Modern cybersecurity is no longer simply about asking:

“What happened?”

You must also answer the following:

  • Who ?
  • When ?
  • Or ?
  • From which machine?
  • From which IP address?
  • On which system?
  • Which account?
  • With what privileges?
  • What action was taken?
  • What happened before?
  • What happened next?
  • Is this activity normal?
  • Are there other similar events?
  • Is this machine critical?
  • Is this user privileged?
  • Is this IP address known to be malicious?
  • Does this activity correspond to a known attack technique?

The SIEM allows these elements to be brought together in a single analysis.

This notion of context is fundamental to reducing the time needed for the investigation.

Categories: