SlideShare a Scribd company logo
EventLog Analyzer
Your complete security arsenal
Nitin Devanand
• Need for a SIEM solution
• EventLog Analyzer – quick overview
• Security attacks - use cases
-Brute force
-Stopping the rise of ransomware
-SQL injection
-Insider threat
-Monitoring privileged user activities
-Securing physical ,virtual and cloud environment
-Compliance
• Q & A
Agenda
Decrypting the security mystery with SIEM (Part 1)  ​
Collect data
from log
sources
Correlate
events
Alert IT about
security
incidents
Generate IT
security and
compliance reports
Archive logs for
forensic
analysis
Decrypting the security mystery with SIEM (Part 1)  ​
Sealing security
loopholes
• To protect from security attacks, it is essential for a company to
deploy various security solutions such as vulnerability scanners,
endpoint security protection tools, perimeter security devices and so
forth.
• This leaves security administrators overwhelmed with the number of
security alerts they get each day.
• Problem faced - lack of contextual understanding of security
information required to distinguish an actual threat from the false
positives.
Decrypting the security mystery with SIEM (Part 1)  ​
Windows
Unix and
Linux
Applications
Network
devices
Predefined
alert criteria
Alertin
g
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Decrypting the security mystery with SIEM (Part 1)  ​
Detecting insider attacks
Dealing insider attacks
More than 40% of attacks are from malicious insiders
in any organization. Therefore, every organization
must keep the same level of security policies for
insiders too.
• Insider threat detection
• Forensic analysis of scope of foot print of the
former employee
Source-http://resources.infosecinstitute.com/top-6-seim-use-cases/#gref
User session monitoring
Provides a complete user audit trial
from log on to log off
Answers who did what, when, and
from where
Reconstruct any network incident
with the help of the user activity
timeline.
Securing physical, virtual and cloud environments
• Apart from data security, there are numerous challenges like
network forensics, troubleshooting, fault monitoring, and
compliance.
• To overcome these challenges, IT security professionals need to
monitor and analyze the log data generated by their cloud
infrastructure.
Results of compliance fail..
Banks suddenly
asks its 3.2
million users to
change their
debit cards
2.6 million card
data is onVisa
and MasterCard
and 600k is on
RuPay platform
The data theft
happened
because of
malware
introduction on
the PoS
supplied by
Hitachi
Payment
Systems
Integrated compliance management
• Out of the box compliance reports for PCI
DSS, FISMA, GLBA, HIPPA, ISO 27001, and
more
• Compliance reports for both Windows event
logs and Linux/Unix syslogs
• Generate compliance reports from a
centralized location
• Get compliance reports in multiple formats:
HTML, PDF, or CSV
• Schedule compliance reports to run
periodically, and get emailed to multiple
administrators
Questions?
Sources :
http://www.hackmageddon.com/
http://www.zdnet.com/article/the-top-security-threats-of-
2016/
Thank you!
eventlog-support@manageengine.com
nick@manageengine.com

More Related Content

What's hot (19)

PDF
UNIFIED MESSAGE ARCHIVING – WHY IT IS IMPORTANT
Micro Focus
 
PPTX
User activity monitoring with SysKit
SysKit Ltd
 
PPTX
Modern Data Security for the Enterprises – SQL Server & Azure SQL Database
WinWire Technologies Inc
 
PDF
Modernize Your Infrastructure and Apps with Microsoft Azure
WinWire Technologies Inc
 
PPTX
Discover365 Integration Presentation
James Garrett
 
PDF
CSF18 Azure Information Protection - Albert Hoitingh
NCCOMMS
 
PDF
Nicolas destor pres_f5agility2018
Nicolas Destor
 
PPTX
Office Track: SharePoint Apps for the IT Pro - Thomas Vochten
ITProceed
 
PPTX
Interoute Intelligent Monitoring
Onomi
 
PDF
[WSO2Con EU 2017] WSO2 Unleashed: Full Stack Automation, Pitfalls and Solutions
WSO2
 
PPTX
CIS bench marks for public clouds
Nagesh Ramamoorthy
 
PDF
APIdays Paris 2019 - RASP for APIs and Microservices by Jean-Baptiste Aviat, ...
apidays
 
PDF
Security and Compliance
run_frictionless
 
PPTX
AppGate: Achieving Compliance in the Cloud
Cryptzone
 
PDF
Information Security Whitepaper
run_frictionless
 
PDF
Streamline RJS Document Management with AutoMate
HelpSystems
 
PPTX
Navigator - Your Cloud Management Platform
FNTS
 
PDF
Office 365 cloud principles
Motty Ben Atia
 
PDF
Building Event Driven Systems
WSO2
 
UNIFIED MESSAGE ARCHIVING – WHY IT IS IMPORTANT
Micro Focus
 
User activity monitoring with SysKit
SysKit Ltd
 
Modern Data Security for the Enterprises – SQL Server & Azure SQL Database
WinWire Technologies Inc
 
Modernize Your Infrastructure and Apps with Microsoft Azure
WinWire Technologies Inc
 
Discover365 Integration Presentation
James Garrett
 
CSF18 Azure Information Protection - Albert Hoitingh
NCCOMMS
 
Nicolas destor pres_f5agility2018
Nicolas Destor
 
Office Track: SharePoint Apps for the IT Pro - Thomas Vochten
ITProceed
 
Interoute Intelligent Monitoring
Onomi
 
[WSO2Con EU 2017] WSO2 Unleashed: Full Stack Automation, Pitfalls and Solutions
WSO2
 
CIS bench marks for public clouds
Nagesh Ramamoorthy
 
APIdays Paris 2019 - RASP for APIs and Microservices by Jean-Baptiste Aviat, ...
apidays
 
Security and Compliance
run_frictionless
 
AppGate: Achieving Compliance in the Cloud
Cryptzone
 
Information Security Whitepaper
run_frictionless
 
Streamline RJS Document Management with AutoMate
HelpSystems
 
Navigator - Your Cloud Management Platform
FNTS
 
Office 365 cloud principles
Motty Ben Atia
 
Building Event Driven Systems
WSO2
 

Viewers also liked (17)

PPTX
Decrypting the security mystery with SIEM (Part 2) ​
Zoho Corporation
 
PPTX
Active Directory security and compliance: Comprehensive reporting for key sec...
Zoho Corporation
 
PPTX
3Com PC3C589C
savomir
 
PPTX
Eje 3 expandir la eep y adaptar ecológica el suelo urbano
Adda Vargas
 
ODP
Typusとadministrateを比較してみよう
baban ba-n
 
PPTX
MOPAN 2015-16 Assessments
MOPANOnline
 
PPT
Agamaimankepadakitab kitaballah-
jidsink
 
PPTX
Apresentação mecânica do solo
gelcine Angela
 
PPTX
Alimentação e nutrição
Luciana Foerstnow
 
PPTX
Impact of OER on Cost and Quality of Course Materials in Postgraduate Distanc...
Open Education Global (OEGlobal)
 
PPTX
Designing digitally-enhanced curricula
Jisc
 
PDF
[CASE STUDY] 378% ROI On Your Sales Funnel Using Facebook Ads
William Marco Locañas
 
PPT
La Poesia Trobadoresca
Sílvia Montals
 
PPTX
Windows 7 Security Enhancements
Presentologics
 
PDF
Windows 7 Security--Windows 7 password reset
Passreset
 
PDF
1200+ sighs of relief for the IT department at City of Grand Rapids - ADSelfS...
Zoho Corporation
 
PDF
Effective User Life Cycle Management in Active Directory
Zoho Corporation
 
Decrypting the security mystery with SIEM (Part 2) ​
Zoho Corporation
 
Active Directory security and compliance: Comprehensive reporting for key sec...
Zoho Corporation
 
3Com PC3C589C
savomir
 
Eje 3 expandir la eep y adaptar ecológica el suelo urbano
Adda Vargas
 
Typusとadministrateを比較してみよう
baban ba-n
 
MOPAN 2015-16 Assessments
MOPANOnline
 
Agamaimankepadakitab kitaballah-
jidsink
 
Apresentação mecânica do solo
gelcine Angela
 
Alimentação e nutrição
Luciana Foerstnow
 
Impact of OER on Cost and Quality of Course Materials in Postgraduate Distanc...
Open Education Global (OEGlobal)
 
Designing digitally-enhanced curricula
Jisc
 
[CASE STUDY] 378% ROI On Your Sales Funnel Using Facebook Ads
William Marco Locañas
 
La Poesia Trobadoresca
Sílvia Montals
 
Windows 7 Security Enhancements
Presentologics
 
Windows 7 Security--Windows 7 password reset
Passreset
 
1200+ sighs of relief for the IT department at City of Grand Rapids - ADSelfS...
Zoho Corporation
 
Effective User Life Cycle Management in Active Directory
Zoho Corporation
 
Ad

Similar to Decrypting the security mystery with SIEM (Part 1) ​ (20)

PDF
Wc4
Said Wali
 
PPTX
encase enterprise
Damir Delija
 
PPTX
IBM i Security SIEM Integration
Precisely
 
PDF
Big security for big data
Giuliano Tavaroli
 
PPTX
SIEM - Activating Defense through Response by Ankur Vats
OWASP Delhi
 
PPTX
EventLog Analyzer - Product overview
ManageEngine EventLog Analyzer
 
PDF
Preventing The Next Data Breach Through Log Management
Novell
 
PPT
What Every Organization Should Log And Monitor
Anton Chuvakin
 
PPTX
Računalna forenzika i automatizirani odgovor na mrežne incidente
Damir Delija
 
PPTX
SIEM - Your Complete IT Security Arsenal
ManageEngine EventLog Analyzer
 
PPTX
IBM i Security: Identifying the Events That Matter Most
Precisely
 
PPT
Logs for Information Assurance and Forensics @ USMA
Anton Chuvakin
 
PPTX
The Data Defenders: SIEM and Log Management in Cybersecurity
wininlifeacademy5
 
PDF
UNIT -III SIEM aur baato kaise hai aap log.pdf
hefagi6193
 
PDF
Leveraging Log Management to provide business value
Enterprise Technology Management (ETM)
 
PDF
A Pragmatic Approach to SIEM: Buy for Compliance, Use for Security
Tripwire
 
PDF
Changing the Security Monitoring Status Quo
EMC
 
DOC
Audit logs for Security and Compliance
Anton Chuvakin
 
PDF
Maceo Wattley Contributor Infosec
Dr. Maceo D. Wattley
 
PPTX
IT Security: Eliminating threats with effective network & log analysis
ManageEngine, Zoho Corporation
 
encase enterprise
Damir Delija
 
IBM i Security SIEM Integration
Precisely
 
Big security for big data
Giuliano Tavaroli
 
SIEM - Activating Defense through Response by Ankur Vats
OWASP Delhi
 
EventLog Analyzer - Product overview
ManageEngine EventLog Analyzer
 
Preventing The Next Data Breach Through Log Management
Novell
 
What Every Organization Should Log And Monitor
Anton Chuvakin
 
Računalna forenzika i automatizirani odgovor na mrežne incidente
Damir Delija
 
SIEM - Your Complete IT Security Arsenal
ManageEngine EventLog Analyzer
 
IBM i Security: Identifying the Events That Matter Most
Precisely
 
Logs for Information Assurance and Forensics @ USMA
Anton Chuvakin
 
The Data Defenders: SIEM and Log Management in Cybersecurity
wininlifeacademy5
 
UNIT -III SIEM aur baato kaise hai aap log.pdf
hefagi6193
 
Leveraging Log Management to provide business value
Enterprise Technology Management (ETM)
 
A Pragmatic Approach to SIEM: Buy for Compliance, Use for Security
Tripwire
 
Changing the Security Monitoring Status Quo
EMC
 
Audit logs for Security and Compliance
Anton Chuvakin
 
Maceo Wattley Contributor Infosec
Dr. Maceo D. Wattley
 
IT Security: Eliminating threats with effective network & log analysis
ManageEngine, Zoho Corporation
 
Ad

More from Zoho Corporation (20)

PPTX
The Future of integrated Identity and Access Management
Zoho Corporation
 
PPTX
One portal for all your login needs - ADSelfService Plus Single sign-on.
Zoho Corporation
 
PDF
Using indicators to deal with security attacks
Zoho Corporation
 
PPTX
Ensuring security and consistency of users' self-service actions in Active Di...
Zoho Corporation
 
PPTX
Empowering ServiceNow help desk for Active Directory management
Zoho Corporation
 
PPTX
WannaCry Ransomware
Zoho Corporation
 
PPTX
Controlling Delegation of Windows Servers and Active Directory
Zoho Corporation
 
PPTX
Microsoft, Active Directory, Security Management Tools and Where ManageEngine...
Zoho Corporation
 
PDF
ALIGN Technology timely alerts its employees of their password expiry using A...
Zoho Corporation
 
PDF
Unisource Worldwide Inc - An ADSelfservice Plus Case study
Zoho Corporation
 
PDF
Case study-self-password-management-camh
Zoho Corporation
 
PDF
Case study-administrative-office-schwarzwald-baar-kreis
Zoho Corporation
 
PDF
Skorpion Zinc's loves 'Password Self-Service' & 'Profile Update' features of ...
Zoho Corporation
 
PDF
Hampshire Collegiate Schools uses ManageEngine ADSelfService Plus password ma...
Zoho Corporation
 
PDF
Indispensable tool to help with Password Reset Issues
Zoho Corporation
 
PDF
ADManager Plus Makes Admissions A CakeWalk For College Montmorency
Zoho Corporation
 
PDF
Helpdesk delegation
Zoho Corporation
 
PDF
How ADManager Plus helped a local govt. wipe out stale accounts from its AD
Zoho Corporation
 
PDF
HomeBanc trusts ManageEngine ADSelfService Plus to resolve its Password expir...
Zoho Corporation
 
PDF
Password Reset Issues Effectively Solved
Zoho Corporation
 
The Future of integrated Identity and Access Management
Zoho Corporation
 
One portal for all your login needs - ADSelfService Plus Single sign-on.
Zoho Corporation
 
Using indicators to deal with security attacks
Zoho Corporation
 
Ensuring security and consistency of users' self-service actions in Active Di...
Zoho Corporation
 
Empowering ServiceNow help desk for Active Directory management
Zoho Corporation
 
WannaCry Ransomware
Zoho Corporation
 
Controlling Delegation of Windows Servers and Active Directory
Zoho Corporation
 
Microsoft, Active Directory, Security Management Tools and Where ManageEngine...
Zoho Corporation
 
ALIGN Technology timely alerts its employees of their password expiry using A...
Zoho Corporation
 
Unisource Worldwide Inc - An ADSelfservice Plus Case study
Zoho Corporation
 
Case study-self-password-management-camh
Zoho Corporation
 
Case study-administrative-office-schwarzwald-baar-kreis
Zoho Corporation
 
Skorpion Zinc's loves 'Password Self-Service' & 'Profile Update' features of ...
Zoho Corporation
 
Hampshire Collegiate Schools uses ManageEngine ADSelfService Plus password ma...
Zoho Corporation
 
Indispensable tool to help with Password Reset Issues
Zoho Corporation
 
ADManager Plus Makes Admissions A CakeWalk For College Montmorency
Zoho Corporation
 
Helpdesk delegation
Zoho Corporation
 
How ADManager Plus helped a local govt. wipe out stale accounts from its AD
Zoho Corporation
 
HomeBanc trusts ManageEngine ADSelfService Plus to resolve its Password expir...
Zoho Corporation
 
Password Reset Issues Effectively Solved
Zoho Corporation
 

Recently uploaded (20)

PDF
Lecture A - AI Workflows for Banking.pdf
Dr. LAM Yat-fai (林日辉)
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PDF
RAT Builders - How to Catch Them All [DeepSec 2024]
malmoeb
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PDF
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
PDF
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
PPTX
Earn Agentblazer Status with Slack Community Patna.pptx
SanjeetMishra29
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PPTX
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PDF
NewMind AI Weekly Chronicles – July’25, Week III
NewMind AI
 
PPTX
PCU Keynote at IEEE World Congress on Services 250710.pptx
Ramesh Jain
 
PDF
Basics of Electronics for IOT(actuators ,microcontroller etc..)
arnavmanesh
 
PDF
Build with AI and GDG Cloud Bydgoszcz- ADK .pdf
jaroslawgajewski1
 
PPTX
Machine Learning Benefits Across Industries
SynapseIndia
 
PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PDF
Integrating IIoT with SCADA in Oil & Gas A Technical Perspective.pdf
Rejig Digital
 
PDF
Per Axbom: The spectacular lies of maps
Nexer Digital
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
Lecture A - AI Workflows for Banking.pdf
Dr. LAM Yat-fai (林日辉)
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
RAT Builders - How to Catch Them All [DeepSec 2024]
malmoeb
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
Earn Agentblazer Status with Slack Community Patna.pptx
SanjeetMishra29
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
NewMind AI Weekly Chronicles – July’25, Week III
NewMind AI
 
PCU Keynote at IEEE World Congress on Services 250710.pptx
Ramesh Jain
 
Basics of Electronics for IOT(actuators ,microcontroller etc..)
arnavmanesh
 
Build with AI and GDG Cloud Bydgoszcz- ADK .pdf
jaroslawgajewski1
 
Machine Learning Benefits Across Industries
SynapseIndia
 
The Future of Artificial Intelligence (AI)
Mukul
 
Integrating IIoT with SCADA in Oil & Gas A Technical Perspective.pdf
Rejig Digital
 
Per Axbom: The spectacular lies of maps
Nexer Digital
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 

Decrypting the security mystery with SIEM (Part 1) ​