3 ms·
That's what the SIEM does, see ones such as IBM QRadar [1]; aggregates all the logs and network flows from across your estate and then uses rules/algorithms to
by cones688 13y ago
That's what the SIEM does, see ones such as IBM QRadar [1]; aggregates all the logs and network flows from across your estate and then uses rules/algorithms to determine threats and security events.
From my limited understanding MozDef is more targeted at ticketing/following through from intelligence gleaned from a SIEM as most times, people then just stick it in Remedy or Jira.
[1] http://public.dhe.ibm.com/common/ssi/ecm/en/wgd03021usen/WGD03021USEN.PDF http://public.dhe.ibm.com/common/ssi/ecm/en/wgd03021usen/WGD...
- jeffbryner 13y agoSorry it's a bit tough to understand. You can think of MozDef as an open source SIEM (taking in logs, parsing, alerting, correlating) plus incident handling workflow with a focus on being open, extensible, visual and realtime. It is early, early days but promising so far!