Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections.
Most teams treat that as noise. It's early-warning threat telemetry.
The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically.
https://graylog.org/post/sendmail-data-in-graylog/
#SIEM #ThreatHunting #EmailSecurity
About This Hashtag
#siem
9 posts
Last used Aug 04
#siem
9 posts· Last used Aug 04
CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
Wazuh (open-source XDR & SIEM) in v4.14.7 released
https://secburg.com/posts/wazuh-4147-released/
#Wazuh #SIEM #XDR #OpenSource #InfoSec
Important reminder for SIEM janitors to frequently check their SIEM for common password field structures to find occurrences where stuff that should not be getting logged to the SIEM is getting logged. I was reminded when I was telling a story about finding credentials and payment information in an applog that was also helpfully being indexed in the SIEM. I am recommending free form regex searches of the raw entry, not just looking for named fields. #SIEM #Cybersecurity #Incidentresponse
Once attackers gain initial access, lateral movement is how they expand their reach without tripping alarms. They mimic legitimate admin behavior to pivot toward domain controllers, sensitive file shares, and databases.
Our latest blog covers the techniques attackers use and the strategies (segmentation, least privilege, MFA, Zero Trust) that help security teams detect and contain it early.
https://graylog.org/post/lateral-movement-security-risk-and-mitigation-strategies/
#CyberSecurity #SIEM #InfoSec #ThreatDetection
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own.
The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding.
Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/
#Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack.
With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data.
New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools.
Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/
#Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife
Wazuh (open-source XDR/SIEM) in v4.14.6 released
https://secburg.com/posts/wazuh-4146-released/
#Wazuh #OpenSource #SIEM #XDR #InfoSec
AWS WAF sees every request hitting your ALB, CloudFront, API Gateway, or AppSync, and makes a block/allow/count/CAPTCHA/challenge decision on each one. The question is whether your security team can actually see and search those decisions.
The AWS WAF Content Pack for Graylog parses the WAF JSON payload, normalizes the fields, and maps enforcement actions to the Graylog Information Model so they flow straight into detection and investigation workflows. Dashboard included.
Details: https://graylog.org/post/aws-waf-data-in-graylog/
#SIEM #AWS #CloudSecurity #Graylog
You've seen all posts