Let's imagine an attack against a company.

At 02:14, an administrator account connects from an unusual IP address.

At 02:16, this account accesses a critical server.

At 02:18, an unusual PowerShell command was executed.

At 02:21, several files are compressed.

At 02:24, an unusual outgoing connection appears.

At 02:26, ​​several accounts were locked.

Taken separately, each of these events may have a legitimate explanation.

But their succession can be an extremely important indicator.

Without centralization, the analyst must consult:

  • firewall logs
  • Active Directory logs
  • Windows logs
  • EDR logs
  • proxy logs
  • cloud logs.

With a SIEM, this information can be gathered in a single platform.

This is one of the first major values ​​of SIEM:

Transforming a multitude of isolated signals into a coherent view of IT environment activity. CISA also recommends centralizing logs, emphasizing that this facilitates the detection of unusual behavior.

Categories: