TechDogs-"Uncoder.IO Now Powered By AI: An Ultimate IDE For Detection Engineering"

IT Security

Uncoder.IO Now Powered By AI: An Ultimate IDE For Detection Engineering

By Business Wire

Business Wire
Overall Rating

Industry-First Augmented Intelligence Framework to Code, Validate, and Share Detection Logic Globally via Sigma Rules and MITRE ATT&CK®

BOSTON--(BUSINESS WIRE)--#CyberDefense--SOC Prime, the world’s largest and most advanced platform for collective cyber defense, announces the upgrade of its Uncoder.IO project to Uncoder AI, an integrated development environment (IDE) for Detection Engineering, which converts generic Sigma rules along with tactical threat intelligence IOC collections into 64 SIEM, EDR, XDR, and Data Lake query formats.

According to the latest research by Gartner, leveraging AI-based threat detection engines focused on behavioral indicators provides increased visibility into cybersecurity threats and contributes to threat detection effectiveness. In practice, this means that the cyber defense industry needs to leverage behavior-based TTP detections at scale, agnostic of SIEM or XDR in place, along with a common threat description language and a common data schema, such as OCSF, to establish a foundation for this shift. With SOC Prime’s innovation-driven mindset focused on the era of AI, the Uncoder.IO project – initiated and supported by the Ukrainian team of security enthusiasts at SOC Prime since 2018 – evolves into Uncoder AI.

“With an upgrade from Uncoder.IO to Uncoder AI, we equip each cyber defender with an IDE to master one common language for cybersecurity, thus enabling collective threat-informed defense," says Andrii Bezverkhyi, inventor of the Uncoder project, CEO and Founder at SOC Prime. “Instead of locking detection algorithms within one of the many SIEM, EDR, XDR, or Data Lake technologies, Uncoder can help you literally speak and understand 64 of these query languages at once while working together with your peers online to create detections against any cyber threat, before it manifests itself into an attack. This is a fundamental change to cyber defense by acting together, we create a positive network effect that drives down the costs while accelerating the speed and accuracy at the same time.”

By taking joint action in describing detection code on offensive tools and TTPs, cyber defenders are able to deploy detection algorithms proactively, months and sometimes even years before adversaries mount an attack. This comes hand in hand with exchanging Detection Engineering and DevSecOps know-how on data access, as well as with accelerating Amazon's OCSF adoption. In collective cyber defense, there is no client-vendor relationship – SOC Prime acts as a partner and as a peer colleague for each Detection Engineering and Threat Hunting professional.

To address the existing cybersecurity challenges demanding cost-efficient, fast, and feasible solutions, SOC Prime offers a large part of the Uncoder capabilities as a freemium community IDE. To unlock the full potential of the IDE for threat-informed defense, security experts can gain from the professional use of Uncoder AI, available at a personally affordable price range, just like buying a Netflix or Spotify monthly subscription, purchasable by a credit card via Stripe.

Uncoder AI fuses collective industry expertise along with artificial and augmented intelligence. Backed by the Sigma language as the core standard for the conversion engine, the tool enables security professionals to code, exchange, and improve detection algorithms while ensuring the privacy, security, and intellectual property rights of threat researchers. Since the official release of Uncoder AI on May 26, 2023, over 3,300+ detection engineers, threat hunters, and SOC analysts from 100+ countries have relied on it to research the latest cyber attacks, write Sigma rules, quickly and reliably translate them to their preferred query language, pack IOC collections alongside behavior-based detections, and get required metadata, including MITRE ATT&CK dictionaries, threat intelligence, CVE and exploit context, as well as log source data auditing requirements – all from a single tool.

Striving to outpace and outsmart attackers, Uncoder AI delivers sub-second performance on any detection engineering task, including line-by-line code validation and bug fixing, automated autocompletion, and IOC-based query generation. Beyond Sigma rule coding and bi-directional query translation, security engineers can build their threat research on top of collective industry expertise. Uncoder AI enriches detection algorithms with relevant threat intelligence from OSINT and external TIPs and automatically generates use case documentation to store on external systems.

The tool is run on a private cloud to provide an even more secure service to SOC Prime’s clients. Similarly to Uncoder.IO, Uncoder AI ensures no code logging or data sharing with third parties while fostering respect for the ownership rights of threat researchers who contribute their detection code. Threat research expressed through Sigma rules is considered the content authors’ intellectual property, and SOC Prime keeps all data confidential unless a researcher decides to share it via the crowdsourcing initiative, Threat Bounty Program. Being a trusted security-minded organization, SOC Prime regularly completes the audit for SOC 2 Type II certification while strictly adhering to GDPR guidelines and verifying its compliance with the high standards of excellence in cybersecurity.

Join the Uncoder community at SOC Prime´s Discord server: https://discord.gg/socprime or learn more about Uncoder at https://uncoder.io.

About SOC Prime

Headquartered in Boston, SOC Prime operates the world’s largest and most advanced platform for collective cyber defense that cultivates collaboration from a global cybersecurity community and curates the most up-to-date Sigma rules compatible with over 27 SIEM, EDR, and XDR platforms. SOC Prime’s innovation, backed by the vendor-agnostic and zero-trust cybersecurity approach, and cutting-edge technology leveraging Sigma language and MITRE ATT&CK® as core pillars are recognized by the independent research companies, credited by the leading SIEM, XDR & MDR vendors, and trusted by 8,000+ organizations, including 42% of Fortune 100 and 21% of Forbes Global 2000. Flexible subscriptions ensure that both organizations and individual operators can benefit from SOC Prime’s curated detection content and enhanced cyber defense capabilities. SOC Prime is backed by DNX Ventures, Streamlined Ventures, and Rembrandt Venture Partners, having received $11.5M in funding in October 2021. For more information, visit https://socprime.com or follow us on LinkedIn & Twitter.

Contacts

Daryna Oliniichuk
d.olyniychuk@socprime.com

First published on Thu, Aug 3, 2023

Enjoyed what you read? Great news – there’s a lot more to explore!

Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!

Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.

Head to the TechDogs homepage to Know Your World of technology today!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs’ members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs’ Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. All information / content found on TechDogs’ site may not necessarily be reviewed by individuals with the expertise to validate its completeness, accuracy and reliability.

Tags:

Identity And Access ManagementSOC Prime Integrated Development Environment (IDE) Detection Engineering Tactical Threat Intelligence

References:

Join The Discussion

  • Dark
  • Light