Under active development Content is continuously updated and improved

Security Tools

SIEM, EDR, vulnerability management, and security platform guidance.

What you'll find here

Use these guides to validate telemetry, detection coverage, response workflows, and continuous monitoring configurations.

Under Construction: This guidance is being actively developed and verified. Content may change.

Guides

9 guides in this section.

Splunk

by Cisco

Security information and event management (SIEM) platform for log analysis and monitoring

4 sources
5 commands
3 frameworks

CrowdStrike Falcon

by CrowdStrike

Endpoint detection and response (EDR) platform with threat intelligence

8 sources
4 commands
3 frameworks

Splunk

by Splunk Inc. (Cisco)

Enterprise SIEM platform for security monitoring, log management, and threat detection

8 sources
6 commands
4 frameworks

Qualys VMDR

by Qualys, Inc.

Cloud-based vulnerability management, detection, and response platform with continuous assessment

9 sources
9 commands
4 frameworks

Tenable Vulnerability Management

by Tenable, Inc.

Exposure management platform for vulnerability assessment, prioritization, and risk analytics

9 sources
10 commands
4 frameworks

Zscaler Zero Trust Exchange

by Zscaler, Inc.

Cloud-native zero trust network security platform for secure internet access (ZIA) and private access (ZPA)

9 sources
9 commands
4 frameworks

Datadog

by Datadog, Inc.

Cloud monitoring and security platform with APM, infrastructure monitoring, and cloud security posture management

8 sources
9 commands
4 frameworks

ServiceNow

by ServiceNow, Inc.

Enterprise IT service management and GRC platform with security operations and vulnerability response

9 sources
9 commands
4 frameworks

Palo Alto Networks

by Palo Alto Networks, Inc.

Next-generation firewall and cloud security platform with advanced threat prevention and zero trust capabilities

8 sources
11 commands
4 frameworks