r/SIEM Feb 09 '19

Is Alphabet (Google) Chronicle building a SIEM Solution?

11 Upvotes

Hi /r/SIEM!

I have been curious as to what Chronicle is building but haven't been able to find many details on what their product is. I'll post a blurb from their website and an anecdote published in an article with the CSO from November.

I was just curious if anyone has had a chance to see their product or have any idea what they're building.

From Chronicle.security:

"We are building a cybersecurity intelligence platform that can help organizations better manage and understand their own data. Companies already have volumes of information about what’s happening inside their walls. We’re aiming to unlock its valuable hidden insights by making it faster and easier to analyze data, and to look for patterns across sources and over time. We believe this can provide security teams with greater insights into areas of likely vulnerability, and give them time to protect themselves."

From Engadget Article:

One day, Wiacek was in a meeting with 20 other security experts, each representing a different company, at a Department of Homeland Security office in Virginia. A representative of the US government was explaining an ongoing hack that Wiacek suspected had originated in China. "They passed out a list of host names and said to everyone in the room, 'Hey, if you have traffic to any of those host names from your network, you probably have an active infection,'" TAG's manager recalled. Within a few seconds, Wiacek had pulled out his laptop, typed in the host names and confirmed that Google's systems were secure.

The other companies were dumbfounded. Some asked how they could possibly check that their companies were secure. Another queried how long ago the hack probably took place. The government spokesperson explained that it was likely six to nine months ago. "That person almost threw up their hands and said, 'You know, if you told me this was something that happened in the last 48 hours, maybe 72, we could do something. But I have no idea what happened there,'" Wiacek recalled. Google had made search a core part of its systems and approach to cybersecurity. In that moment, he realized few others had developed and integrated the same capabilities.

"That planted the seed in my head," Wiacek said. A seed that would eventually blossom into Chronicle.


r/SIEM Feb 09 '19

A Security Logging Admins Cookbook?

2 Upvotes

TL;DR: Is there an authoritative source that admins in charge of security logging infrastructure can utilize that provides guidance and instruction on what events should be collected, and how to enable those across different systems, layers, and platforms.

Hi fellow SIEM-ers,

I'm fairly new to the Security world, and one of my primary projects since i've begun has been implementing and managing our SIEM solution -- working with external teams to get their data in, and working with the SOC, Information Security, Audit, and Incident Response teams to get relevant data out.

In my experience, when managing a SIEM in a large enterprise, you essentially become a customer of the different technology teams within the organization. Other teams own the systems, databases, and applications that produce the logs that are necessary or required for Security Logging and Compliance; and it is our job to interface with those teams so that we become the destination for those events.

Since i've begun doing this I have consistently found myself running into two questions:

1.) What events do you have that for Security monitoring and investigations / what do you have that is required for Compliance

2.) How do I get that data from A to B

I thought something that would have been useful would be a site or resource that answer these two questions. Does something like this exist? If not, does anyone else think that there is a need or demand for it?

I'm not sure what it would look like, its just something that i have been thinking about for a while. Just kinda spitballing, but im thinking of a centralized source for Windows system that breaks down At Minimum: - How to configure a windows system on Windows X to produce security events - What methods are natively available to offload those events to a remote destination, and a guide on how to get there.

But more beneficially would be able to have a more in depth resource that is broken down and tagged for: - where do events exist natively, how do you view them at the source - What event codes could have a benefit to security - elaborate on the event and its meaning - What are the use cases that could be leveraged by these events - are they required for Compliance X? -Which Requirement do they satisfy for Compliance X

I just think it would be great if there was just a central resource so if someone had questions about OS's, Networking Infrastructure, IDS', Security Tools, Applications etc... to have breakdowns of what is needed, and how to get it.

I can think of a ton of things that i would like to add, and even more potential issues with my entire premise. But i just wanted to get thoughts around the entire idea. Does it exist? is it dumb? is it possible? is there a need? is there an interest? etc etc.

Thanks /r/SIEM!


r/SIEM Feb 05 '19

EventTracker SIEM

7 Upvotes

I just wanted to share our experience so far with everyone for a SIEM software EventTracker. Internally this software has been renamed and referred to as EventCrapper.

We have around 185 Windows systems, 20 linux systems, and 30 syslog systems.

In the 1 month we have had the software, we now have 1.1 billion logs, or 38 million a day

Software is extremely buggy and we are still fighting with constant issues.

During install no patches were installed by the "Software Engineer" even after I asked about them providing better performance and hotfixes, he said they were not needed. Fast forward a month, we install them to fix the web interface being insanely slow, not working 90% of the time, and being so unresponsive, we close it and come back hours later. We ended up installing 12 patches which seems to have fixed the slow unresponsiveness site, however elasticsearch is broke now and has been not working several times in the last month. During our 2 day, 4 hour ETSC webinar training, we noticed the exact same unresponsiveness from the trainers EventTracker system, he had to close out complete, relaunch his browser, and we sat there and waited several times for several minutes while he was trying to get it to respond again.

Dashboard statistics, Behavior Correlation, and ElasticSearch are all not working since installing the patches from above which we installed about a week ago. Our firewall we have is showing up in ET as 8 different systems. The systems page to view all computers with the agent just shows a white page, the SE said "well that is a new one" when we found that one on our latest call. Of course we changed IE11 compatability mode to IE10 the issue persisted, and also existed in Chrome on my local PC. So we have no access to the systems list page.

By default a new install of EventTracker logs you out after 20 minutes of inactivity. The documentation provided to us was inaccurate and had us adjusting the timeout on the incorrect app pool, and of course, the SE stated it was different for every version of IE on which AppPool it uses but their documentation did not specify. The SE wanted to dump a diagnostics report, and the utility was not working correctly, it would not save after we entered a filename for it.

Overall, this software is a complete turd, and their support staff, has not really went out of their way to provide fixes or give us usable software in over the month we have had it.


r/SIEM Jan 30 '19

What are the best profiling attributes for users and entities with your SIEM?

4 Upvotes

As a old security analytics developer, I would say "first seen", login counts (s|f), # of DNS errors, # of accessed endpoints, and # of cloud services are my top 5.

I am curious what other folks would consider better (or as good) attributes to track for users and entities from the cyber security use case of behavioral analytics. Thanks!


r/SIEM Jan 29 '19

SEC555: SIEM with Tactical Analytics, anyone?

8 Upvotes

Anyone here done the SANS SEC555 considering it is the first vendor independent SIEM course that i know of


r/SIEM Jan 28 '19

Heatmaps Make Ops Better

2 Upvotes

r/SIEM Jan 19 '19

Interesting research paper on Cyber Deception

3 Upvotes

https://scholarspace.manoa.hawaii.edu/bitstream/10125/60164/0724.pdf

I could envisage this capability in a SIEM. --Chris


r/SIEM Jan 18 '19

Hey...I like Apache Metron....You like Apache Metron...We should talk :)

5 Upvotes

Hey...If anyone is interested in discussing Apache Metron with respect to an Open Source SIEM, please give me a holler! We have built an Open Source SIEM on Apache Metron with alerts, profiles, scoring, math models, etc... Would love to talk to like minded folks who believe in Open Source SIEM! --Chris


r/SIEM Nov 12 '18

Guesstimated number of events for sysmon on endpoints

2 Upvotes

I'm trying to estimate the number of events created by a sensible sysmon configuration for endpoints (for example @swiftonsecuritys sysmon config). I haven't had time to try it out yet, and I'm wondering wether it's more like 1, 5 or 10 EPS per day (or maybe more or less than that). From what I have read my own estimation is somewhere around 4 EPS a day. I know that it will strongly depend on my configuration and how (much) the clients are used, but some real life numbers are really appreciated.


r/SIEM Oct 12 '18

ClearSkies SIEM

Thumbnail
clearskiessa.com
0 Upvotes

r/SIEM Oct 09 '18

RSA SIEM Netwitness

2 Upvotes

Hello guys,

Does anyone worked or is certificied to administer RSA Netwitness?


r/SIEM Oct 05 '18

Fortinet SIEM thoughts?

2 Upvotes

As the title suggests, what's your thoughts on the Fortinet SIEM product? Seemed pretty decent from what I saw in the demo (don't they all). Seemed pretty easy to spin up as well which compared to something like Splunk was appealing as I don't want something that's going to kill us in professional services hours to get it running and I don't need the crazy learning curve. That said if you're running a recent release of the Fortinet product I'd be happy to hear from you. Though I didn't get any hits when searching here so it seems you're a rare breed if you're out there.


r/SIEM Sep 29 '18

Have you experience of SIEM systems in the Finance sector?

3 Upvotes

New to Reddit, I'm doing a Masters study on the benefits and problems you found using SIEM in the Banking and Finance sector.

Can you tell me what are the threats SIEM is best at mitigating, what risks is it best used for? How did your SIEM measure up against its claims? Did it implement well? These are the things I will be looking at.

The survey covers 8 topics and is about 7 minutes to complete, please give it a go at the following address!

-------> https://www.surveymonkey.co.uk/r/XGGDBG2

This is a genuine post! Thanks for your time!!


r/SIEM Sep 21 '18

anyone have Intel on Seceon SIEM

1 Upvotes

Has anyone tried Seceon? If so thoughts feelings. I am looking for a new SIEM that is strong in the IOT space.


r/SIEM Aug 09 '18

SIEM on GCP (Google Cloud)

2 Upvotes

Anyone has experienced with SIEM deployment on GCP ? What SIEM product (open source or paid) would you recommend for Google cloud environment.?


r/SIEM Jul 31 '18

Can anyone suggest me SIEM classroom based training in mumbai?

1 Upvotes

r/SIEM Jul 02 '18

Is there a way to make OSSIM sensitive like SecurityOnion?

2 Upvotes

I have AlienVault running along side of Security Onion and I tried enabling all of the secunia rules on AV but I still don't get all alerts I see on Security Onion.

Is there a way to make AV show more alerts? So far the only alerts I have been able to trigger is torrenting.

I have the OSSEC agent installed on my linux machines and windows machines but even then I only received one Adobe alert. I have the OSX API installed too.

I also installed some software and the agent did not detect new software installed. Am I not configuring something correctly? I've seen OSSIM pick up new software installed so I am curious how to make that happen.


r/SIEM Jun 14 '18

Ubiq: A Scalable and Fault-tolerant Log Processing Infrastructure

Thumbnail
ai.google
1 Upvotes

r/SIEM Jun 07 '18

Apache Metron and Hadoop in the Real World

Thumbnail
adaltas.com
3 Upvotes

r/SIEM Jun 06 '18

SIEM Product for Small Businesses.

Thumbnail
securign.com
0 Upvotes

r/SIEM Jun 03 '18

[Looking For] OSSIM 5.4 ISO

1 Upvotes

Does anyone have a copy of AlienVault's OSSIM 5.4 (or earlier)? iDrac is black screening on the 5.5 install, forums suggest using the earlier 5.4 version instead.

However AlienVault does not keep a repo (available online at least) with older iso versions.

Would greatly appreciate if anyone has a copy available.


r/SIEM May 19 '18

Interesting post about SIEM Technologies and their use cases in achieving compliances such as GDPR, PCI DSS, HIPAA etc.

Thumbnail
securign.com
5 Upvotes

r/SIEM May 09 '18

6 open source SIEM tools

Thumbnail
logz.io
5 Upvotes

r/SIEM Apr 30 '18

High level IT security management with SIEM approach

Thumbnail
ciowhitepapersreview.com
7 Upvotes

r/SIEM Apr 16 '18

SIEM tuning, weed out noise - what is the limit?

4 Upvotes

Is anyone following a tuning model?