Resources
Blog
Practical guidance on self-hosted security monitoring — detection fundamentals, threat intelligence standards, and compliance across Southeast Asia.
Latest
What Is UEBA? User and Entity Behaviour Analytics Explained
Rule-based detection catches attacks that match a known pattern. UEBA catches the ones that don't — a real user, with real credentials, doing something they have never done before. Here is how behavioural analytics works and what it needs to function.
28 July 2026 · 5 min read
STIX and TAXII Explained: How Threat Intelligence Actually Moves Between Systems
STIX is the language threat intelligence is written in. TAXII is how it travels. Together they turn a spreadsheet of suspicious IP addresses into structured, machine-readable intelligence your platform can act on automatically.
24 July 2026 · 4 min read
AI-Assisted Investigation in the SOC: What It Does, and What It Cannot Do
Large language models are genuinely useful for security investigation — summarising timelines, translating questions into queries, drafting reports. They are also confidently wrong on occasion. Here is where the line sits, and why it matters where the model runs.
23 July 2026 · 4 min read
YARA Rules Explained: Pattern Matching for Malware Detection
Hash matching catches a file you have seen before. YARA catches the next variant of it. A practical guide to how YARA rules are structured, how to write one, and how to avoid the false positives that make teams switch them off.
21 July 2026 · 5 min read
VirusTotal Integration in a SIEM: Automated File Reputation Without Sending Your Files Away
VirusTotal aggregates 70+ antivirus engines into one reputation lookup. Used correctly, it enriches alerts automatically. Used carelessly, it uploads your confidential documents to a service other people can search.
18 July 2026 · 4 min read
Guides and comparisons
What is a SIEM?
The fundamentals of security information and event management.
Deploy a self-hosted SIEM on Ubuntu 24.04
Step-by-step deployment from a clean server.
SIEM vs EDR vs XDR
How the three categories differ and where they overlap.
SIEM vs SOAR
Detection versus orchestration, and why you need both.
Detecting ransomware with a SIEM
The behavioural signals that precede encryption.
SIEM implementation checklist
What to get right before go-live.
SIEM log retention best practices
Balancing cost, compliance and investigation depth.
ClickHouse vs Elasticsearch for security logs
Why the storage engine shapes operational cost.
Cloud vs on-premise SIEM: total cost
Modelling three-year cost honestly.
The MSSP business case for on-premise SIEM
Margin, isolation and per-tenant economics.
OT and IoT network monitoring
Visibility where you cannot install agents.
PDPA compliance and SIEM in Malaysia
What the law requires of your logging.
Indonesia's PDP Law and security logging
Residency obligations for Indonesian institutions.
Singapore PDPA: a SIEM guide
Mapping controls to the PDPA and MAS TRM.
SOC 2 compliance and SIEM
Which Trust Services Criteria your logs satisfy.
Start with the free tier
Deploy nPro on your own infrastructure. Free for up to 99 agents, with no per-gigabyte ingestion charge and no time limit.