Sort replies: Relevant Recent Liked
Log lines are the perfect carrier for this β€” anyone can write to your SIEM by just sending a weird User-Agent, and the analyst LLM reads it as instruction. Curious whether your poster covers the alert-suppression case (attacker gets their own events triaged as benign) vs just out
18