Learn why logging needs evolved, where legacy tools fail, and what to expect from a modern solution with hot multi-year retention and no ingestion penalties.
Resources · Library
The resource library.
Blooprints, integration guides, and malware research reports in one searchable place, all of it published and maintained by the Bloo team.
Featured
Featured resources.
Captures EDR telemetry from the CrowdStrike Falcon platform, including detections, incidents, and process, network, and host activity streamed through the Falcon Event Streams and Falcon Data Replicator APIs.
Captures authentication telemetry from Cisco Duo, including second-factor outcomes, device enrollment activity, and administrator actions retrieved from the Duo Admin API logs.
Captures firewall telemetry from Fortinet FortiGate appliances, including traffic sessions, UTM security events, VPN activity, and system logs delivered over syslog.
Captures GitHub organization and enterprise audit events, covering repository changes, member and permission updates, and authentication activity from the audit log API and audit log streaming.
Captures Kubernetes API server audit events, recording which principal performed which action on which resource across the cluster, with request and response detail at configurable audit levels.
Captures syslog and auditd streams from Linux hosts, covering authentication events, process execution, kernel messages, and daemon activity over standard syslog transports.
Captures endpoint telemetry from Microsoft Defender for Endpoint, covering alerts and device process, file, registry, network, and logon events delivered through the streaming API.
Captures identity telemetry from Microsoft Entra ID, covering interactive and non-interactive sign-ins, audit events for directory changes, and Identity Protection risk detections.
Captures identity telemetry from the Okta System Log, covering sign-in activity, MFA outcomes, application access, and administrative and directory changes.
Captures firewall telemetry from Palo Alto Networks next-generation firewalls, including traffic, threat, URL filtering, and decryption logs delivered over syslog or through Strata Logging Service.
Captures telemetry from the SentinelOne Singularity platform, including threat detections, agent and management activity, and Deep Visibility process, file, and network events.
Captures secure web gateway telemetry from Zscaler Internet Access and Zscaler Private Access, including web transactions, cloud firewall logs, DNS activity, and user access events streamed through NSS and LSS feeds.
Advanced SOCKS5 Backconnect Proxy Malware with Residential IP Masking Capabilities
Comprehensive analysis of SmokeLoader malware family, its evolution, and threat landscape
Advanced Remote Access Trojan with Persistent Surveillance Capabilities
Advanced Information Stealer with Multi-Platform Targeting Capabilities
Evolution, Capabilities, and Threat Analysis of the DRATzarus (ThreatNeedle) Malware Family
Evolution, Capabilities, and Threat Analysis of the GolangGhost Malware Family
Evolution, Capabilities, and Threat Analysis of the DarkGate Malware Family
Evolution, Capabilities, and Threat Analysis of the Supper Malware Family
Evolution, Capabilities, and Threat Analysis of the Lumma Stealer Malware Family
Evolution, Capabilities, and Threat Analysis of the Mimikatz Credential Stealer
Evolution, Capabilities, and Threat Analysis of the Cobalt Strike Framework
Evolution, Capabilities, and Threat Analysis of the Ghost RAT Malware Family
Comprehensive Malware Analysis of the InvisibleFerret Backdoor in Lazarus Group Operations
Evolution, Capabilities, and Threat Analysis of the Quasar Malware Family
Learn why logging needs evolved, where legacy tools fail, and what to expect from a modern solution with hot multi-year retention and no ingestion penalties.
Evolution, Capabilities, and Threat Analysis of the SystemBC Malware Family
Cloud-based security platform integration that protects applications and APIs from web threats including DDoS attacks, SQL injection, and credential abuse through Akamai's SIEM API.
AWS vulnerability management service integration that automatically scans AWS workloads including EC2 instances, ECR container images, and Lambda functions for software vulnerabilities and network exposure.
Comprehensive integration with AWS CloudTrail for security and compliance monitoring.
Seamless integration with AWS CloudWatch for monitoring and observability.
Native integration with AWS GuardDuty for comprehensive threat detection and security monitoring.
Real-time data streaming integration with AWS Kinesis.
Secure and scalable blob storage integration with Azure Blob Storage for log ingestion and data processing using Event Grid and Storage Queues.
High-throughput event streaming integration with Azure Event Hub for real-time data ingestion and processing.
Endpoint protection and detection platform integration with Cisco Secure Endpoint (formerly AMP for Endpoints) for comprehensive security monitoring and threat detection.
Cloudflare Logpush Connector for forwarding logs from Cloudflare Logpush API to DNIF, supporting multiple datasets including Zero Trust Network Session Logs, Audit logs, and Gateway logs.
AI-powered Digital Risk Monitoring platform integration that provides real-time visibility of cyber threats and actionable intelligence through CloudSEK's Alerts API.
Integration with Google Cloud Platform activity logs for security monitoring.
Real-time messaging and event streaming with Google Cloud Pub/Sub.
Comprehensive integration with Google Workspace services including Gmail, Drive, Calendar, and Admin SDK for security monitoring and compliance.
Identity and access management integration with Jumpcloud.
Security monitoring and threat detection for Microsoft Exchange Online environments.
Integration with Microsoft Sentinel for advanced security analytics and threat intelligence.
Cloud-based business email service integration offering secure webmail, file sharing, video conferencing, and messaging capabilities with comprehensive mail flow and activity logging.
Comprehensive security integration with Sophos endpoint protection.
Vulnerability management and security monitoring integration with Tenable Security Center.
Advanced threat detection and response integration with Trend Micro Vision One.
Evolution, Capabilities, and Threat Analysis of the Volgmer Malware Family
New additions, delivered monthly.
New reports, guides, and Blooprints land in the newsletter first.