new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

logging/context

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Mean time to identify a breach is approximately 200 days

According to the IBM Cost of a Data Breach Report 2025, the mean time to identify a breach continues to hover around 200 days. Standardized security event logging with consistent keywords can improve detection and response time.

Security event logging vocabulary goal and assumptions

The OWASP logging vocabulary aims to simplify monitoring and alerting by defining specific keywords for security events. Success requires: Observability/SRE groups support and encourage developer use; Incident Response ingests data or provides notification means; Architects support and adopt the standard; Developers embrace and implement it with understanding of potential attacks.

Libraries implementing OWASP logging vocabulary

Multiple language libraries implement the OWASP logging vocabulary: Python has lucabello/owasp-logger and thatsjet/security_event_logger; C#/.NET has byteguard-hq/byteguard-security-logger; Java, Go, and Node.js have thatsjet/security_event_logger.

Give your agent this brain