<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Analytics &#8211; SCRT Team Blog</title>
	<atom:link href="/category/analytics/feed/" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>Orange Cyberdefense Switzerland&#039;s technical blog</description>
	<lastBuildDate>Thu, 26 Mar 2026 09:17:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>/wp-content/uploads/2024/10/cropped-favicon-32x32-1-32x32.png</url>
	<title>Analytics &#8211; SCRT Team Blog</title>
	<link>/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Insomni’Hack 2026 &#8211; Golden Payout writeup</title>
		<link>/2026/03/25/insomnihack-2026-the-golden-payout-writeup/</link>
		
		<dc:creator><![CDATA[Frédéric Bourla]]></dc:creator>
		<pubDate>Wed, 25 Mar 2026 23:35:02 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<category><![CDATA[Insomni'hack]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[writeup]]></category>
		<guid isPermaLink="false">/?p=7338</guid>

					<description><![CDATA[The challenge A massive data breach has just hit our corporate network. Highly sensitive documents have been spotted on a prominent Darknet leaking platform. Preliminary network telemetry has flagged suspicious outbound traffic originating from a specific workstation belonging to one of our DBAs. As part of the Rapid Response Investigation Team, you have been assigned &#8230; <a href="/2026/03/25/insomnihack-2026-the-golden-payout-writeup/" class="more-link">Continue reading <span class="screen-reader-text">Insomni’Hack 2026 &#8211; Golden Payout writeup</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Getting Started With SplunkUI</title>
		<link>/2023/01/03/getting-started-with-splunkui/</link>
		
		<dc:creator><![CDATA[Didier Cambefort]]></dc:creator>
		<pubDate>Tue, 03 Jan 2023 13:06:26 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[splunkUI]]></category>
		<guid isPermaLink="false">/?p=3477</guid>

					<description><![CDATA[When developing new Splunk apps with a customised user interface, everything but SplunkUI is deprecated. Thus, it is only a matter of time before you need to jump from that building with faith. Most Splunk users are not web developers. Developing web UI is known to be a nightmare, that&#8217;s why they chose to be &#8230; <a href="/2023/01/03/getting-started-with-splunkui/" class="more-link">Continue reading <span class="screen-reader-text">Getting Started With SplunkUI</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Splunk Boss Of The SOC (BOTS) @Insomni&#8217;hack</title>
		<link>/2022/04/04/splunk-boss-of-the-soc-bots-insomnihack/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Mon, 04 Apr 2022 09:28:41 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<category><![CDATA[Insomni'hack]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">/?p=3453</guid>

					<description><![CDATA[It&#8217;s was a pleasure this year to meet you at the 2022 edition of our amazing security conference Insomni&#8217;hack ! With Splunk collaboration, we come back this year with &#8220;Splunk Boss Of The SOC&#8221; challenge. What is BOTS and his history Boss Of The SOC (BOTS) is a blue-team version of capture the flag competition. &#8230; <a href="/2022/04/04/splunk-boss-of-the-soc-bots-insomnihack/" class="more-link">Continue reading <span class="screen-reader-text">Splunk Boss Of The SOC (BOTS) @Insomni&#8217;hack</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>SOCs real-life challenges &#038; solutions</title>
		<link>/2022/02/07/socs-real-life-challenges-solutions/</link>
		
		<dc:creator><![CDATA[Greg Divorne]]></dc:creator>
		<pubDate>Mon, 07 Feb 2022 11:10:39 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<guid isPermaLink="false">/?p=3308</guid>

					<description><![CDATA[Introduction As SCRT&#8217;s blue teamers, we often deal with Security Operations Centers (SOCs). Being able to interact with many different SOCs for our consultancy service gives us the possibility to understand the main challenges a SOC faces and how to solve them. This blog post results from a Master of Advanced studies&#8217; thesis for Geneva&#8217;s &#8230; <a href="/2022/02/07/socs-real-life-challenges-solutions/" class="more-link">Continue reading <span class="screen-reader-text">SOCs real-life challenges &#038; solutions</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Event Masker &#8211; 2021.08 Release</title>
		<link>/2021/07/26/event-masker-2021-08-release/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Mon, 26 Jul 2021 12:43:15 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<guid isPermaLink="false">/?p=3192</guid>

					<description><![CDATA[We are proud to announce a new release for Event Masker, with many productivity tweaks and significant enhancements. ES Integration It was cumbersome to move from the tab where you had the notable event you wanted to mask, to the tab with Event Masker opened on the correct rule. That is why you may now &#8230; <a href="/2021/07/26/event-masker-2021-08-release/" class="more-link">Continue reading <span class="screen-reader-text">Event Masker &#8211; 2021.08 Release</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Splunk &#038; advanced filtering with Event Masker</title>
		<link>/2021/05/03/splunk-advanced-filtering-with-event-masker/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Mon, 03 May 2021 14:34:47 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">/?p=3164</guid>

					<description><![CDATA[What is Splunk ? Splunk is a Data-to-Everything Platform designed to ingest and analyze all kind of data. They can be visualized and correlated through Splunk searches, alerts, dashboards, and reports. Splunk is the #1 of 2020 Gartner Magic Quadrants in SIEMs for its performant analysis and visionary in Application Performance Management category. Splunk and &#8230; <a href="/2021/05/03/splunk-advanced-filtering-with-event-masker/" class="more-link">Continue reading <span class="screen-reader-text">Splunk &#38; advanced filtering with Event Masker</span></a>]]></description>
		
		
		
			</item>
	</channel>
</rss>
