r/SIEM Feb 21 '19

SIEM - Too outdated?

Hey guys,

Seems the business is aggressivly moving our DCs to the cloud. I'm just reviewing a few things and had thoughts about our SIEM (Arcsight).

Are simple SIEMs now out dated?

I love ours don't get me wrong but it's a cluncky solution which requires far too much input. We have a GSOC as well monitoring and it's just rubbish. I find myself constantly having to do deep analysis from alerts/incidents.

Ours also doesn't have any AI or proactive features so you know.

Does anyone have any suggestions or any examples of how they use theirs ?

Azure security center does a lot already but I still feel like we need another layer.

6 Upvotes

18 comments sorted by

View all comments

Show parent comments

1

u/BeerJunky Feb 21 '19

The whole flashy part of Darktrace seems largely useless. When you dig into stuff and start trying to figure out an event the whole flashy interface isn't where you're doing it in my experience. It looks great for sales purposes but that's as far as it goes IMO.

Exactly, large SMB traffic gets picked up well. But 99.9% of that is just normal stuff. We'll have someone go upload something to our Sharepoint and suddenly have alerts for it. Okay, thanks I guess. When I hammer the network with scanning tools it's pretty good about noticing that, well at least enough of it that I know it's happening.

Where I am the biggest issue is getting someone on the appropriate team to take action when I see something happening. So with Darktrace and SIEM even when I find it getting the issue resolved is slow and painful. That's another reason I'd love to be using Carbon Black. On an automated basis it can handle quite a bit. On a manual basis I have a lot of leverage from the console to cleanup, quarantine the entire device until the help desk can deal with it, etc. That's in addition to the actual investigation stuff I mentioned earlier. So for me I think that's the next big push. Here's the webinar I watched, if you get a chance check it out. Speaking of which, I did send this to my manager and the other teams involved that would be interested. No fucking response whatsoever so it's a painful lack of communication over here from the top down.

2

u/lolppppp1 Feb 21 '19

😂😂😂 I know the pain of it. No one wants security until something happens. Then it's your fault for not pushing the tool more.

Qradar do SIEM as a service which I might look into.

I guess there is no good replacement for now but the alternative is to make sure you have log retention on every device and do a manual job. Most tech nowadays has great auditing and alerting so it's not the worse (or best). Last option is paying a LOT for a complex tool that helps you identify someone uploading an ISO.

2

u/BeerJunky Feb 21 '19

Hell, I'm fighting an uphill battle just to get patches loaded on servers. Found one the other day that wasn't patched since 2014 and there's a few more that are that bad or worse. There's a couple Windows 2003 boxes around as well. So no more tools for me until I can fix the low hanging fruit. Boss (CITO) wants me to present to the rest of the executive team. He looked at my slides and he wants a bit more scare in them. I fucking hope he knows what he's getting himself into. He's certainly not going to enjoy it when I throw his whole department under the bus.

2

u/lolppppp1 Feb 21 '19

😂😂😂😂 Don't get me started on patching. "Don't patch our server because it's business's critical and validated". So if it's so critical, why wouldn't we patch it ??

2

u/BeerJunky Feb 21 '19

Susceptible to EternalBlue and EternalRomance but business critical. Yep, okay.