Modern cybersecurity is no longer simply about asking:
“What happened?”
You must also answer the following:
- Who ?
- When ?
- Or ?
- From which machine?
- From which IP address?
- On which system?
- Which account?
- With what privileges?
- What action was taken?
- What happened before?
- What happened next?
- Is this activity normal?
- Are there other similar events?
- Is this machine critical?
- Is this user privileged?
- Is this IP address known to be malicious?
- Does this activity correspond to a known attack technique?
The SIEM allows these elements to be brought together in a single analysis.
This notion of context is fundamental to reducing the time needed for the investigation.