A cybersecurity incident is not limited to detection.
After an alert, the team must determine:
- when the attack began;
- which account was compromised;
- which machine was initially affected;
- how the attacker moved;
- what data was consulted;
- what actions have been carried out;
- if other systems are compromised;
- if the attacker still has access.
Historical logs then become essential.
The SIEM allows you to search for events over a given period and reconstruct a chronology.
This capability can greatly facilitate the work of analysts.