{"id":13292,"date":"2023-10-25T15:23:55","date_gmt":"2023-10-25T09:23:55","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13292"},"modified":"2023-10-25T15:23:55","modified_gmt":"2023-10-25T09:23:55","slug":"next-level-threat-hunting-shift-your-siem-from-reactive-to-proactive","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/next-level-threat-hunting-shift-your-siem-from-reactive-to-proactive\/","title":{"rendered":"NEXT-LEVEL THREAT HUNTING: SHIFT YOUR SIEM FROM REACTIVE TO PROACTIVE"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/cdn-jnkep.nitrocdn.com\/GTmurwhroBoLJVMAHNGccmBVEhSunPoF\/assets\/images\/optimized\/rev-25967c7\/graylog.org\/wp-content\/uploads\/2022\/07\/5f0348fe8b70ba60071c2dfc_5c41fdd63b33dd693189bff0_proactive20threat20hunting-e1695819642551.jpeg\" \/><\/p>\n<div>\n<p>Threat hunting is\u00a0<a href=\"https:\/\/graylog.org\/docs\/threat-intelligence-integration-from-source-to-secure\/\">proactively identifying and thwarting unusual network activity<\/a>\u00a0that could indicate an attempted security breach. It\u2019s a historically manual activity, making it time-intensive and arduous. It\u2019s no wonder, then, why most organizations don\u2019t have the time, budget, or resources to undertake it effectively\u2026if at all. That\u2019s why many organizations rely on\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Cyber_threat_hunting\">\u201creactive\u201d threat response solutions<\/a>, including firewalls, intrusion detection, and SIEM to alert analysts to an event after it occurs. Without the resources to commit to proactive threat hunting, reactive solutions are the next best option.<\/p>\n<p>But if threat hunting is on your to-do list this year, a little-discussed solution is the ability to turn a reactive threat response into a proactive one. Specifically, it\u2019s very possible and economical to\u00a0<strong>shift your SIEM from reactive to proactive to start leveling up your threat hunting capabilities.<\/strong><\/p>\n<p>The benefits of this shift can be significant. Proactive SIEM-supported threat identification can provide more context and improve threat response times. It also creates a proprietary understanding of your unique threats, which is more valuable and effective than relying solely on third-party threat intelligence. Additionally, it makes automating security rules more viable, especially to stakeholders concerned about impeding legitimate activity.<\/p>\n<p>Let\u2019s talk about the 5 steps to shift your SIEM from reactive to proactive.<\/p>\n<p><strong>1. Identify Your \u2018Area of Influence\u2019<\/strong><\/p>\n<p>Start by identifying where you want to focus first. Maybe it\u2019s a particular system, a highly targeted group, or an activity where you suspect your organization may be vulnerable to attack. This will help you tailor your scope to make the best use of available resources and will come in handy in later steps.<\/p>\n<p><strong>2. Set Up a Centralized Log Management System<\/strong><\/p>\n<p>A centralized log management system aggregates network log information so that all log data is in one place. Centralizing your log management feeds information to analysts more quickly and delivers a more holistic view of network activity. It also sets the stage for step 3.<\/p>\n<p><strong>3. Augment Log Data with Third-Party Intelligence<\/strong><\/p>\n<p>Third-party intelligence is any relevant supplemental data source that helps you accurately determine a threat. This is the moment when your area of influence comes back into play since knowing the scope of your inquiry allows you to choose relevant resources to support it.<\/p>\n<p>Third-party intelligence adds more context for faster analysis and accurate decision-making. It also increases your security team\u2019s internal \u2018learning curve\u2019 about what indicates a threat actor versus benign activity. There are several types of third-party data sources available. Learn more by downloading our\u00a0<a href=\"https:\/\/graylog.org\/docs\/expanding-security-log-enrichment-beyond-threat-intelligence\/\">white paper on security log enrichment<\/a>.<\/p>\n<p><strong>4. Pinpoint and Validate Your Conclusions<\/strong><\/p>\n<p>Once you\u2019ve accumulated enough data relevant in your area of influence, regroup to determine what you\u2019ve learned. This is an opportunity for analysts to get creative by identifying characteristics of threat actors and pinpointing commonalities in confirmed threats to draw data-validated conclusions. With those in hand, your team can brainstorm possible security rules to automatically thwart these types of threats in the future.<\/p>\n<p><strong>5. Automate Proactive Security Rules<\/strong><\/p>\n<p>It\u2019s time to automate and test your freshly developed security. Because you\u2019re working from your organization\u2019s own data, automating \u201chome-grown\u201d rules can help minimize threat misidentification, which\u00a0<a href=\"https:\/\/graylog.org\/post\/selling-stakeholders-on-automated-threat-response\/\">keeps stakeholders on board<\/a>. Now your team is free to begin the process again with a new (or amended) area of inquiry.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>Utilizing SIEM for proactive threat hunting allows you to develop and evolve a proprietary understanding of threats to your organization\u2014and automate threat responses\u2014in an economical and resource-resilient way.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>Source: <a href=\"https:\/\/graylog.org\/post\/next-level-threat-hunting-shift-your-siem-from-reactive-to-proactive\/\">https:\/\/graylog.org\/post\/next-level-threat-hunting-shift-your-siem-from-reactive-to-proactive\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>About DT Asia<\/strong><\/p>\n<p>DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n<p>Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>","protected":false},"excerpt":{"rendered":"<p>Threat hunting is\u00a0proactively identifying and thwarting unusual network activity\u00a0that could indicate an attempted security breach. It\u2019s a historically manual activity, making it time-intensive and arduous. It\u2019s no wonder, then, why most organizations don\u2019t have the time, budget, or resources to undertake it effectively\u2026if at all. That\u2019s why many organizations rely on\u00a0\u201creactive\u201d threat response solutions, including firewalls, intrusion detection, and SIEM to alert analysts to an event after it occurs. Without the resources to commit to proactive threat hunting, reactive solutions are the next best option.<\/p>","protected":false},"author":11,"featured_media":13294,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13292","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13292"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13292\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13294"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}