What i like most area the capabilities of the tool: - The ability to analyze logs and provide a detailed interpretation of the information, including the analysis and verdict, is one of the features I personally value the most, as it significantly reduces analysis time and gives us a solid framework to classify threats. - Compatibility with multiple log sources, which allows the integration of less common log sources or events OpenSearch, enabling further customization of detections. This includes the ability to implement Sigma or YARA rules and send alerts directly to the AI for processing -Although there is one section I have not used extensively yet, I believe it adds a lot of value: Threat Intelligence. This module provides very valuable information about attacks occurring around the world, and most importantly, correlates them with their respective APTs, giving us a strong foundation to continue our investigations
April 2, 2026
What I dislike most is the platform's visual aesthetics, which makes it less user-friendly for someone new.
April 1, 2026