One point that is often overlooked is that logs constitute a target.

An attacker who wants to erase traces of their activity may try to:

  • delete events
  • edit logs
  • disable logging
  • compromise the log server
  • interrupt collection.

MITRE ATT&CK also documents the fact that adversaries can search for or exploit logs and target the logging infrastructure itself. [6]

Therefore, the SIEM must be protected against:

  • the removal
  • the modification
  • unauthorized access
  • the alteration
  • data loss.

Logging should not become an additional weak point.

Categories: