“The ability to enrich data with specific IOCs bakes all the context directly into the data, saving investigators time by not having to enrich at search time.”
“We wanted a more resilient and flexible data pipeline, The immediate need was converting the right Endgame data to ECS, and dropping unneeded fields to make room for additional data sources and retain relevant data for longer."












