詳細検索

SIEM


What is AI Security Operations? Practical guide to defense strategies that change with automatic detection and SOAR utilization
Security
March 14, 2026
4分で読めます

What is AI Security Operations? Practical guide to defense strategies that change with automatic detection and SOAR utilization

Now that attackers are leveraging AI, automation is essential for defenders. How will the use of AI change security operations, such as anomaly detection, alert prioritization, and automatic response through SOAR? We will explain realistic defense strategies in which humans and AI work together. |Colorkrew Security

What is lateral movement? A practical guide to defense-in-depth to prevent lateral deployment after intrusion
Security
March 12, 2026
5分で読めます

What is lateral movement? A practical guide to defense-in-depth to prevent lateral deployment after intrusion

To prevent lateral movement after intrusion, it is essential to have a multi-layered defense of privilege management, network isolation, and behavior detection. Based on the concept of Assume Breach, we will explain practical measures that can be used in common with Azure, AWS, and GCP. |Colorkrew Security

There are logs but can't be detected? Security Operational Pitfalls and 5 Improvements
Security
February 24, 2026
5分で読めます

There are logs but can't be detected? Security Operational Pitfalls and 5 Improvements

Explains the pitfall of security operation, "I take logs but don't notice the attack". From the perspective of an infrastructure engineer, we will introduce five steps to transform logs from mere storage objects into "defensive weapons" using correlation analysis and automatic detection. |Colorkrew Security

OSINT and SQL Injection Threats|What are the Risks of Exposing Admin Pages?
Security
January 23, 2026
6分で読めます

OSINT and SQL Injection Threats|What are the Risks of Exposing Admin Pages?

OSINT Explains Admin Page Identification and SQL Injection Attack Flow, WAF Evasion Methods, Detection Methods, and Defense-in-Depth Practices|Colorkrew Security

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points
Security
January 22, 2026
4分で読めます

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points

Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security

Ransomware Countermeasures Summary: A Complete Guide to Attack Methods, Damage, and Defense-in-Depth
Security
October 19, 2025
3分で読めます

Ransomware Countermeasures Summary: A Complete Guide to Attack Methods, Damage, and Defense-in-Depth

Systematically explains ransomware attack methods, damage risks, and multi-layered defense practices. Introducing a realistic defense model that includes EDR, SIEM, and backup strategies|Colorkrew Security

Why security personnel should invest in "integrated log management" [Improve operational efficiency and detection]
Security
October 15, 2025
4分で読めます

Why security personnel should invest in "integrated log management" [Improve operational efficiency and detection]

Distributed log management doesn't give you a complete picture of an attack. Log integration realizes correlation analysis, early detection, and man-hour reduction, and strengthens defenses with "lines" rather than "points". Explain the key points of integrated management that are essential in the cloud era. |Colorkrew Security

Logs are meaningless just by collecting them|Operational points to make use of them
Security
September 29, 2025
3分で読めます

Logs are meaningless just by collecting them|Operational points to make use of them

Logs are meaningless just by collecting them. We will explain in an easy-to-understand manner the key points of "usable log operation" using Microsoft Sentinel and Defender, as well as examples of failures and improvement measures. |Colorkrew Security

[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel
Security
August 4, 2025
2分で読めます

[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel

Detect brute force attacks early with Microsoft Sentinel! Learn how to create custom alerts and integrate Logic Apps to avoid missing a lot of logon failures. Colorkrew Security Blog

"The result of sticking to our own SOC..." The importance of outsourcing to learn from failure cases
Security
April 19, 2025
5分で読めます

"The result of sticking to our own SOC..." The importance of outsourcing to learn from failure cases

Are you wondering whether to operate your own SOC or outsource it? In this article, we will explain in detail the importance of outsourcing through examples of SOC operation failures. It shows how companies with talent shortages, cost management, and the risk of false positives can solve their challenges by outsourcing. If you're looking for tips to streamline your security operations and reduce risk, check out this one. |Colorkrew Security

Freedom from "alert fatigue"! How to reduce the burden of SOC operations?
Security
March 14, 2025
4分で読めます

Freedom from "alert fatigue"! How to reduce the burden of SOC operations?

Alert fatigue in SOC operations is caused by false positives and labor shortages. In this article, we'll explore specific ways to reduce the burden, such as improving alert accuracy, automating prioritization, and implementing SOAR. Colorkrew Security Blog

How to easily integrate Azure logs with Microsoft Sentinel | Step-by-step guide for beginners
Security
March 7, 2025
3分で読めます

How to easily integrate Azure logs with Microsoft Sentinel | Step-by-step guide for beginners

Explain how to integrate Azure logs with Microsoft Sentinel for beginners. It also explains the key points of supporting efficient log management and security enhancement, utilizing KQL, and monitoring operations. Colorkrew Security Blog