Blog Entries

29. 09. 2026 Alessio Dallaporta Blue Team, Machine Learning

Detecting Data Exfiltration with Elastic Machine Learning

Data exfiltration is rarely as obvious as a large file being copied to an attacker-controlled server. In many environments, sensitive information leaves through channels that look legitimate: a cloud storage service, a familiar application, an unusual destination country, or a removable device. This is where Elastic’s Data Exfiltration Detection (DED) package can help. Instead of…

Read More
09. 03. 2020 Enrico Alberti Log-SIEM, NetEye

Store Years of NetFlow Historical Data with Elastic Rollup on NetEye 4.9

Keeping historical data around for analysis is extremely useful but often avoided due to the financial cost of archiving massive amounts of data. Retention periods are thus driven by financial realities rather than by the usefulness of extensive historical data. The Elastic Stack data rollup features provide a means to summarize and store historical data…

Read More
21. 02. 2020 Tobias Goller Log Management, NetEye

Tornado Use Case with Elastic

Before I tell you about one of my latest customer requirements, I would like to briefly explain what our NetEye Tornado module is. In our user guide you will see it written that Tornado is the successor to NetEye’s Event Handler. It is a plugin-based, stateless, scalable rule matching engine written in Rust, based on…

Read More

Archive