Analysis should not relies only on beautiful dashboards on your SIEM When you talk about incident response and network analysis, you are often confronted with two approaches (which can be sometimes implemented together) : IOC analysis based on whitelists,blacklists, indicators of compromise and technical CTI data, you can compare every IP/domain connection to your indicators and try to find what’s wrong…