← All talks

SIEM Detection Rules: Elastic Stack & Public Logic Explained #shorts

BSides Frankfurt0:36833 viewsPublished 2026-04Watch on YouTube ↗
About this talk
Discover how to centrally collect all your IDP logs using the Elastic Stack. Install and configure SIEM detection rules, with public access to the exact logic behind them. Plagiarize them for your own environment! #SIEM #ElasticStack #LogManagement #Cybersecurity #DetectionRules
Show transcript [en]

How do you detect it? Centrally collect all of your IDP logs. Um my preference is in putting it all in the elastic stack cuz that's what we do. Um install and configure all of your built-in seam detection rules. I've got a link there and then the QR code, trust me, it goes to that website. Um it's okay. Uh the we've we publish all of our detection rules. Um it's all public. You can see the exact logic behind it. You can plagiarize them if you're not using elastic and put them in your environment. Um just, you know, don't go out and resell them, but, you know, you can feel free to plagiarize them in your own environment. That's okay.