Resources

Blog

Practical guidance on self-hosted security monitoring — detection fundamentals, threat intelligence standards, and compliance across Southeast Asia.

Latest

Fundamentals

What Is UEBA? User and Entity Behaviour Analytics Explained

Rule-based detection catches attacks that match a known pattern. UEBA catches the ones that don't — a real user, with real credentials, doing something they have never done before. Here is how behavioural analytics works and what it needs to function.

28 July 2026 · 5 min read

Fundamentals

STIX and TAXII Explained: How Threat Intelligence Actually Moves Between Systems

STIX is the language threat intelligence is written in. TAXII is how it travels. Together they turn a spreadsheet of suspicious IP addresses into structured, machine-readable intelligence your platform can act on automatically.

24 July 2026 · 4 min read

Fundamentals

AI-Assisted Investigation in the SOC: What It Does, and What It Cannot Do

Large language models are genuinely useful for security investigation — summarising timelines, translating questions into queries, drafting reports. They are also confidently wrong on occasion. Here is where the line sits, and why it matters where the model runs.

23 July 2026 · 4 min read

Fundamentals

YARA Rules Explained: Pattern Matching for Malware Detection

Hash matching catches a file you have seen before. YARA catches the next variant of it. A practical guide to how YARA rules are structured, how to write one, and how to avoid the false positives that make teams switch them off.

21 July 2026 · 5 min read

Fundamentals

VirusTotal Integration in a SIEM: Automated File Reputation Without Sending Your Files Away

VirusTotal aggregates 70+ antivirus engines into one reputation lookup. Used correctly, it enriches alerts automatically. Used carelessly, it uploads your confidential documents to a service other people can search.

18 July 2026 · 4 min read

Guides and comparisons

Start with the free tier

Deploy nPro on your own infrastructure. Free for up to 99 agents, with no per-gigabyte ingestion charge and no time limit.

nPro AI

Online

Hi! I'm the nPro assistant. How can I help you learn about our SIEM & monitoring tools today?

Powered by nPro AI