Connects seemingly unrelated events from different sources to identify complex attack patterns.
Open Source Security Information Management by AlienVault (now AT&T Cybersecurity). It acts as a SIEM (Security Information and Event Management) platform that:
An open-source Host-based Intrusion Detection System (HIDS). It sits on your servers and endpoints to perform:
The "unified" approach relies on the specific strengths of each tool working in tandem:
Detecting unauthorized changes to critical system files. Rootkit Detection: Identifying hidden malicious software.