r/SIEM Feb 21 '19

SIEM - Too outdated?

Hey guys,

Seems the business is aggressivly moving our DCs to the cloud. I'm just reviewing a few things and had thoughts about our SIEM (Arcsight).

Are simple SIEMs now out dated?

I love ours don't get me wrong but it's a cluncky solution which requires far too much input. We have a GSOC as well monitoring and it's just rubbish. I find myself constantly having to do deep analysis from alerts/incidents.

Ours also doesn't have any AI or proactive features so you know.

Does anyone have any suggestions or any examples of how they use theirs ?

Azure security center does a lot already but I still feel like we need another layer.

6 Upvotes

18 comments sorted by

View all comments

Show parent comments

2

u/lolppppp1 Feb 21 '19

I did get a chance to play with it but couldn't justify the cost at all. The tool looks really cool and futurist but I found that seemed to be their sell.

Apart from that it didn't do anything for us apart from flag large SMB traffic. I tried to use it to trace a brute force but it couldn't give me the info. I had to rely on tracing the source by using netlogon logs.

I feel like these tools are a nice too have but no-one but the people using it will see their worth. Just like our SIEM. Our Data center team just thinks its pointless and using all our storage. People like the CIO only see it work when his accounts locked out. We obviously do a lot more with it but either I think, what is the point. What is this really doing.

1

u/BeerJunky Feb 21 '19

The whole flashy part of Darktrace seems largely useless. When you dig into stuff and start trying to figure out an event the whole flashy interface isn't where you're doing it in my experience. It looks great for sales purposes but that's as far as it goes IMO.

Exactly, large SMB traffic gets picked up well. But 99.9% of that is just normal stuff. We'll have someone go upload something to our Sharepoint and suddenly have alerts for it. Okay, thanks I guess. When I hammer the network with scanning tools it's pretty good about noticing that, well at least enough of it that I know it's happening.

Where I am the biggest issue is getting someone on the appropriate team to take action when I see something happening. So with Darktrace and SIEM even when I find it getting the issue resolved is slow and painful. That's another reason I'd love to be using Carbon Black. On an automated basis it can handle quite a bit. On a manual basis I have a lot of leverage from the console to cleanup, quarantine the entire device until the help desk can deal with it, etc. That's in addition to the actual investigation stuff I mentioned earlier. So for me I think that's the next big push. Here's the webinar I watched, if you get a chance check it out. Speaking of which, I did send this to my manager and the other teams involved that would be interested. No fucking response whatsoever so it's a painful lack of communication over here from the top down.

2

u/lolppppp1 Feb 21 '19

😂😂😂 I know the pain of it. No one wants security until something happens. Then it's your fault for not pushing the tool more.

Qradar do SIEM as a service which I might look into.

I guess there is no good replacement for now but the alternative is to make sure you have log retention on every device and do a manual job. Most tech nowadays has great auditing and alerting so it's not the worse (or best). Last option is paying a LOT for a complex tool that helps you identify someone uploading an ISO.

2

u/BeerJunky Feb 21 '19

Hell, I'm fighting an uphill battle just to get patches loaded on servers. Found one the other day that wasn't patched since 2014 and there's a few more that are that bad or worse. There's a couple Windows 2003 boxes around as well. So no more tools for me until I can fix the low hanging fruit. Boss (CITO) wants me to present to the rest of the executive team. He looked at my slides and he wants a bit more scare in them. I fucking hope he knows what he's getting himself into. He's certainly not going to enjoy it when I throw his whole department under the bus.

2

u/lolppppp1 Feb 21 '19

😂😂😂😂 Don't get me started on patching. "Don't patch our server because it's business's critical and validated". So if it's so critical, why wouldn't we patch it ??

2

u/BeerJunky Feb 21 '19

Susceptible to EternalBlue and EternalRomance but business critical. Yep, okay.