<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Detection on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/detection/</link><description>Recent content in Detection on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/detection/index.xml" rel="self" type="application/rss+xml"/><item><title>SIEM (Security Information and Event Management)</title><link>https://lesitedefrancois.be/en/security/siem/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/siem/</guid><description>&lt;p&gt;&lt;strong&gt;SIEM (Security Information and Event Management)&lt;/strong&gt; is a platform that aggregates security telemetry from across an organisation&amp;rsquo;s infrastructure, normalises it into a common schema, applies correlation rules and behavioural analytics to detect threats, and retains the data for investigation and compliance reporting. The name combines two earlier disciplines: &lt;strong&gt;SIM (Security Information Management)&lt;/strong&gt; — long-term log retention, compliance reporting, and forensic search — and &lt;strong&gt;SEM (Security Event Management)&lt;/strong&gt; — real-time alert correlation and incident detection. Modern SIEMs do both simultaneously, serving as the primary visibility layer for a Security Operations Centre (SOC). Leading platforms include Splunk Enterprise Security, IBM QRadar, Microsoft Sentinel, Elastic Security, Exabeam, and LogRhythm; all share the same fundamental architecture despite differing in query language (SPL for Splunk, KQL for Sentinel, EQL/KQL for Elastic, AQL for QRadar), correlation engine design (search-based vs dedicated CEP engine), and deployment model (on-premises, SaaS, or hybrid).&lt;/p&gt;</description></item><item><title>SOC (Security Operations Centre)</title><link>https://lesitedefrancois.be/en/security/soc/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/soc/</guid><description>&lt;p&gt;A &lt;strong&gt;SOC (Security Operations Centre)&lt;/strong&gt; is the organisational function responsible for defending an infrastructure against security threats through continuous monitoring, alert triage, incident investigation, and coordinated response. It is not a single product: it is the combination of &lt;strong&gt;people&lt;/strong&gt; (security analysts operating in tiered roles), &lt;strong&gt;processes&lt;/strong&gt; (runbooks, escalation paths, incident classification, post-incident review), and &lt;strong&gt;technology&lt;/strong&gt; (primarily a &lt;strong&gt;SIEM&lt;/strong&gt; for detection and visibility, a &lt;strong&gt;SOAR&lt;/strong&gt; platform for orchestration and actuation, EDR agents, vulnerability scanners, threat intelligence feeds, and ticketing or case management systems). The SOC&amp;rsquo;s purpose is to close the loop between something going wrong in the infrastructure and someone doing something about it — with enough structure that the response is consistent, attributable, and auditable regardless of which analyst is on shift. Operating models range from a fully internal 24×7 team, through a virtual SOC (vSOC) sharing analysts across business units, to an outsourced &lt;strong&gt;MDR (Managed Detection and Response)&lt;/strong&gt; or MSSP engagement where a third party operates the SIEM and initial triage on the organisation&amp;rsquo;s behalf; the technology stack is largely the same across models, but the boundary of who performs each tier of work changes. Analyst tiers are conventionally structured as &lt;strong&gt;L1&lt;/strong&gt; (alert triage, false-positive filtering, initial enrichment, escalation decisions), &lt;strong&gt;L2&lt;/strong&gt; (deeper investigation, correlation across data sources, containment recommendations), and &lt;strong&gt;L3&lt;/strong&gt; (threat hunting, malware reverse engineering, incident lead, playbook authoring, purple-team exercises) — with escalation governed by severity classification (P1–P4 or equivalent), SLA targets for &lt;strong&gt;MTTD (Mean Time to Detect)&lt;/strong&gt; and &lt;strong&gt;MTTR (Mean Time to Respond)&lt;/strong&gt;, and documented runbooks that define what each tier may do autonomously versus what requires approval.&lt;/p&gt;</description></item></channel></rss>