Let's imagine an attack against a company.
At 02:14, an administrator account connects from an unusual IP address.
At 02:16, this account accesses a critical server.
At 02:18, an unusual PowerShell command was executed.
At 02:21, several files are compressed.
At 02:24, an unusual outgoing connection appears.
At 02:26, several accounts were locked.
Taken separately, each of these events may have a legitimate explanation.
But their succession can be an extremely important indicator.
Without centralization, the analyst must consult:
- firewall logs
- Active Directory logs
- Windows logs
- EDR logs
- proxy logs
- cloud logs.
With a SIEM, this information can be gathered in a single platform.
This is one of the first major values of SIEM:
Transforming a multitude of isolated signals into a coherent view of IT environment activity. CISA also recommends centralizing logs, emphasizing that this facilitates the detection of unusual behavior.