By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Permiso launches open-source P0LR Espresso to normalize cloud logs for faster threat response – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Permiso launches open-source P0LR Espresso to normalize cloud logs for faster threat response – News
News

Permiso launches open-source P0LR Espresso to normalize cloud logs for faster threat response – News

News Room
Last updated: 2025/10/03 at 9:37 AM
News Room Published 3 October 2025
Share
SHARE

Identity threat detection and response startup Permiso Security Inc. today launched a new open-source tool aimed at simplifying one of the biggest pain points in cloud defense: inconsistent logging across platforms.

Called P0LR Espresso, the first part short for P0 Labs Live Response, the framework normalizes cloud runtime logs to give security teams faster, clearer insights when triaging suspicious activity.

The tool seeks to assist with the issue whereby security practitioners have long been hindered by vendor-specific log formats. Amazon Web Services Inc., Google Cloud Platform, Microsoft Azure, Okta Inc. and GitHub all log activity differently, often labeling identical fields with completely different names.

For example, what AWS calls eventName might appear as protoPayload.methodName in GCP. Analysts investigating identity behavior or cross-environment anomalies must spend valuable time learning each provider’s structure and rewriting queries accordingly.

P0LR Espresso addresses the issue by unifying critical fields, such as identity, IP address, user agent and action, into a consistent schema. The result allows defenders to focus directly on the story contained in the data instead of having to decipher multiple log structures.

The tool is designed to assist with Priority-0 Live Response investigations, where analysts are under pressure to quickly determine if an identity is compromised. P0LR Espresso helps streamline triage and reduces the risk of missing key indicators from inconsistent log naming conventions by “pulling shots” of normalized context.

The interface within P0LR Espresso comes with three primary sections: an event list, indicators of compromise panel and identity activity analysis.

The event list offers normalized views of activities with filters for users, IPs and actions, as well as counts of indicators of compromise. The complimentary IOC panel allows deeper exploration of triggered alerts and the identity activity analysis view plots behavior across timelines, making it easier to spot anomalies or unusual activity clusters.

The company said in a blog post that normalizing during the initial ingestion of runtime events greatly simplifies all downstream log analysis, whether manual investigations or additional automated detection evaluation.

Image: News/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article I tried Amazon and Google’s new smart home gadgets this week, ask me anything!
Next Article Nvidia G-Assist will use AI to improve your laptop’s battery life now
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Here’s my top 10 list of Apple and non-Apple tech – what’s yours? – 9to5Mac
News
Baidu’s AI bot has 300 million users, two months after reaching 200 million milestone · TechNode
Computing
Late-stage funding surges as UK tech ranked second globally – UKTN
News
Sony shrinks PS5 Slim storage in the US, too
News

You Might also Like

News

Here’s my top 10 list of Apple and non-Apple tech – what’s yours? – 9to5Mac

10 Min Read
News

Late-stage funding surges as UK tech ranked second globally – UKTN

2 Min Read
News

Sony shrinks PS5 Slim storage in the US, too

1 Min Read
News

Will Bigbear.AI be worth more than Palantir in 10 years?

6 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?