07 - References & Resources
Expand your knowledge on logging, SIEM, detection engineering, and automated response with these industry-standard resources.
📖 Official Documentation & Standards
- OWASP Logging Cheat Sheet: Comprehensive guide on what to log, what not to log, and how to format logs securely.
- Elastic Common Schema (ECS): The open-source specification for structuring log data.
- Common Event Format (CEF): Micro Focus ArcSight's logging standard.
🔍 Detection Engineering & Sigma
- Sigma HQ Repository: The central GitHub repository containing thousands of community-driven Sigma rules for various threats.
- Sigma CLI: The tool used to convert Sigma rules to specific SIEM query languages.
- Uncoder.io: A web-based translation tool for SIEM queries and Sigma rules.
🤖 SOAR Platforms & Automation
- Shuffle: An open-source SOAR platform for building security playbooks.
- Tines: A powerful, no-code automation platform heavily used in modern security teams.
⚖️ Compliance & Frameworks
- PCI DSS Requirements: Specific logging requirements outlined in Requirement 10.
- NIST SP 800-92: Guide to Computer Security Log Management.