Re: SIEM Analysis

Steve Grubb <[email protected]> Thu, 14 Oct 2010 11:30:36 -0400
Newsgroups gmane.comp.security.ids.prelude.user
Organization Red Hat
Message-ID <[email protected]>
On Thursday, October 14, 2010 11:10:42 am Schubert, Aaron wrote:
> So far I have come up with these classification I want to pay attention to
> on a daily basis:
> 
> Exploit (from Snort)
> Unauthorized admin session attempt (from logs)
> Possible worm like activity (from correlator)
> 
> As far as analysis is concerned, what else would be good to filter/look for
> on a daily basis?

failed login attempts
applications that segfaulted
MAC system status changes

-Steve
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-technologies.com/mailman/listinfo/prelude-user