Learn. Share. Secure. Access product knowledge, get certified, and collaborate with the global Securonix user community.
Join the discussion, ask questions, get solutions.
Discover product guides and helpful how-tos.
Join groups and collaborate with peers.
Stay up to date with our product team.
Share your ideas and suggestions with our team.
Discover and join upcoming events.
Explore Securonix solutions, products, and company insights
Access product guides, release notes, and technical documentation
Get active findings and detection strategies from Securonix Threat Research
Discover the ThreatQ threat intelligence platform and solutions
Find step-by-step guides, release notes, and troubleshooting resources
Discover and deploy integrations, extensions, and apps for the ThreatQ platform
name: 'Browser Process Spawning Download-and-Execute Chain to Temp Analytic'signatureid: EDR-SYM972-RUNcategory: 'Execution'threatname: 'Exploitation for Client Execution'functionality: 'Endpoint Management Systems'description: | Detects a Chromium-
name: 'GRIMWEDGE Persistence Scheduled Task Creation Analytic'signatureid: WEL-ACC83-RUNcategory: 'Persistence'threatname: 'Scheduled Task/Job: Scheduled Task'functionality: 'Microsoft Windows'lifecycle: experimentaldescription: | Detects creation o
name: Gryxa Toolkit Working Directory or Component Script Referenced in Process Execution Analyticsignatureid: EDR-SYM964-RUNcategory: 'Defense Evasion'threatname: 'Masquerading: Match Legitimate Resource Name or Location'functionality: 'Endpoint Man
name: SYSTEM Scheduled Task Created with Minute Interval Executing from ProgramData or Diagnostics Path Analyticsignatureid: EDR-SYM965-RUNcategory: 'Persistence'threatname: 'Scheduled Task/Job: Scheduled Task'functionality: 'Endpoint Management Syst
name: Scheduled Task Registered with Sub-Hourly Repetition Executing from ProgramData or Diagnostics Path Analyticsignatureid: WEL-ACC82-RUNcategory: 'Persistence'threatname: 'Scheduled Task/Job: Scheduled Task'functionality: 'Microsoft Windows'descr
Authors: Nitish Singh, Nikhil Kumar Chadha, and Tanmay KumarIntroduction:The Monthly Intelligence Insights report provides a summary of top threats curated, monitored, and analyzed by Securonix Threat Watch in August 2026. The report also includes a
OverviewOn September 1, 2026, Volexity's Network Security Monitoring service caught a spear-phishing email hitting multiple non-governmental organization customers. The lure was a donation-form pretext, the kind of email a fundraising team might send
Executive Summary:On 9 September 2026, Securonix ThreatWatch team began tracking lapsus.ar[.]io after the site appeared online carrying "LAPSUS$ GROUP - CHAPTER II" branding. At the time of review, the site used "LAPSUS$ GROUP - CHAPTER II" branding
Dense security events can slow an investigation before it starts. When a log contains unfamiliar error codes, identity attributes, device posture, and application context, ask Sam, the AI SOC Analyst, to explain it in plain language. Try thisPaste th
Audience : SOC Analysts, Security Engineers, Detection Engineers, MSSPs, Security Operations LeadersProduct Module : Securonix Unified Defense SIEM | Agentic MeshLast Updated : May 21, 2026KB ID : KB-20260521-agentic-mesh-overviewTags : Agentic Mesh,
Currently, the Task Title field in the ThreatQ Create Tasks integration appears to only support static text.We would like to request support for dynamic attribute substitution in the Task Title, allowing attribute values from the associated object to
Did you know SAM understands Diamond Model Analysis? You can ask Sam to create a report on a violation, something that usually takes a LOT of time to do manually. While working a Violation, Ask Sam: Please prepare a diamond model analysisorFor this
Ability to Modify Alert Disposition After ClosureCurrently, if an alert is mistakenly closed as “True Positive” instead of “False Positive,” there is no option available to revert or modify the disposition after closure.Request:It would be very helpf
Greetings,I have an ask from a client to integrate CyberArk API instead of the syslog connector. Currently there is no OOTB parser for it. Would I have to get a cloud collector setup for it?Thank you,Martel
We are pulling data from FS-ISAC into ThreatQ as an event. The issue I am facing here is that we are unable to get the indicators (specifically bank account numbers and phone numbers) ingested into the platform as an indicator.We need to be able to i
Hello, We have recently onboarded Cloudflare audit logs and was instructed by a technician that we could also bring in Cloudflare WAF logs on the same data source. It has been enabled on the application, but we are not seeing the WAF logs. Has anyone
We noticed a log source searchable period has been showing "16hr in future - 91 days ago" for the past 4-5days. How do we fix this?
Is there a reporting feature on the HUB to be able to alert when disk space is filling up, when resources are in over use, or when there is an excessive amount of failures going to the UI?
I have a ton of open and closed sources feeding reports, vulnerabilities & CVE indicators into ThreatQ. Because “reports”, “vulnerabilities”, and “indicators” are all different threat libraries inside of ThreatQ, I’ve struggled to find a way to d
Currently, the RF IOC enrichment action provides only a limited set of attributes, such as risk score and malware verdict. Malware attribution, however, is not included in the enrichment results.Since we are paying for an RF license, we would like to
Where security professionals share intelligence and strengthen defense together
Learn More →
Bring your questions. Learn live with the Securonix Training team.
Join open Office Hours for guidance on course content, product functionality, training logistics, and questions from the Securonix Connect community.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.