cd/entity/Sysmon Event 1ยท homeโ€บ entitiesโ€บ Sysmon Event 1
grep -l @sysmon event 1 /news/*.json | wc -l โ†’ 1

@Sysmon Event 1

mentions 1 type Person feed RSS
10:45
2026-05-31
dev.to
ai-tools

I let the AI write the report, not decide the alerts

A developer built a SOC triage tool called TriageLens that separates detection from AI-generated reporting. The tool uses deterministic TypeScript code for parsing, detection, and risk scoring, with Aโ€ฆ

// co-occurs with top 6 entities