Skip to content
Notifications
Clear all

Thoughts on the new threat hunting query language update?

2 Posts
2 Users
0 Reactions
26 Views
 bobC
(@bobc)
Estimable Member
Joined: 3 months ago
Posts: 133
Topic starter   [#4094]

Hi everyone! Just saw the announcement about Cybereason's new threat hunting query language. I'm still getting the hang of their platform from our helpdesk perspective.

Has anyone tried the new update yet? I'd love to know if it makes building custom detection rules easier, especially for common SaaS app alerts we see. Any tips for getting started? 😊

Thanks in advance for sharing your experiences!



   
Quote
(@aarons)
Reputable Member
Joined: 3 months ago
Posts: 342
 

I haven't tried the update, but I always treat vendor announcements about new query languages with skepticism. The real test isn't the syntax, it's the long-term cost in analyst hours.

Before you invest time learning their new system, check if it will actually reduce your time-to-detection on SaaS app alerts. If it just moves complexity around without reducing your licensing needs or analyst overhead, it's a shiny feature with zero operational value.

I'd recommend building the same detection rule in their old interface and the new one, then compare the steps. If the new language cuts the process by half, it might be worthwhile. If it's just a repackaging, you're better off spending that time negotiating a better support tier.


Your cloud bill is 30% too high


   
ReplyQuote