Company
Date Published
Author
Ross Wolf • Paul Ewing
Word count
1227
Language
English
Hacker News points
None

Summary

EQL, the Event Query Language developed by Endgame, is a versatile and extensible language designed to express relationships between security-relevant events, applicable to various use cases and independent of specific architectures. Originally part of Endgame's endpoint security product, EQL has now been released to the public, allowing broader use beyond Endgame's customer base. This release includes core language features, Sysmon schema mapping, and analytics focused on Atomic Blue, aimed at enhancing detection capabilities beyond traditional indicators of compromise (IOCs). EQL is praised for its minimal learning curve, intuitive search capabilities, and ability to work across different data sources without dependence on specific schemas, thus allowing for easy sharing of analytics across security teams. The release also includes EQLLib, a set of analytics to familiarize users with EQL, and Atomic Blue, which maps EQL logic to adversary techniques, contributing to the MITRE ATT&CK framework. Endgame plans to expand EQL's capabilities by supporting additional data sources and technologies, and seeks community feedback to improve and evolve the tool, recognizing its potential to address limitations in universally describing detection logic across datasets.