Building a security incident investigation module

Datamplify started developing an incident investigation prototype for Security Information and Event Management (SIEM) systems.

It brings together alerts, findings and related evidence from different cybersecurity tools into a common investigation workflow. The prototype links this evidence to affected assets and reconstructs events into a single chronological incident timeline, helping security teams investigate suspicious activity, understand possible attack paths and prioritise their response. An AI-assisted component will also be explored to summarise evidence, highlight possible relationships between events and support analyst prioritisation, while final decisions remain with the human analyst.

Healthcare is the project’s primary validation use case, with Papageorgiou General Hospital participating as an end user and providing a real-world environment for validation against operational security needs.

The project will also explore applicability to health-data exchange infrastructures, including the European Health Data Space (EHDS) / HealthData@EU, examining their architecture and open-source components to identify potential sources of security logs and alerts for event correlation and incident reconstruction.

Leave a Reply

Your email address will not be published. Required fields are marked *