Skip to content

Author: Cathy Gaphty

Cathy is a cybersecurity-focused technical writer who turns complex security concepts into clear, usable content for practitioners and decision-makers. She partners with security engineers, analysts, and product teams to create architecture guides, API references, runbooks, and user documentation for the Léargas Security platform, and its integrated systems. Her work supports incident response, threat detection, and compliance initiatives aligned to frameworks such as NIST CSF and ISO 27001. Cathy favors a docs-as-code approach with Git and Markdown, validating steps in lab environments to ensure accuracy down to commands and configurations. Known for crisp, audience-specific writing and meticulous reviews, she bridges the gap between security theory and day-to-day operations.

Zeek vs NetFlow: Why Léargas chose Zeek

Zeek vs NetFlow is a decision many organizations face when selecting a network monitoring and security foundation. This overview explains how each approach collects and analyzes traffic—and why we proudly build on Zeek with the Léargas Security platform. What is Zeek? Zeek is an open-source framework for network security monitoring that passively inspects packets and converts activity into structured, real-time logs. Its event-driven architecture
Read More

Real-Time Vulnerability Correlation Reduces False Positives and Speeds Remediation

This case study explains how Léargas introduced real-time vulnerability correlation to raise alert accuracy, reduce noise, and speed response. As a result, analysts now get current vulnerability context the moment an alert is triggered. Background The Léargas platform already excelled at correlating data across logs, endpoints, and network activity. However, analysts often reviewed alerts without knowing each asset’s latest exposure. Consequently, teams spent extra
Read More

SentinelOne Integration for MSPs: Léargas Unifies Visibility

SentinelOne integration for MSPs is now live in the Léargas Platform. Managed IT Providers and MSSPs get one real-time view that links endpoint detections to network behavior. This deep integration adds speed, context, and automation so teams can investigate and respond without gaps. What this integration delivers Complete correlation: Léargas ingests SentinelOne alerts, telemetry, and policy events. It maps them to network flows, from
Read More