IAizzat Aziziinblog.izzat.me·Jul 6 · 10 min readTuning Out the Noise: How to Reduce Alert Fatigue in Splunk Without Missing Real ThreatsThere's a quiet failure mode that affects nearly every detection program eventually, and it rarely looks like failure from the inside. A detection gets built — maybe even one very much like the ones i00
IAizzat Aziziinblog.izzat.me·Jul 3 · 9 min readBuilding Dashboards That SOC Analysts Actually Use (Not Just Look Pretty)Picture two dashboards. The first is dense with panels — heat maps, geographic plots, animated counters, a dozen colors competing for attention. It's the one that gets shown in leadership meetings, an12J
IAizzat Aziziinblog.izzat.me·Jul 1 · 11 min readWriting Detection Rules That Actually Catch Something: A Walkthrough of Real SPL QueriesIn Part 2, you learned to build SPL searches in layers. In Part 3, you learned how correlation searches connect separate signals into a meaningful pattern, using a condition, a time window, and an act00
IAizzat Aziziinblog.izzat.me·Jun 29 · 8 min readCorrelation Searches 101In Part 2 of this series, you built a search that found users with an unusually high number of failed logons. That's a genuinely useful search — but on its own, it has a hard ceiling. A user might hav00
IAizzat Aziziinblog.izzat.me·Jun 22 · 7 min readChoosing the Right Privacy Tools for Your Situation (Not Just the Popular Ones)This is the final part of the series — and in many ways, the one that ties everything else together. Across the previous five parts, you audited your exposure, removed yourself from data broker sites,00