

EP125 Will SIEM Ever Die: SIEM Lessons from the Past for the Future
13 snips Jun 12, 2023
AI Snips
Chapters
Transcript
Episode notes
Focus on Business Risk
- Prioritize protecting the business itself, not just its machines.
- Focus on business risks like downtime and data loss, not just malware.
Threat Chains over Single Indicators
- Relying on single indicators like firewall drops is unreliable due to high false positives.
- Combine multiple indicators into threat chains for more accurate detection.
SIEM for Patterns, Not Signatures
- Avoid using SIEM for detecting specific known threats; use IDS/EDR instead.
- Focus SIEM on patterns, anomalies, and behaviors for zero-day threat detection.