Company
Date Published
Author
Dany Kanes, Jordan Obey
Word count
685
Language
English
Hacker News points
None

Summary

Datadog's Cloud SIEM now offers an "Impossible Travel Detection Rule" to identify anomalous login patterns, helping detect security breaches by analyzing user locations across the globe. This rule type analyzes logs to determine if a user has traveled between locations at an impossible speed, flagging suspicious activity and generating Security Signals to notify users. To create effective rules, users can specify log search syntax and group values by dimension, while fine-tuning rules with suppression lists to minimize false positives. By enabling this feature, organizations can improve their security posture and detect potential threats in real-time.