As we have witnessed the rise in cyberattacks in the past few years, we are convinced that prevention and monitoring are just the initial steps toward being prepared against any cybersecurity attacks. What we should do is develop more capabilities toward threat hunting, internal threat intelligence, and strong incident response empowered with digital forensics investigation.
Most of the organizations in the industry today are already using SIEM as their primary and central monitoring platform. Traditionally, we have been using SIEM as a platform that receives information from the rest of the network, as mentioned earlier in this chapter, to correlate and identify threats and security incidents. In essence, SIEM has always acted like a device that listened and didn't say a word. In today's cybersecurity scenario...