Friday, May 5, 2017

Hacking the SIEM

Day 1 of Security B-Sides Austin is in the books. One talk in particular stuck with me: "Hack the SIEM" by John Griggs of Meta Studios, Inc.

Your SIEM is an aggregation of lots of data about your company - it contains information about endpoints, network controls, detective capabilities, and incidents. To an attacker, it is a gold mine of recon.

John brought up a different point, one I had not considered: your Security Information and Event Management system, or SIEM, may also be the single pane of glass that your SOC relies on. If an attacker doesn't show up in the SIEM, your SOC may not be aware of the incident - even if the originating network control is squawking at the top of its lungs.

Ergo, an attacker doesn't have to cover all of its tracks - they only need to stop their actions from showing up in the SIEM. Sure, original logs will show the attacker's trail in the post-mortem, but depending on their objectives, avoiding real-time detection may be all the attacker needs.

Is your SIEM locked down to prevent it from being used and abused by an attacker?

Do you have something to add? A question you'd like answered? Think I'm out of my mind? Join the conversation below, reach out by email at david (at), or hit me up on Twitter at @dnlongen

Whois David?

My photo

I have spent the better part of two decades in information technology and security, with roots in application developer support, system administration, and network security. My specialty is cyber threat intelligence - software vulnerabilities and patching, malware, social networking risks, etc. In particular, I strive to write about complex cyber topics in a way that can be understood by those outside the infosec industry.

Why do I do this? A common comment I get from friends and family is that complex security topics give them headaches. They want to know in simple terms how to stay safe in a connected world. Folks like me and my peers have chosen to make a profession out of hacking and defending. I've been doing this for the better part of two decades, and so have a high degree of knowledge in the field. Others have chosen different paths - paths where I would be lost. This is my effort to share my knowledge with those that are experts in something else.

When not in front of a digital screen, I spend my time raising five rambunctious teens and pre-teens - including two sets of twins. Our family enjoys archery, raising show and meat rabbits, and simply enjoying life in the Texas hill country.

For a decade I served as either Commander or a division leader for the Awana Club in Dripping Springs, Texas; while I have retired from that role I continue to have a passion for children's ministry. At the moment I teach 1st through 3rd grade Sunday School. Follow FBC Dripping Springs Kids to see what is going on in our children's ministries.