Apache Kafka: Open Source Streaming Data Lake for Threat Detection Customers would normally need to deploy a proprietary software with a database and /or data lake to contain large volumes of Data to detect threats, such as inside a SIEM. This of course becomes extremely expensive and your are locked into a vendor. Apache Kafka,… Continue reading Apache Kafka: Open Source Streaming Data Lake for Threat Detection
Category: ArcSight
AWS Logging and Monitoring Design
AWS Logging and Monitoring Design With practical and tangible Action plan – not just theoretical fluff ignored by hackers. Firstly, as much as AWS want to advertise they are secure, enabling Logging Monitoring AWS is; Not straight forward Missing allot of information from AWS, which falls under your shared responsibility. (Public Cloud Security Get out… Continue reading AWS Logging and Monitoring Design
HP ArcSight Vs. IBM QRadar Vs. McAfee Nitro Vs. Splunk Vs. RSA Security Vs. LogRhythm
HP ArcSight Vs. IBM QRadar Vs. McAfee Nitro Vs. Splunk Vs. RSA Security Vs. LogRhythm Original – https://www.itcentralstation.com/product_reviews/logrhythm-nextgen-siem-review-32130-by-vinod-shankar The key products compared here are based on Gartner Magic Q which is what Organizations typically use to select SIEM vendors. The Vendors mentioned here in the deck are : 1. HP ArcSight 2. McAfee Nitro 3.… Continue reading HP ArcSight Vs. IBM QRadar Vs. McAfee Nitro Vs. Splunk Vs. RSA Security Vs. LogRhythm
Comprehensive Explanation: What is a SIEM (in 2020 and beyond.)
Comprehensive Explanation: What is a SIEM (in 2020 and beyond.) [I have not had the time to proof read nor correct grammatical errors, spelling mistakes and typos. ] SIEM unifies Threat Detection and Hunting. This is an old topic worth revising and level setting with the latest advancements, concepts and learning from a decades of… Continue reading Comprehensive Explanation: What is a SIEM (in 2020 and beyond.)
Device Configuration for sending Threat Logs to a SIEM
Device Configuration for sending Threat Logs to a SIEM Microsoft Windows SYSMON – https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon Windows Local and Group Policy / ADM files Powershell File System
InterSET UEBA – Unsupervised Machine Learning for SOC operations.
InterSET UEBA – Unsupervised Machine Learning for SOC operations. Machine Learning Best Practices Reference: Hype Cycle for Data Science and Machine Learning, 2019 How Can Midsize Enterprises Exploit AI and Data Monetization 1. StartwithYourUseCase You can’t find a solution without understanding the problem. Before buying or implementing new machine learning technology, identify the security use… Continue reading InterSET UEBA – Unsupervised Machine Learning for SOC operations.
ArcSight Multi-Tenancy Design for MSSPs
ArcSight Multi-Tenancy Design for MSSPs Customer tagging is a feature developed mainly to support MSSP environments, although private organizations can use the technique to denote cost centers, internal groups, or business units. A Customer is not a source or target of an event, but it can be thought of as the owner of an event.… Continue reading ArcSight Multi-Tenancy Design for MSSPs
Microfocus Security ArcSight ESM
Microfocus / ArcSight Data Platform / ArcSight ESM Reference Architecture Connector -> Logger -> ESM (Ideally.) Connector -> ESM -> Logger Connector -> Logger & ESM Youtubes Here’s the video showing what is possible with that CIRCP MISP integration How ArcSight, CIRCL MISP and MITRE ATT&CK matrix can be used to provide realtime protection against… Continue reading Microfocus Security ArcSight ESM