Blog
Security research, threat analysis, and product updates from the AlphaSOC team.

Enhanced Threat Detection with Sigma and AlphaSOC Wisdom
AlphaSOC Wisdom brings threat intelligence directly into Sigma rules, enriching detections with domain reputation, infrastructure type, and behavioral risk flags: no external feeds required.

Sigma Correlations in AlphaSOC
AlphaSOC now supports Sigma Correlations, linking multiple events over time to produce high-confidence OCSF findings for multi-stage attack patterns that individual rules miss.

Introducing the AlphaSOC Cribl Dashboard
The AlphaSOC for Cribl Search pack brings OCSF detection findings into a purpose-built dashboard for triage, entity analysis, and raw event inspection.

Azure Event Hubs Silently Truncates JSON Payloads
Azure Event Hubs truncates JSON logs that exceed undocumented size limits, appending "..." and producing invalid JSON with no error or warning. Here is how we found it and fixed it.

Finding Patient Zero With Security Analytics
Most detection stacks confirm compromise after the fact. Learn how prevalence analysis and correlation surface the earliest foothold before feeds catch up.