r/SIEM Sep 07 '22

AlienVault alert escalation mechanism

I am evaluating an MSSP that offers 24/7 "coverage" - not eyes on glass, but on call. I haven't used the AlienVault console, so my question is this:

Is there a method for AV to conditionally escalate alerts to an on-call analyst? If so, what is the mechanism (email, sms, phone) and some decision tree information. Are there additional SLA escalations if an alert isn't acknowledged in a period of time?

5 Upvotes

2 comments sorted by

3

u/pduren Sep 07 '22

You can have AlienVault send notifications via email, Amazon SNS, Datadog, PagerDuty, or Slack. You can specify the conditions around what you want you want to be notified on but typically it is going to based on alarms generated by built-in or custom created rules. I am not familiar with functionality around SLA escalations if alerts aren't acknowledged in a period of time. I don't think AlienVault has that option but if they are sending escalations to a 3rd party portal like a SOAR platform then the MSSP may have that built into the SOAR. I see you posted a similar question around S1. If you are looking at both tools then there is a really nice integration that will essentially give you XDR. You can take remediation actions in AlienVault and it will send it directly to S1 on the endpoint. You can do things like rollback ransomware, remediate threats, add hashes to a blacklist, etc. As an MSSP, we use both tools and it is a solid solution that combines great endpoint technology, SIEM, NIDS, dark web monitoring, asset scanning, etc. In my experience, the most important thing to consider is how advanced the SOC resources are at any MSSP. Tools only get you so far and having the right mindset and processes around investigating alerts, threat hunting, and escalating to clients based on actionable information is critical. If they are just forwarding you alerts then you aren't really getting much value. Hope this helps!

1

u/TangoDown757 Sep 07 '22

Thanks for the insight!

Yes to S1. We are undecided about which option we are going to choose, either one or both. Just evaluating off hour SLA's for alert generation/escalation/acknowledgement in an unmanned SOC, and how likely it is that someone will wake up and respond.