Events 0
En
Ua
Events 0
Search result:
Cribl integrates CardinalOps: new capabilities for modernizing SIEM- image 1

Cribl integrates CardinalOps: new capabilities for modernizing SIEM

Cribl announced the acquisition of CardinalOps—a solution for Agentic Detection Engineering. The company considers this deal an important step towards creating an open alternative to traditional SIEM platforms.

According to Cribl, modern cybersecurity teams face multiple challenges simultaneously. The volume of telemetry data is constantly growing, IT infrastructures are becoming increasingly complex and distributed, threats are evolving faster, and cybersecurity budgets are not keeping up with these changes. As a result, organizations are forced to collect more data, spend more resources on processing it, and maintain tools, but this does not guarantee a better level of protection.

Cribl integrates CardinalOps: new capabilities for modernizing SIEM - image 1
A NEW APPROACH

Why the traditional SIEM approach no longer works

For many years, the market followed the same model: more event logs, more tools, more detection rules, and consequently, a higher level of security. In practice, this approach led to a different outcome. Organizations ended up with more complex infrastructures, higher costs, and significant operational burdens, but failed to ensure that their detection mechanisms were indeed operational.

That’s why Cribl is focusing on rethinking the very architecture of cybersecurity operations. We believe that customers need a platform that doesn’t require centralizing all data and paying for its storage and indexing. Instead, they expect a more open approach that allows the gradual modernization of existing infrastructure without being tied to a single vendor.

CRIBL PLATFORM

From telemetry to effective detection

Before acquiring CardinalOps, the Cribl platform already supported the full telemetry lifecycle. It allows collecting, analyzing, transforming, routing, storing, and utilizing telemetry data across various environments.

The platform is characterized by its openness and independence from specific vendors. Clients can work with different security tools without having to reshape their entire infrastructure around a single solution.

A vital part of this architecture is the federated approach to data management. Instead of moving all telemetry to a single centralized repository, the platform allows searching and analyzing where the data already resides. This helps reduce costs, avoid data duplication, and retains infrastructure flexibility. CardinalOps capabilities are now being integrated into this foundation.

SYNERGY OF SOLUTIONS

How CardinalOps complements the Cribl platform

CardinalOps uses AI for continuous evaluation and improvement of threat detection mechanisms. The solution matches existing protection means against actual cyber adversary tactics and techniques, helping organizations objectively assess coverage levels and identify gaps.

The platform automates detection engineering processes, finds faulty or excessively “noisy” rules, identifies missing detection mechanisms, and helps make better use of existing security tools. Combined with Cribl’s capabilities for enterprise-scale telemetry management, CardinalOps ensures continuous quality control of detection, helping to quickly turn telemetry data into actionable insights and enhance the overall level of cyber defense.

CardinalOps helps to:

  • assess threat coverage levels;
  • identify detection mechanism gaps;
  • detect faulty rules;
  • find rules that create excessive informational noise;
  • automate significant parts of detection engineering processes;
  • enhance the efficiency of existing protection means.

Cribl notes that this component was the missing link between telemetry and the tangible results of SOC performance.

TELEMETRY EFFICIENCY

Data is present, but effective detection is absent

One of the key arguments for acquiring CardinalOps was the results of the company’s own research. On average, organizations today collect enough telemetry to cover about 90% of MITRE ATT&CK techniques. Meanwhile, SIEM systems have detection mechanisms for only about 21% of these techniques.

Another problem is that approximately 13% of SIEM rules operate incorrectly. The reasons may include changes in data schemas, filter modifications, or mismatches in data models and event types. In such cases, detection mechanisms may cease to function without any apparent signs to analysts. This gap between the collected telemetry volume and actual detection capabilities is a primary issue of modern SIEM solutions.

“Today, organizations are looking for a comprehensive approach that helps efficiently work with telemetry, improve threat detection quality, and manage costs. The combination of Cribl’s and CardinalOps’ capabilities allows us to move precisely in this direction. We see great potential in this solution for the market as it enables the modernization of existing SOCs without the need to completely restructure the infrastructure or abandon already implemented protection tools.”

Oleksiy Nayda
Cribl BDM, iITD
Cribl integrates CardinalOps: new capabilities for modernizing SIEM - image 2
quote background
quote circle

Not another SIEM, but a different approach

CardinalOps is not a new SIEM and does not replace it as a standalone product. Instead, the solution adds one of the key functional components of modern cybersecurity operations—continuous detection engineering.

Combined with the Cribl telemetry platform, this forms a complete operational cycle: from data collection and optimization to continuous improvement of detection mechanisms. This approach is what Cribl refers to as the beginning of a new generation of open, modular SIEM based on the customer’s existing telemetry infrastructure.

Enhancing coverage without creating a new closed platform

One of CardinalOps’ key features is the continuous analysis of detection coverage levels according to the MITRE ATT&CK framework.

The solution automatically matches existing rules with attack techniques, identifies gaps, checks the functionality of rules, and provides recommendations for creating new detection mechanisms. It supports work with implemented SIEM and EDR solutions, allowing organizations to improve protection efficiency without abandoning existing tools.

As a result, cybersecurity teams gain a more comprehensive view of their security posture, can quickly identify vulnerabilities, and assess how well their detection mechanisms comply with contemporary threats.

Cribl integrates CardinalOps: new capabilities for modernizing SIEM - image 3

Cost reduction without losing effectiveness

Another principle that Cribl considers fundamentally important is optimizing data processing costs. The company emphasizes that integrating CardinalOps does not mean a need to collect even more telemetry or move all information to a new centralized repository.

On the contrary, data processing is suggested before it starts incurring additional costs. Telemetry can be routed according to specific use cases—for threat detection, event correlation, investigations, compliance requirements, or future AI services.

At the same time, CardinalOps helps ensure that the detection mechanisms using this data remain effective even after changes in infrastructure or information sources. Thus, organizations no longer have to choose between resource savings and protection quality.

CONCLUSION

From telemetry to intelligent threat detection

Cribl calls the acquisition of CardinalOps one of the key steps in developing its AI Platform for Telemetry. The company aims to provide an open architecture combining telemetry management, continuous detection engineering, and the ability to utilize existing customer infrastructure.

Integration of CardinalOps technologies has already begun. In the foreseeable future, it is set to form a full-fledged open alternative to traditional SIEM architectures, built on principles of modularity, federated data management, and vendor independence. This will enable organizations to modernize their cybersecurity operations more effectively, reducing infrastructure complexity, optimizing costs, and enhancing detection quality against modern threats.

iITD is the official distributor of Cribl, assisting partners and customers in implementing modern solutions for telemetry management and cybersecurity operations modernization.

Our team is ready to demonstrate the Cribl platform’s capabilities, discuss new CardinalOps features, and help evaluate how the solution can strengthen your specific infrastructure.

NEWS

Current news on your topic

All news
All news