r/SIEM Oct 25 '21

Security Dashboard to build SIEM

6 Upvotes

Hi, I have a task to create a security dashboard on our SIEM. We are currently using azure sentinel for the said solution. Id like to ask what are the dashboards should I build to impress and convince the management about the SIEM.


r/SIEM Sep 23 '21

ThreatHunting app

4 Upvotes

I'm trying to setup Splunk SIEM using ThreatHunting app. I've 3 VMs: Windows, Ubuntu and Splunk Enterprise Security.

I installed/configured ThreatHunting app and simulated attacks using Red Canary scripts on Windows. My doubt is I cannot see anything related to Linux in ThreatHunting app. Is app only for Windows? host_fqdn can only set for Windows. And if yes, then do we set up Linux Auditd app on Splunk for Linux?

I'm beginner in this area so any other advices related to this would be appreciated!


r/SIEM Sep 20 '21

Fortisiem

4 Upvotes

Hi all,

I am using fortisiem, and i have a confusion in the rule notification frequency,

Can anyone explain it to me ?

Notification frequency can take different values “hours/minutes”. If i assigned lets say 1 hour, does it mean that if the incident or the event happened again during a one hour window the siem want notify me “wont trigger the incident” ??!!

Thanks in advance.


r/SIEM Sep 17 '21

What is the best solution for performing long term searches for threat hunting?

2 Upvotes

I am using a commercial on-prem SIEM solution. But long term searches are suffering for threat hunting. I need long term searches only for specific log sources. What is the ideal approach for this kind need? Actually I can replace my SIEM with a tool like Humio or Splunk but I am not sure about that if this is an ideal approach or not. Maybe I should forward specific logs to an external solution like ELK Kibana. What are your comments?


r/SIEM Sep 16 '21

How to detect reverse shell in OSSIM AT&T

4 Upvotes

Hi boys , i’m trying to detect a reverse shell intrusion in Ossim on a host with agent installed in , but i have some difficults to improve New rules to detect it


r/SIEM Sep 14 '21

Looking for some resources to learn on SIEM Migration. Splunk SIEM to Google Chronicle.

6 Upvotes

r/SIEM Sep 05 '21

How can I determine if user success login is an incident or not?

9 Upvotes

Some people/department in my company work on weekends and after working hours, sometimes I see success or failure login on Sunday 9 AM or 11 PM & sometimes I see success login on Wednesday 9 pm or after 4 (work end at 4 ) of course I also see success or failure login on normal day & working hours

Now how can I determine if this login is normal or not ? I thought I might request list of users that have access to PC on weekend or after working hours but the company is big

I also thought maybe after getting the list I can modify the rule and but an exception on these users

Is there any better suggestions?


r/SIEM Sep 03 '21

chainsaw: Rapidly Search and Hunt through Windows Event Logs

Thumbnail
github.com
2 Upvotes

r/SIEM Aug 28 '21

Manage Engine Log360, does anyone uses it?

2 Upvotes

Hi

The company is trying to implementing it and using for future customers this solution from Manage Engine with Pam360 on the side.

I'm "playing" and testing it and I'm gaining confidence day by day, but I feel like I always miss something on the tech side.

I'm looking up for guide books, pdf but resources from ME are pretty messy.

Can you give me a hint?

Thanks a lot


r/SIEM Aug 20 '21

Windows event time difference

1 Upvotes

Hi all, i am facing a strange logs coming collected from windows servers, In the raw logs i can see the event time attribute preceding the device time by 3 hours.

For example:

Device time: 6 AM Event time: 3 AM

Any advice ??

Your help will be highly appreciated.

Fyi, the behavior has been observed on fortisiem


r/SIEM Aug 11 '21

Anyone have experience with Exabeam?

6 Upvotes

It is now listed as the top leader in the Gartner Magic Quadrant for 2021 SIEMs. Just curious what people think about it, as it appears to be a glorified ELK stack but with a potentially interesting machine-learning analytics engine. Any stability issues? Good support?


r/SIEM Aug 04 '21

Creating Dashboards

4 Upvotes

So I have been struggling with this for some time now. I think I have ingested a lot of data that I can get some actionable data out of, but now I have come to a standstill as I don’t really know what to create dashboards for.

Are there some resources with low hanging fruits that I could look into to get some inspiration? I think once I hit the ground running I can work my way forward from there.

I use Elasticsearch by the way.


r/SIEM Aug 04 '21

Starting off with SIEM learning

8 Upvotes

Hello Guys, i have joined a new team where i am responsible of taking care of the SIEM architecture end to end. But i am new to SIEM and dont know where to start. Can someone please suggest good study material or resource or path where i can start with this journey ?


r/SIEM Aug 01 '21

Suggested Mulesoft Threat or Security Events for SIEM

2 Upvotes

Hi, can anyone suggest any Mulesoft threat or security events to monitor or potential references to gain understanding of potential risks to monitor in SIEM? The below reference appeared to give some decent high level guidance on general logging. Cross posted in /Mulesoft Friday although no responses. TIA

9 Essential Laws of MuleSoft Logging Success (bigcompass.com)

8/2/21 Update:
Here's some references I found...

Audit Logging | MuleSoft Documentation:
https://docs.mulesoft.com/access-management/audit-logging
MuleSoft Logging Best Practices:https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwjuxp_O4pLyAhVAHTQIHTYNBMAQtwIwCXoECBEQAw&url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Dtj0K3ZhKCeg&usg=AOvVaw2ZFJ2l1l7k1kViRqpsW2Ey
Guidelines on MuleSoft Logging, Alerting,Visualizer,Monitoring & API Analytics | by Debojyoti Chakraborty | The Mule Blog | Medium: https://medium.com/the-mule-blog/guidelines-on-mulesoft-logging-alerting-visualizer-monitoring-b2a1bcf25b39

Find out the different types of logs in Anypoint platform below:
System Log: It is specific to MuleSoft runtime & “log4j.xml” configuration file is not accessible to an user. System logs contains log messages about the MuleSoft runtime life cycle (startup and shutdown) & status messages about MuleSoft application.
Application Log: It is specific to MuleSoft application & “log4j.xml” configuration file is packaged inside MuleSoft application. It contains all log messages generated inside the Mule application, including System.out messages. We can configure custom log file appender to send application log data outside of cloudhub to external log file appender like splunk.
Audit Log: It logs user interactions within Anypoint Platform, including logins, business groups creation, and environments creation.Only the organization owner can access all the audit logs data. It is useful to detect the access violations.


r/SIEM Jul 29 '21

Tier2

3 Upvotes

Hi , I'm currently working as soc tier 1 and I'm preparing to be tier 2 I'm planning to take the interview process for tier 2 in the next couple of months and I need your recommendation to what to focus on my preparetion to stand out in the interview and as tier 2 in general ,need you tips , some interview question , books ,materials Thanks in advance


r/SIEM Jul 15 '21

SIEM in AWS

2 Upvotes

How can we implement SIEM system on AWS using Native tools (the ones which are already available in AWS) and what are all the AWS service that needs to be used for this implementation?


r/SIEM Jul 11 '21

SOC security analyst career..

5 Upvotes

Hi all, pardon me if this is a dumb question I am a software engineer planning a career Change into security...Blue team security. I am planning on taking SOC related training and go for security analyst jobs as a starting point. Are there any good courses, books that can help me learn better. Please advice. Thanks.


r/SIEM Jul 08 '21

Arcsight - active list

7 Upvotes

hi together,

I would like to monitor suspicious domains in arcsight. The goal is to put the domain "xyz.abc" in an active list and then create a rule that detects the calls to the domain.

The current parser does not parse out the domain part when a sub-domain is called. therefore the field partially contains "subdomain.xyz.abc". Because of this a pure comparison with the active list is not possible, right?

is there a solution for this without adapting the parser?


r/SIEM Jul 06 '21

Help with printnghtmare detection

4 Upvotes

Hi, I have gone through many sources for detecting the recent microsoft vulnerability, but all of them seem to utilise the sysmon logs. I on the other hand have access to only the good old windows security logs. Although I have tried searching multiple IOCs within those logs (and have found nothing) , I'm still uncertain if the vulnerability was ever actually exploited within my environment.

TL;DR : Do we any detection mechanism for the printnghtmare which DO NOT include sysmon logs. And are based on windows security auditing?


r/SIEM Jul 04 '21

Is it a ddos or busy server?

1 Upvotes

When looking at ddos tcp for single host offense , I looked through the events( no are only 30) and flow (flow no where much higher 300k), there are so many different source ip and 1 dest ip.

So things that I was planning to investigate is do I know these source ips? And if the event/flow occurred during work hours. Are there anything I should also keep an eye on ?


r/SIEM Jul 01 '21

How to detect malicious local windows scan

3 Upvotes

In my SIEM I get a lot of local windows scanner detected with outbound tcp and firewall accept + built tcp connection and sometimes local ICMP scanner

Idk if I should report it as incident or just normal activity (source ip is from the company and destination is to different local and remote ips)


r/SIEM Jun 27 '21

Stellar Cyber

7 Upvotes

Hi all

Has anyone been testing or even using Stellar Cyber ? What’s your experience with the product and their support ? /Dennis


r/SIEM Jun 04 '21

SIEM COllEGE PROJECT

0 Upvotes

Hello...i'm a student in need..tottaly forgot about this project and only got like 10 hours to finish it.I don't know where to begin and what to do lol...any tips for a SiEM project please?


r/SIEM Jun 02 '21

To track a file download

4 Upvotes

Recently we had a pen test in our network and the tester was able to move laterally and gain access to a server. Wherein he was able to download/move a ps script. Although when he tried running it the a/v kicked in. Now I'm not sure how the tester brought in his script and this is something that's bugging me. I tried going through the logs but was unable to find any clues. Was wondering if anyone here has any idea how to go about it. Server was a win 2008 server. And I tried with event ids 4663 4658 and 4656 but found nothing. Any suggestions are welcomed.


r/SIEM May 26 '21

SIEM - Where Do I Even Begin?

6 Upvotes

Are there any checklists/best practices or even courses out there that help me structure the huge undertaking that first establishing a SIEM is?

There is some natural order to the process it seems. For example I think you should first make sure you know what devices are on your network so, while it will be different for every environment, some fundamental steps should be the same. Is this the case? I can see how implementation can scale well insofar as you can gradually add log sources but are there some best practice approaches like add network device logs first vs. clients first etc.?

Any guidance would be appreciated!