Compound queries in Gravwell unlock incredible potential for analysts who need to ask critical questions about their data.
In this short video, we use a compound query containing a non-temporal lookup table to combine two discrete data sources in order to understand the different locations from which an attacker was staging their malware and gain further insights into the attacker’s TTPs across our systems.
Gravwell is a data platform with security lake features that enables teams to investigate, collaborate, and analyze data on-demand, from any source — all with unlimited data collection and retention.…