{"id":64138,"date":"2023-03-26T15:10:18","date_gmt":"2023-03-26T13:10:18","guid":{"rendered":"https:\/\/www.cocus.com\/how-does-a-siem-system-detect-threats-siem-use-cases\/"},"modified":"2024-03-04T15:59:22","modified_gmt":"2024-03-04T13:59:22","slug":"how-does-a-siem-system-detect-threats-siem-use-cases","status":"publish","type":"post","link":"https:\/\/www.cocus.com\/en\/how-does-a-siem-system-detect-threats-siem-use-cases\/","title":{"rendered":"How does a SIEM system detect threats? \u2013 SIEM Use Cases"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"64138\" class=\"elementor elementor-64138 elementor-62734\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-64f56580 elementor-section-full_width elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"64f56580\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2226542f lottie-bg-no\" data-id=\"2226542f\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-30e656a elementor-widget elementor-widget-text-editor\" data-id=\"30e656a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Malicious <a href=\"https:\/\/www.cocus.com\/en\/lockbit-apt-siem-protection-advanced-attacks\/\">cyberattacks<\/a> on companies are becoming increasingly sophisticated, so a company&#8217;s security measures must be adapted accordingly. One very effective threat detection measure is SIEM (Security Information and Event Management) software. We present several SIEM use cases that you should be aware of.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-26c26fe elementor-widget elementor-widget-text-editor\" data-id=\"26c26fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A <a href=\"https:\/\/www.cocus.com\/en\/siem-systems\/\">SIEM system<\/a> is designed to detect and respond to a wide range of security events and incidents. By analyzing log data from multiple sources and applying advanced analytics, SIEM systems can give organizations a comprehensive view of their security posture and help them identify and respond to potential security threats even before the situation becomes serious.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fbbf5bd elementor-widget elementor-widget-text-editor\" data-id=\"fbbf5bd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Many companies are also required to comply with certain regulations such as the DSGVO or PCI DSS. SIEM software can help monitor compliance in this case as well. Maybe these SIEM use cases also affect your company?<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1d8961b elementor-section-full_width elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"1d8961b\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c89cfa8 lottie-bg-no\" data-id=\"c89cfa8\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2df6438 elementor-widget elementor-widget-heading\" data-id=\"2df6438\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">How a SIEM system detects threats <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3bb5867 elementor-widget elementor-widget-text-editor\" data-id=\"3bb5867\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>But how can a SIEM system identify and alert on such events?<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-07b2930 elementor-widget elementor-widget-text-editor\" data-id=\"07b2930\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Specific security events or incidents that the system should detect and respond to are called &#8220;detection use cases&#8221; or &#8220;analytic stories.&#8221; The secret here is to implement detection patterns that come from threat intelligence information or machine learning\/AI capabilities. The different SIEM use cases can vary from company to company.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fd6753f elementor-widget elementor-widget-heading\" data-id=\"fd6753f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Typical SIEM Use Cases<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-701e4f5 elementor-widget elementor-widget-text-editor\" data-id=\"701e4f5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-family: 'Peter-Medium'; color: #ff961e;\">Suspicious user account activity:<\/span> A SIEM system can detect suspicious user account login activity by analyzing log data from authentication systems such as Active Directory. If an employee attempts to log in with multiple incorrect passwords or from an unusual location, the SIEM can trigger an alert to the security team.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-798f882 elementor-align-start elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"798f882\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"cocus cocus-cocus-icon-89\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">For example, in the familiar use case of \"impossible travel,\" a SIEM detects user activity from two locations that cannot be traveled to in the intervening time.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7b1b95 elementor-widget elementor-widget-text-editor\" data-id=\"d7b1b95\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-family: 'Peter-Medium'; color: #ff961e;\">Data exfiltration attempts:<\/span> Another category of anomalies is data exfiltration attempts, which SIEMs detect by analyzing log data from network devices such as routers and firewalls.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ff7ad6 elementor-align-start elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"1ff7ad6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"cocus cocus-cocus-icon-89\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">For example, if a device is transmitting large amounts of data to an external IP address, the SIEM may trigger an alert and initiate an automated response to block the traffic.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-31cbe3e elementor-widget elementor-widget-text-editor\" data-id=\"31cbe3e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-family: 'Peter-Medium'; color: #ff961e;\">Insider threats:<\/span> So-called insider threats are monitored by SIEM systems by analyzing log data from various sources such as activity logs and file access logs.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b5a6039 elementor-align-start elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"b5a6039\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"cocus cocus-cocus-icon-89\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">If an employee attempts to access sensitive data outside of their normal working hours or attempts to access data they do not have permission to access, the SIEM can raise an alert to the security team.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2425dc1 elementor-widget elementor-widget-text-editor\" data-id=\"2425dc1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-family: 'Peter-Medium'; color: #ff961e;\">Malware infections:<\/span> SIEMs can also play a role in malware defense alongside traditional endpoint protection systems. A SIEM system can detect malware infections on devices by analyzing log data from various sources, such as firewalls, antivirus software and intrusion detection systems.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-19673c8 elementor-align-start elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"19673c8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"cocus cocus-cocus-icon-89\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">For example, if a device attempts to connect to a command-and-control server, the SIEM can warn and automatically isolate the device from the network.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6f7388d elementor-widget elementor-widget-text-editor\" data-id=\"6f7388d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-family: 'Peter-Medium'; color: #ff961e;\">Compliance violations:<\/span> One final example &#8211; a SIEM system can detect compliance violations by analyzing log data from multiple sources such as database logs and access control systems.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-81429cb elementor-align-start elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"81429cb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<i aria-hidden=\"true\" class=\"cocus cocus-cocus-icon-89\"><\/i>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">For example, if an employee accesses sensitive data without proper authorization, the SIEM can trigger an alert and initiate an automated response to ensure the employee's access is revoked.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-371ddfa elementor-widget elementor-widget-text-editor\" data-id=\"371ddfa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In addition to looking for known patterns and SIEM use cases, a SIEM solution can help security teams <strong>proactively look for potential threats<\/strong> by analyzing large amounts of data.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c52ef28 elementor-widget elementor-widget-text-editor\" data-id=\"c52ef28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>For example, systems can analyze network traffic to identify anomalies that could indicate a potential security threat.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fc5032e elementor-widget elementor-widget-heading\" data-id=\"fc5032e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Individual SIEM Solutions<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4eb1d62 elementor-widget elementor-widget-text-editor\" data-id=\"4eb1d62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>COCUS provides services to implement and operate efficient and effective SIEM solutions. Not quite sure where to even start to implement the various SIEM use cases? We offer you a Rapid SIEM approach based on <a href=\"https:\/\/partners.splunk.com\/solutionscatalog\/partner\/333699\/cocus-consulting-gmbh\" target=\"_blank\" rel=\"noopener\">Splunk<\/a> that helps organizations start their SIEM implementation at a fixed, affordable price and quickly realize value.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f92e105 elementor-widget elementor-widget-heading\" data-id=\"f92e105\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h5 class=\"elementor-heading-title elementor-size-default\">We have the solution when it comes to the security of your business. Contact us and we will implement your individual SIEM use cases!<\/h5>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-621340a elementor-widget elementor-widget-button\" data-id=\"621340a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cocus.com\/en\/about-us\/contact\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Discuss SIEM Use Cases<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>A SIEM system detects security risks, raises alarms &amp; reacts automatically. But how &amp; which events does a SIEM identify exactly?<\/p>\n","protected":false},"author":24,"featured_media":72046,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[424,570],"tags":[586,426,518],"class_list":["post-64138","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-en","category-news-en","tag-automation-en","tag-cybersecurity-en","tag-siem-en"],"_links":{"self":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/64138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/comments?post=64138"}],"version-history":[{"count":0,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/64138\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/media\/72046"}],"wp:attachment":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/media?parent=64138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/categories?post=64138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/tags?post=64138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}