Integrating Logs and Flows in QRadar
When an application is developed, a provision to log the details in it is also developed alongside. Logging is usually used to debug the application while developing as well as to troubleshoot and provide support to it. Every application can have different types of logs. Some of these logs contain security information, such as identity and access management logs, buffer overflow messages, and file tampering. All such logs play an important role in understanding the security risk for an organization.
Consider a scenario where a hacker gains access to a system; the first thing the hacker does is delete or purge the entries in the logs that would alert their unauthorized access to the system. This way, the hacker remains safe and can then do lateral movement to access other critical servers. So, how do we monitor and detect such attacks? The answer is by using flows in conjunction with logs. As the adage goes, flows don’t lie!
If someone...