Skip to main content

Overview

Recommended Content | Usage Insights

S
Written by Sergey Bayrachny

The Overview is an all-in-one starting point to quickly check out for Content recommendations individually tailored to your needs and get insights into your company's Content usage over time and compared to your industry and country.

Setting Industry


For insights and recommendations to be relevant, it's important to have your company's industry and country set correctly.

If your industry is not set yet, click on "here" in the welcoming message.

A modal appears where you can select your industry from the dropdown. Choose a relevant option and click Confirm.

The changes are applied at once.

If you think that the industry currently set for your company is wrong, you can request to change it in the upper right corner.

After you update your industry:

  • If you have a Manager role, the selected industry will be applied to your company configuration at once.

  • If you don't have a Manager role, the selected industry has to be approved by your Manager.

  • If your company's team does not include a Manager role, our admins will review the requested change.

Users with a Manager role can also update their company's industry in the Account settings.

Users without a Manager role cannot edit this setting.

Dashboards


Dashboards display key information about your company's Content usage. The insights are updated twice a day.

Company Rank


The current rating of your company in its industry by the amount of Content in use.

While this metric is purely based on volume, it may indirectly indicate the effort that a particular company invests in timely research and detection of the latest behaviors used in cyber attacks.

Content Usage


Insights into your company's Content usage.

  • In Use: the number of Content items your company has copied, downloaded, or deployed using the SOC Prime Platform

  • Premium: the number of available Premium Content items which your company has not copied, downloaded, or deployed yet

  • Free: the number of available Free Content items which your company has not copied, downloaded, or deployed yet

Usage Trend Compared to Industry


The monthly trend of Content usage by your company compared to its industry (average and top performer).

This metric helps to determine if you’re dedicating enough effort and speed to researching, developing, and deploying threat detection rules and queries to understand the latest threats landscape, prepare your defenses in advance, and timely detect and respond to the latest cyber attacks.

Techniques & Sub-Techniques Addressed


Insights into MITRE ATT&CK® techniques and sub-techniques addressed by the Content your company has used, calculated by matching exact manually set ATT&CK tags vs ATT&CK Enterprise matrix.

  1. The number of techniques and sub-techniques addressed by the Content your company has used

  2. The percentage of all techniques and sub-techniques addressed by the Content your company has used

  3. The average number of techniques and sub-techniques addressed by the Content in use for companies in your industry

Coverage is a dynamic process, as > 85% of the Content is updated during each year. Coverage indication should be used as a reflection of the team’s progress towards detecting the latest behaviors used in cyber attacks, is not static, and should not be treated as a 100% detection possibility. For more information, we recommend the M.A.D. certification available here.

Trending Searches


Top searches on the SOC Prime Platform sourced by over 30,000 users from 8,000+ companies and 155 countries. The trend is calculated based on the popularity for the last 14 days.

Click a search term to go to Advanced Search and see the Content that matches it.

Recommended Content


The lower part of the page includes 7 different sorting and filtering options tailored specifically to your company. Each tab lists the top 5 Content items. To check out all Content for the selected option, click See All at the bottom of the page.

  • Latest Vulnerabilities. Recommended Rules and Queries to detect the exploitation of the most recent, critical, exploitable and publicly disclosed cybersecurity vulnerabilities

  • Log Sources. Recommended Rules and Queries which match the log sources defined in your default Search Profile

  • Threat Actors. Recommended Rules and Queries to detect the activity of Threat Actors (Groups) relevant to your industry and country per MITRE ATT&CK

  • Smoking Guns. The most stable, validated and popular behavior-based Sigma rules to detect the most severe malicious activity

  • Country. Recommended Content most relevant in your country, based on SOC Prime’s dynamic usage statistics across 155 countries

  • Industry. Recommended Content most relevant in your industry, derived from dynamic usage statistics of at least 100 companies that work in the same industry as your company

  • CERT Toolkit. Content to detect threats mentioned in CERT teams reports and advisories for the country where your company has its HQ

Did this answer your question?