A cybersecurity incident is not limited to detection.

After an alert, the team must determine:

  • when the attack began;
  • which account was compromised;
  • which machine was initially affected;
  • how the attacker moved;
  • what data was consulted;
  • what actions have been carried out;
  • if other systems are compromised;
  • if the attacker still has access.

Historical logs then become essential.

The SIEM allows you to search for events over a given period and reconstruct a chronology.

This capability can greatly facilitate the work of analysts.

Categories: