<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Incident Detection &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/incident-detection/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 04 Nov 2025 14:14:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>The End Of Legacy SIEM: Why It’s Time To Take Command</title>
		<link>https://noise.getoto.net/2025/11/04/the-end-of-legacy-siem-why-its-time-to-take-command/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Tue, 04 Nov 2025 14:14:13 +0000</pubDate>
				<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[Security Operations (SOC)]]></category>
		<category><![CDATA[siem]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=439d4e6070b97c22bb97d1e24ebe86d0</guid>

					<description><![CDATA[Security teams have long depended on SIEM tools as the backbone of threat detection and response. But the threat landscape, and the technology required to defend against it, has changed dramatically.Rapid7’s new whitepaper, The End of Legacy SIEM and t...]]></description>
		
		
		<enclosure url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt449dc1bfc144e45a/6888cb60ce39f6210cb8edd3/1753794060323.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Stories from the SOC Part 2: MSIX Installer Utilizes Telegram Bot to Execute IDAT Loader</title>
		<link>https://noise.getoto.net/2024/04/10/stories-from-the-soc-part-2-msix-installer-utilizes-telegram-bot-to-execute-idat-loader/</link>
		
		<dc:creator><![CDATA[Tom Elkins]]></dc:creator>
		<pubDate>Wed, 10 Apr 2024 13:00:00 +0000</pubDate>
				<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Managed Detection and Response (MDR)]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=cfec09639fe5363bdd6dab5564bab671</guid>

					<description><![CDATA[In part one of our blog series, we discussed how a Rust based application was used to download and execute the IDAT Loader. In part two of this series, we will be providing analysis of how an MSIX installer led to the download and execution of the IDAT Loader.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2024/04/GettyImages-1493136853.jpg" length="0" type="" />

			</item>
		<item>
		<title>Sharpen Your IR Capabilities With Rapid7’s Detection and Response Workshop</title>
		<link>https://noise.getoto.net/2022/04/04/sharpen-your-ir-capabilities-with-rapid7s-detection-and-response-workshop/</link>
		
		<dc:creator><![CDATA[Mikayla Wyman]]></dc:creator>
		<pubDate>Mon, 04 Apr 2022 13:28:08 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8f9a231995271e82aba5b746c78546fd</guid>

					<description><![CDATA[Rapid7's Detection and Response Workshop helps you determine if your tools can immediately detect and respond to threats.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/04/d-r-workshop.jpg" length="0" type="" />

			</item>
		<item>
		<title>What&#8217;s New in InsightIDR: Q4 2021 in Review</title>
		<link>https://noise.getoto.net/2022/01/06/whats-new-in-insightidr-q4-2021-in-review/</link>
		
		<dc:creator><![CDATA[Margaret Wei]]></dc:creator>
		<pubDate>Thu, 06 Jan 2022 20:41:17 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Extended Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<category><![CDATA[Product Updates]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=d1e1a150733f5afc2c704db26e7eab30</guid>

					<description><![CDATA[This post offers a closer look at some of the recent releases in InsightIDR, our extended detection and response (XDR) solution, from Q4 2021.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2022/01/insightIDR-q4.jpg" length="0" type="" />

			</item>
		<item>
		<title>Building Threat-Informed Defenses: Rapid7 Experts Share Their Thoughts on MITRE ATT&#038;CK</title>
		<link>https://noise.getoto.net/2021/11/04/building-threat-informed-defenses-rapid7-experts-share-their-thoughts-on-mitre-attck/</link>
		
		<dc:creator><![CDATA[Margaret Wei]]></dc:creator>
		<pubDate>Thu, 04 Nov 2021 13:30:00 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Extended Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[Managed Detection and Response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=9324b8efb60fe52ac2836cac0f0a3df2</guid>

					<description><![CDATA[Three members of Rapid7's Managed Detection and Response team tell us about their firsthand experience MITRE's ATT&#38;CK Matrix for Enterprise.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/11/mitre-q-a.jpg" length="0" type="" />

			</item>
		<item>
		<title>[The Lost Bots] Episode 5: Insider Threat</title>
		<link>https://noise.getoto.net/2021/09/13/the-lost-bots-episode-5-insider-threat/</link>
		
		<dc:creator><![CDATA[Rapid7]]></dc:creator>
		<pubDate>Mon, 13 Sep 2021 13:32:46 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[Lost Bots]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=463766aca34d5b92178909a29e97c1c1</guid>

					<description><![CDATA[In this episode of The Lost Bots, we’re joined by Alan Foster (Manager, Domain Engineers) to discuss insider threats.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/09/-The-Lost-Bots--Episode-1--External-Threat-Intelligence.jpeg" length="0" type="" />

			</item>
		<item>
		<title>Cybersecurity as Digital Detective Work: DFIR and Its 3 Key Components</title>
		<link>https://noise.getoto.net/2021/09/03/cybersecurity-as-digital-detective-work-dfir-and-its-3-key-components/</link>
		
		<dc:creator><![CDATA[Jesse Mack]]></dc:creator>
		<pubDate>Fri, 03 Sep 2021 13:12:36 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=10032fbdd6a0b9c8a3dc06cfac2b6599</guid>

					<description><![CDATA[We highlight 3 elements of a well-formulated digital forensics and incident response (DFIR) strategy.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/09/digital-detective-DFIR.jpg" length="0" type="" />

			</item>
		<item>
		<title>Once Again, Rapid7 Named a Leader in 2021 Gartner Magic Quadrant for SIEM</title>
		<link>https://noise.getoto.net/2021/07/06/once-again-rapid7-named-a-leader-in-2021-gartner-magic-quadrant-for-siem/</link>
		
		<dc:creator><![CDATA[Meaghan Donlon]]></dc:creator>
		<pubDate>Tue, 06 Jul 2021 15:15:07 +0000</pubDate>
				<category><![CDATA[Awards]]></category>
		<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e0bffc229456a9f8bc223f04bf4937e5</guid>

					<description><![CDATA[This is the second consecutive time our SaaS SIEM—InsightIDR—has been named a Leader in this report.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/07/cyber-detection2.jpg" length="0" type="" />

			</item>
		<item>
		<title>How to Combat Alert Fatigue With Cloud-Based SIEM Tools</title>
		<link>https://noise.getoto.net/2021/02/22/how-to-combat-alert-fatigue-with-cloud-based-siem-tools/</link>
		
		<dc:creator><![CDATA[Margaret Zonay]]></dc:creator>
		<pubDate>Mon, 22 Feb 2021 14:35:36 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<category><![CDATA[siem]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=443619b75159cdb68a6c585dc6929ebd</guid>

					<description><![CDATA[Fortunately, there’s a way to get the visibility your team needs and streamline alerts: leveraging a cloud-based SIEM.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/02/How-to-Combat-Alert-Fatigue-With-Cloud-Based-SIEM-Tools2.jpg" length="0" type="" />

			</item>
		<item>
		<title>Monitor Google Cloud Platform (GCP) Data With InsightIDR</title>
		<link>https://noise.getoto.net/2021/02/16/monitor-google-cloud-platform-gcp-data-with-insightidr/</link>
		
		<dc:creator><![CDATA[Margaret Zonay]]></dc:creator>
		<pubDate>Tue, 16 Feb 2021 21:53:21 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=19dc6d22072eb34544073fda2c0aec94</guid>

					<description><![CDATA[Today, more and more organizations are adopting multi-cloud or hybrid environments, creating increasingly more dispersed security environments]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/02/Monitor-Google-Cloud-Platform--GCP--Data-With-InsightIDR2.jpg" length="0" type="" />

			</item>
		<item>
		<title>Talkin’ SMAC: Alert Labeling and Why It Matters</title>
		<link>https://noise.getoto.net/2021/02/12/talkin-smac-alert-labeling-and-why-it-matters/</link>
		
		<dc:creator><![CDATA[matthew berninger]]></dc:creator>
		<pubDate>Fri, 12 Feb 2021 14:42:09 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Managed Detection and Response]]></category>
		<category><![CDATA[Security Operations Center (SOC)]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=eb03b0191ebbb523c5defe15237a58bf</guid>

					<description><![CDATA[This blog post will demonstrate some common pitfalls of alert labeling, and offers a new framework for SOCs to use.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2021/02/Talkin--SMAC--Alert-Labeling-and-Why-It-Matters2.jpg" length="0" type="" />

			</item>
		<item>
		<title>What’s New in InsightIDR: Q4 2020 in Review</title>
		<link>https://noise.getoto.net/2020/12/18/whats-new-in-insightidr-q4-2020-in-review/</link>
		
		<dc:creator><![CDATA[Margaret Zonay]]></dc:creator>
		<pubDate>Fri, 18 Dec 2020 14:50:17 +0000</pubDate>
				<category><![CDATA[Detection and Response]]></category>
		<category><![CDATA[Incident Detection]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[InsightIDR]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=61c6b9cb308ebe718654bf7f1ba912f1</guid>

					<description><![CDATA[As we near the end of 2020, we wanted to offer a closer look at some of the recent updates and releases in InsightIDR from Q4 2020.]]></description>
		
		
		<enclosure url="https://blog.rapid7.com/content/images/2020/12/What-s-New-in-InsightIDR--Q4-2020-in-Review2.jpg" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 32/227 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-09 07:12:12 by W3 Total Cache
-->