|
|
|
|
|
by shaeqahmed
1240 days ago
|
|
Some big differences: - Matano has realtime Python + SQL detections as code with advanced correlation support. Chronicle uses inflexible YARA-like detection rules iirc - Matano supports Sigma detections by automatically transpiling them to the Python detection format - Matano has an OSS Vendor Agnostic Security Data Lake and can work with multiple clouds / let's you bring your own query engine (Snowflake, Spark, Athena, BigQuery Omni). Chronicle is a proprietary SIEM that uses BigQuery under the hood and cannot be used with other tooling. There are no limits on data retention or ingestion with Matano, it's your S3 bucket and the compute scales horizontally. |
|
I looked at your sample detection on the home page. This is have for me but I can't get others to use it. I promise you, doing a little market research on thid outside of the tech bubble will save you a lot of money and resources.