Analyzing your SIEM Flashcards
(20 cards)
The process of reviewing SIEM alerts to determine their severity and legitimacy.
Alert triage
Logs, events, and alerts used to reconstruct a timeline of attacker activity.
Security event reconstruction
The process of identifying relationships between alerts across multiple systems.
Cross-log correlation
A SIEM feature that displays real-time dashboards of security trends and alerts.
Visual analytics interface
A step-by-step method to confirm whether an alert represents a true incident.
Alert validation
A SIEM insight where the same hash is seen across multiple hosts in a short period
Lateral movement indicator
Evidence in SIEM showing repeated attempts to access unauthorized resources.
Access violation pattern
A method of grouping multiple related alerts into a single incident for investigation.
Alert aggregation
SIEM alert showing an application making outbound connections to a rare external IP.
Potential C2 communication
SIEM alert showing an unusual number of login attempts in a short time frame.
Brute-force login indicator
A low-severity alert repeated over time that may indicate a stealthy attack.
Alert frequency anomaly
An alert triggered by activity during non-working hours from a privileged account.
Suspicious user behavior
An incident where exfiltrated data volume exceeds baseline values.
Data leakage detection
The investigation of failed authentications followed by a successful login.
Possible compromised credentials
SIEM log entries showing the same user logging in from two countries within minutes.
Impossible travel anomaly
Alert involving registry modification, script execution, and outbound traffic from the same endpoint.
Multi-stage attack correlation
The SIEM function that assigns a risk score to assets or alerts based on context.
Risk-based alerting
Investigating a sudden spike in alerts from a single IP address.
Source-focused investigation
The use of threat intelligence feeds in SIEM to enrich log analysis.
Contextual enrichment
A known-good activity flagged incorrectly due to overly sensitive detection rules.
False positive