Skip links

Blog

“Imposible traveler” detection with Wazuh

"Imposible traveler" detection with Wazuh What is the "Impossible Traveler" use case? The concept of “Impossible Traveler” is an anomaly detection technique based on the geographic location of a user’s actions. It is so called because it refers to situations in which a user apparently accesses a system from two or more distant locations in a very short period of time, which would be basically impossible in the real world. This type of behavior may indicate compromised or unauthorized access to an account. Example: A typical example could be if a user, “User1”, logs in from Buenos Aires at 10:00

This Was Our Talk at Antel Arena

This Was Our Talk at Antel Arena On October 8 and 9, Datasec participated in the Consciencia Digital event at Antel Arena, where we presented the challenges and benefits of 24/7 cybersecurity monitoring. It was an enriching experience, bringing together attendees and experts to exchange ideas on the importance of continuous digital protection. During the talk, Luis Balduini and Carlos Serra shared their insights, explaining how the Security Operations Center (SOC) helps organizations detect threats in real-time and ensure a swift response to incidents. Participants also had the chance to visit our booth, explore our comprehensive solutions, and engage directly
EVENTOS LOLBIN: cómo identificarlos y detectarlos

LOLBIN EVENTS: How to Identify and Detect Some of Them

En el presente documento, se llevó a cabo la investigación de eventos de tipo LOLBIN (Living off the Land Binaries) desde su entendimiento, las variantes que existen (según las herramientas y comandos aplicados), hasta reglas generadas para detectarlos en un sistema de tipo SIEM.