#siem

6 posts · Last used 3d

Back to Timeline
Vern McCandlish @malanalysis@infosec.exchange · 3d ago
Important reminder for SIEM janitors to frequently check their SIEM for common password field structures to find occurrences where stuff that should not be getting logged to the SIEM is getting logged. I was reminded when I was telling a story about finding credentials and payment information in an applog that was also helpfully being indexed in the SIEM. I am recommending free form regex searches of the raw entry, not just looking for named fields. #SIEM #Cybersecurity #Incidentresponse
0
0
0
Graylog @Graylog@infosec.exchange · Jul 16, 2026
Once attackers gain initial access, lateral movement is how they expand their reach without tripping alarms. They mimic legitimate admin behavior to pivot toward domain controllers, sensitive file shares, and databases. Our latest blog covers the techniques attackers use and the strategies (segmentation, least privilege, MFA, Zero Trust) that help security teams detect and contain it early. https://graylog.org/post/lateral-movement-security-risk-and-mitigation-strategies/ #CyberSecurity #SIEM #InfoSec #ThreatDetection
0
0
0
Graylog @Graylog@infosec.exchange · Jul 14, 2026
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
1
0
0
Graylog @Graylog@infosec.exchange · Jul 09, 2026
Email threats aren't slowing down, and email security tools like Mimecast generate a lot of valuable telemetry: blocked threats, quarantined messages, impersonation attempts, DLP triggers. The problem is that data often stays siloed from the rest of your security stack. With Graylog 6.2.3+, you can pull Mimecast logs directly via API v2.0 and get immediate visibility through pre-built Illuminate Dashboards, correlated alongside endpoint, firewall, and identity data. New blog covers the integration prerequisites, input configuration steps, supported log types, and what analysts gain from centralized investigation instead of bouncing between tools. Full post: https://graylog.org/post/unlock-email-threat-visibility-with-mimecast-and-graylog/ #Cybersecurity #EmailSecurity #SIEM #InfoSec #GraylogLife
0
1
0
Graylog @Graylog@infosec.exchange · Jul 02, 2026
AWS WAF sees every request hitting your ALB, CloudFront, API Gateway, or AppSync, and makes a block/allow/count/CAPTCHA/challenge decision on each one. The question is whether your security team can actually see and search those decisions. The AWS WAF Content Pack for Graylog parses the WAF JSON payload, normalizes the fields, and maps enforcement actions to the Graylog Information Model so they flow straight into detection and investigation workflows. Dashboard included. Details: https://graylog.org/post/aws-waf-data-in-graylog/ #SIEM #AWS #CloudSecurity #Graylog
0
0
0

You've seen all posts