A SIEM use case typically describes:

  • a threat
  • the necessary data
  • a detection logic
  • an alert
  • a level of criticality
  • an investigation procedure
  • An answer.

Example :

Use case: Compromised privileged account

Sources:

  • Active Directory
  • Entra ID
  • VPN
  • EDR
  • firewall.

Detection:

  • unusual authentication
  • followed by an increase in privileges
  • followed by access to a critical server.

Action :

  • critical alert
  • investigation
  • account verification
  • Possibly blocking depending on the level of confidence.

This approach makes the SIEM truly operational.

Categories: