DEW #145 - Modified Z-Score for Anomaly Detection, Watermarking for Audit Logs -> SIEM and Zack gives you all an RFC for homework (opens in new tab)
You must write "I will not write a detection rule for IP addresses" 1000 times
Read the original article