Apache Kafka: Open Source Streaming Data Lake for Threat Detection

Apache Kafka: Open Source Streaming Data Lake for Threat Detection Customers would normally need to deploy a proprietary software with a database and /or data lake to contain large volumes of Data to detect threats, such as inside a SIEM. This of course becomes extremely expensive and your are locked into a vendor. Apache Kafka,… Continue reading Apache Kafka: Open Source Streaming Data Lake for Threat Detection

AWS Logging and Monitoring Design

AWS Logging and Monitoring Design With practical and tangible Action plan – not just theoretical fluff ignored by hackers. Firstly, as much as AWS want to advertise they are secure, enabling Logging Monitoring AWS is; Not straight forward Missing allot of information from AWS, which falls under your shared responsibility. (Public Cloud Security Get out… Continue reading AWS Logging and Monitoring Design

HP ArcSight Vs. IBM QRadar Vs. ​McAfee Nitro Vs. Splunk Vs. RSA Security Vs. LogRhythm

HP ArcSight Vs. IBM QRadar Vs. ​McAfee Nitro Vs. Splunk Vs. RSA Security Vs. LogRhythm Original – https://www.itcentralstation.com/product_reviews/logrhythm-nextgen-siem-review-32130-by-vinod-shankar The key products compared here are based on Gartner Magic Q which is what Organizations typically use to select SIEM vendors. The Vendors mentioned here in the deck are : 1. HP ArcSight 2. McAfee Nitro 3.… Continue reading HP ArcSight Vs. IBM QRadar Vs. ​McAfee Nitro Vs. Splunk Vs. RSA Security Vs. LogRhythm

Comprehensive Explanation: What is a SIEM (in 2020 and beyond.)

Comprehensive Explanation: What is a SIEM (in 2020 and beyond.) [I have not had the time to proof read nor correct grammatical errors, spelling mistakes and typos. ] SIEM unifies Threat Detection and Hunting. This is an old topic worth revising and level setting with the latest advancements, concepts and learning from a decades of… Continue reading Comprehensive Explanation: What is a SIEM (in 2020 and beyond.)

InterSET UEBA – Unsupervised Machine Learning for SOC operations.

InterSET UEBA – Unsupervised Machine Learning for SOC operations. Machine Learning Best Practices Reference: Hype Cycle for Data Science and Machine Learning, 2019 How Can Midsize Enterprises Exploit AI and Data Monetization 1. StartwithYourUseCase You can’t find a solution without understanding the problem. Before buying or implementing new machine learning technology, identify the security use… Continue reading InterSET UEBA – Unsupervised Machine Learning for SOC operations.

Published
Categorised as ArcSight

Microfocus Security ArcSight ESM

Microfocus / ArcSight Data Platform / ArcSight ESM Reference Architecture Connector -> Logger -> ESM (Ideally.) Connector -> ESM -> Logger Connector -> Logger & ESM Youtubes Here’s the video showing what is possible with that CIRCP MISP integration How ArcSight, CIRCL MISP and MITRE ATT&CK matrix can be used to provide realtime protection against… Continue reading Microfocus Security ArcSight ESM