Blog Entries

29. 09. 2026 Alessio Dallaporta Blue Team, Machine Learning

Detecting Data Exfiltration with Elastic Machine Learning

Data exfiltration is rarely as obvious as a large file being copied to an attacker-controlled server. In many environments, sensitive information leaves through channels that look legitimate: a cloud storage service, a familiar application, an unusual destination country, or a removable device. This is where Elastic’s Data Exfiltration Detection (DED) package can help. Instead of…

Read More
11. 05. 2026 Alessio Dallaporta Blue Team, SEC4U

Bridging The Gap

Why a Purple Team Program Makes Cybersecurity More Effective In today’s cybersecurity landscape, having defensive tools in place is no longer enough. Firewalls, SIEM platforms, detection rules, playbooks, and threat intelligence feeds are all essential components, but the real question is this: how well do they actually perform under realistic attack conditions? This is where…

Read More
23. 03. 2026 Alessio Dallaporta Blue Team

Inside Elastic Security Detection Rules: Internal Structure & Upgrade Mechanics

A Rule Is More Than a Query In modern detection engineering, a rule is often misunderstood as just a query that triggers alerts. In reality, within Elastic Security, a detection rule is a structured, versioned, and lifecycle-managed object that goes far beyond simple query logic. Understanding this structure is essential for anyone operating in a…

Read More

Archive