SIEM is not enough, widening SOC visibility with open source tools

SIEM is not enough, widening SOC visibility with open source tools

For a SOC (Security Operations Center) it is vital to continuously be informed about the events of the monitored network on a centralized platform. The SIEM (Security Information and Event Management) system performs this task. It harvests the information from various log sources and – in accordance with the settings – generates security events.

read more
NETWORK THREAT HUNTING WITH NETFLOW

NETWORK THREAT HUNTING WITH NETFLOW

Threat hunting is a good old process in the field of Cybersecurity. It covers human-driven analytics and searching through datasets (networks, endpoints, security solutions, etc.), in order to detect malicious activities, which could’ve evaded detection by existing IDPS or other automated detections.

read more

Pin It on Pinterest