4 ms·
2) Log as much as possible and do something with the logs. Log everything and continue to improve your SIEM or security stack based on new threat intel. This i
by phaus 7y ago
2) Log as much as possible and do something with the logs. Log everything and continue to improve your SIEM or security stack based on new threat intel.
This is a good one. If you have a SIEM + Log Aggregation setup and you don't have robust logging and/or aren't feeding those logs into it, you should have saved yourself some time and burned the money you spent on it.