SGreene > 7-44.2 Log Analysis, Detection, and Response Tools > Flashcards
Automation tool that models the behavior of humans and machines
UEBA (User Entity Behavior Analytics)
Often used to simplify complex data and tell a story
Data Visualization
Automation tool for real time data capture, event correlation analysis, and reporting
SIEM
Automation tool that combines multiple threat intelligence feeds
TIP (Threat Intelligence Platform)
Automation tool that allows an organization to define incident analysis and response procedures in a digital workflow
SOAR (Security Orchestration Automation Response)