext. The request carries the full path, query parameters, and cookies lacking the Secure flag, allowing observers on open Wi-Fi or compromised routers to read or tamper with traffic before TLS begins. Modern browsers such as Chrome since version 90 attempt HTTPS first, yet legacy clients, explicit http:// links in emails, scripts, and failed HTTPS fallbacks continue to send unprotected requests. HSTS instructs browsers to use HTTPS after the first successful visit, yet the header itself travels over HTTPS and cannot protect the very first connection from a new device or cleared cache. Preloading embeds the rule directly in the browser, eliminating the initial plaintext request entirely, but demands includeSubDomains and a one-year max-age, making the change effectively irreversible for months. The article recommends verifying Secure flags on all cookies, ensuring single-step redirects to the same host, and testing HSTS incrementally before considering preload.

HabrOther

OSINT for the Lazy Part 18: Extracting Value from Wayback Machine Archives for Bug Bounty and Security Research

The article explores passive reconnaissance techniques using web archive tools to uncover forgotten endpoints, configuration files, and sensitive parameters without directly interacting with target systems. It highlights three command-line utilities—waybackurls, gau, and waymore—that query public archives such as Wayback Machine, Common Crawl, AlienVault OTX, and URLScan to retrieve historical URLs. These tools help bug bounty hunters and penetration testers discover old API endpoints, admin panels, backup files, and JavaScript with hardcoded secrets that may still be exploitable. Installation instructions, usage examples, and filtering options are provided for each tool to maximize efficiency and reduce noise in results. The piece emphasizes that all methods remain fully passive, minimizing detection risk while requiring proper authorization before any active testing. Advanced users are advised to combine the tools for broader coverage and deeper analysis of archived responses.

HabrOther

OSINT Investigation Exposes Fraudulent Russian Garlic Investment Scheme Masquerading as Local Production

An in-depth OSINT probe into a Russian agricultural investment project promising 50-70% annual returns from garlic farming has revealed a likely import arbitrage operation sourcing produce from China and Uzbekistan. The project claimed ownership of over 300 hectares of fields, a proprietary seed fund, and guaranteed sales to major retailers including Magnit, Perekrestok, Pyaterochka, and Svetofor, yet public records show minimal profitability and heavy debt. Financial statements from linked cooperatives indicated just 2.2% net margin alongside loans exceeding annual revenue fourfold, pointing to reliance on continuous new investor capital. Registry checks confirmed no financial licenses, no seed-breeding status, and actual cultivated land far below advertised figures. Import declarations and equipment registrations further indicated the operation functions as a repackaging hub for foreign garlic sold under private labels. The parent group has been placed on the Bank of Russia blacklist, with related sites blocked by Roskomnadzor while Telegram channels continue aggressive marketing.