SIEM Analysis
"Schubert, Aaron" <[email protected]> Thu, 14 Oct 2010 10:10:42 -0500
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <950F909D7BFFA041A0714E004BE2E96528BE6AE222@EXCHVS5A.mx.state.mo.us> |
So far I have come up with these classification I want to pay attention to on a daily basis: Exploit (from Snort) Unauthorized admin session attempt (from logs) Possible worm like activity (from correlator) As far as analysis is concerned, what else would be good to filter/look for on a daily basis? _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-user