1
1

00:00:00,120  -->  00:00:01,410
<v Instructor>Security information</v>
2

2

00:00:01,410  -->  00:00:03,540
and event management systems.
3

3

00:00:03,540  -->  00:00:07,470
Now log review is a critical part of security assurance.
4

4

00:00:07,470  -->  00:00:10,170
We're going to gather logs from all sorts of different systems,
5

5

00:00:10,170  -->  00:00:12,210
but gathering logs does you no good
6

6

00:00:12,210  -->  00:00:14,370
if you don't actually look at those logs.
7

7

00:00:14,370  -->  00:00:17,220
Now logs shouldn't be reviewed just after an incident.
8

8

00:00:17,220  -->  00:00:18,420
You shouldn't use them just as part
9

9

00:00:18,420  -->  00:00:20,010
of an instant response, for example.
10

10

00:00:20,010  -->  00:00:22,170
But you should look at them regularly and routinely
11

11

00:00:22,170  -->  00:00:23,460
as part of your threat hunting
12

12

00:00:23,460  -->  00:00:25,260
and proactive system management.
13

13

00:00:25,260  -->  00:00:26,670
To do this effectively though,
14

14

00:00:26,670  -->  00:00:28,680
you really do need to use a SIEM.
15

15

00:00:28,680  -->  00:00:31,290
Now a SIEM is a solution that provides real-time
16

16

00:00:31,290  -->  00:00:33,780
or near-real-time analysis of security alerts
17

17

00:00:33,780  -->  00:00:36,720
generated by network hardware and applications.
18

18

00:00:36,720  -->  00:00:38,040
Now as we look at a SIEM,
19

19

00:00:38,040  -->  00:00:39,660
there's a lot of uses for one.
20

20

00:00:39,660  -->  00:00:40,920
But one of the best things they do
21

21

00:00:40,920  -->  00:00:43,230
is they help us correlate events.
22

22

00:00:43,230  -->  00:00:45,000
Let's take a simple example.
23

23

00:00:45,000  -->  00:00:46,260
You're looking through the logs
24

24

00:00:46,260  -->  00:00:47,670
and you see that somebody has logged in
25

25

00:00:47,670  -->  00:00:49,680
over a VPN from Asia.
26

26

00:00:49,680  -->  00:00:52,440
It's John Smith, and he's logging in from Asia
27

27

00:00:52,440  -->  00:00:53,820
because he is on a business trip.
28

28

00:00:53,820  -->  00:00:55,440
Well, there's nothing wrong with that.
29

29

00:00:55,440  -->  00:00:57,270
But if you look at just moments later,
30

30

00:00:57,270  -->  00:01:00,150
you see that John Smith's ID has been used to log in
31

31

00:01:00,150  -->  00:01:02,130
to the server room in your building.
32

32

00:01:02,130  -->  00:01:03,360
Well, that's an issue
33

33

00:01:03,360  -->  00:01:05,220
because he can't both be in your server room
34

34

00:01:05,220  -->  00:01:06,990
and on a business trip in Asia.
35

35

00:01:06,990  -->  00:01:08,850
So one of those two things is wrong.
36

36

00:01:08,850  -->  00:01:10,830
Now either one by itself is fine,
37

37

00:01:10,830  -->  00:01:12,660
but putting those together and correlating them
38

38

00:01:12,660  -->  00:01:15,330
flags as something that we need to look into and figure out
39

39

00:01:15,330  -->  00:01:16,740
where is this person
40

40

00:01:16,740  -->  00:01:18,780
and how is he in two very different places
41

41

00:01:18,780  -->  00:01:20,430
both at the same time.
42

42

00:01:20,430  -->  00:01:24,240
A SIEM helps you do this very quickly and very easily.
43

43

00:01:24,240  -->  00:01:26,790
Now a security and information event management system
44

44

00:01:26,790  -->  00:01:29,580
or a SIEM can be implemented many different ways.
45

45

00:01:29,580  -->  00:01:32,310
You could do this as software, hardware appliances,
46

46

00:01:32,310  -->  00:01:34,500
or even as an outsource managed service.
47

47

00:01:34,500  -->  00:01:36,210
Now to effectively deploy a SIEM,
48

48

00:01:36,210  -->  00:01:38,760
you have to consider a lot of different things.
49

49

00:01:38,760  -->  00:01:41,250
First, you need to be able to log all relevant events
50

50

00:01:41,250  -->  00:01:43,800
and filter out anything that is not considered relevant
51

51

00:01:43,800  -->  00:01:45,870
anything that's irrelevant data.
52

52

00:01:45,870  -->  00:01:48,000
Second, you need to make sure you can establish
53

53

00:01:48,000  -->  00:01:50,370
and document the scope of the events.
54

54

00:01:50,370  -->  00:01:51,960
Exactly what are you going to log
55

55

00:01:51,960  -->  00:01:54,660
what is inside and outside of your scope.
56

56

00:01:54,660  -->  00:01:58,170
Third, you need to develop use cases to define a threat.
57

57

00:01:58,170  -->  00:02:00,660
This will help you define exactly what you do
58

58

00:02:00,660  -->  00:02:02,130
and do not consider a threat
59

59

00:02:02,130  -->  00:02:04,320
and then what you may take action on later.
60

60

00:02:04,320  -->  00:02:06,390
Speaking of that, that brings us to number four.
61

61

00:02:06,390  -->  00:02:09,720
You need to plan incident responses for given events.
62

62

00:02:09,720  -->  00:02:12,600
If you know that when you see this type of thing happen,
63

63

00:02:12,600  -->  00:02:14,940
you are going to take those type of actions.
64

64

00:02:14,940  -->  00:02:15,930
That's what we're talking about here.
65

65

00:02:15,930  -->  00:02:17,370
It's pre-planned responses
66

66

00:02:17,370  -->  00:02:19,860
for any kind of given threat you might face.
67

67

00:02:19,860  -->  00:02:22,320
Fifth, we want to establish a ticketing process
68

68

00:02:22,320  -->  00:02:25,290
so we can track all these different events that we flag.
69

69

00:02:25,290  -->  00:02:26,430
This way as we go in the SIEM,
70

70

00:02:26,430  -->  00:02:27,780
we see something that's unusual.
71

71

00:02:27,780  -->  00:02:30,180
Like my example earlier was somebody logging in from Asia
72

72

00:02:30,180  -->  00:02:32,490
and at the local office at the same time,
73

73

00:02:32,490  -->  00:02:35,040
you can flag that and have it tracked throughout the process
74

74

00:02:35,040  -->  00:02:36,480
to make sure it doesn't get dropped.
75

75

00:02:36,480  -->  00:02:39,330
Six, we want to schedule regular threat hunting.
76

76

00:02:39,330  -->  00:02:41,010
Now by doing this, we want to make sure
77

77

00:02:41,010  -->  00:02:42,810
we're not missing any important events
78

78

00:02:42,810  -->  00:02:44,370
that may have escaped alerts.
79

79

00:02:44,370  -->  00:02:46,140
By going through and doing threat hunting,
80

80

00:02:46,140  -->  00:02:48,750
we're going to be able to catch bad guys doing bad things
81

81

00:02:48,750  -->  00:02:50,820
that may have escaped our alerts.
82

82

00:02:50,820  -->  00:02:53,820
And finally, our seventh item is providing auditors
83

83

00:02:53,820  -->  00:02:55,980
and analysts an evidence trail.
84

84

00:02:55,980  -->  00:02:58,800
A SIEM is a great place with a centralized repository
85

85

00:02:58,800  -->  00:03:00,330
of lots of different data.
86

86

00:03:00,330  -->  00:03:02,340
And so it's a great place for auditors and analysts
87

87

00:03:02,340  -->  00:03:04,920
to look through as they're doing their analysis.
88

88

00:03:04,920  -->  00:03:06,930
Now when I talk about a SIEM solution,
89

89

00:03:06,930  -->  00:03:09,870
there are lots of different SIEM solutions out there.
90

90

00:03:09,870  -->  00:03:10,950
There are many commercial
91

91

00:03:10,950  -->  00:03:12,720
and open-source solutions available,
92

92

00:03:12,720  -->  00:03:15,540
and it's up to you to decide which one you want to use.
93

93

00:03:15,540  -->  00:03:17,040
As we go through the rest of this lesson,
94

94

00:03:17,040  -->  00:03:18,360
I'm going to bring up a couple of them
95

95

00:03:18,360  -->  00:03:19,680
and show you what they look like.
96

96

00:03:19,680  -->  00:03:21,810
We're going to cover things like Splunk,
97

97

00:03:21,810  -->  00:03:26,810
ELK or Elastic Stack, ArcSight, QRadar,
98

98

00:03:26,970  -->  00:03:30,960
AlienVault and OSSIM, and Graylog.
99

99

00:03:30,960  -->  00:03:32,460
Let's start with Splunk.
100

100

00:03:32,460  -->  00:03:35,130
Splunk is a market-leading big data information
101

101

00:03:35,130  -->  00:03:36,840
gathering and analysis tool,
102

102

00:03:36,840  -->  00:03:38,970
and it can import machine-generated data
103

103

00:03:38,970  -->  00:03:41,580
via connector or a visibility add-on.
104

104

00:03:41,580  -->  00:03:43,545
Now Splunk is really good at connecting
105

105

00:03:43,545  -->  00:03:46,020
lots of different data systems.
106

106

00:03:46,020  -->  00:03:48,150
In fact, it has different connectors built
107

107

00:03:48,150  -->  00:03:50,070
for most network operating systems
108

108

00:03:50,070  -->  00:03:52,080
and different application formats.
109

109

00:03:52,080  -->  00:03:54,570
Essentially, all the data from all the different systems
110

110

00:03:54,570  -->  00:03:57,270
can be indexed as it's taken off those systems
111

111

00:03:57,270  -->  00:03:59,580
and then written to a centralized data store.
112

112

00:03:59,580  -->  00:04:01,950
This allows Splunk to be able to go through historical
113

113

00:04:01,950  -->  00:04:04,290
or real-time data and be able to search through it
114

114

00:04:04,290  -->  00:04:06,510
using its proprietary search algorithms
115

115

00:04:06,510  -->  00:04:08,940
called the search processing language.
116

116

00:04:08,940  -->  00:04:10,380
Now once you get those results,
117

117

00:04:10,380  -->  00:04:12,960
you can start visualizing it using different tools.
118

118

00:04:12,960  -->  00:04:15,300
So when you use Splunk, it looks something like this.
119

119

00:04:15,300  -->  00:04:17,610
Notice here I have what looks like a dashboard.
120

120

00:04:17,610  -->  00:04:19,560
On here, I can see the important information.
121

121

00:04:19,560  -->  00:04:20,520
I see a lot of data.
122

122

00:04:20,520  -->  00:04:23,040
I see the trends going up or going down.
123

123

00:04:23,040  -->  00:04:24,510
I can see events over time
124

124

00:04:24,510  -->  00:04:27,090
and I can actually drill down by clicking into each one
125

125

00:04:27,090  -->  00:04:30,000
by going in and looking at the data behind it as well.
126

126

00:04:30,000  -->  00:04:31,770
Splunk is a really great tool
127

127

00:04:31,770  -->  00:04:33,210
and it can be installed locally
128

128

00:04:33,210  -->  00:04:35,520
or as a cloud-based solution.
129

129

00:04:35,520  -->  00:04:36,450
When you buy Splunk,
130

130

00:04:36,450  -->  00:04:37,860
it comes with a lot of templates
131

131

00:04:37,860  -->  00:04:39,540
and pre-configured dashboards,
132

132

00:04:39,540  -->  00:04:40,950
security intelligence searches,
133

133

00:04:40,950  -->  00:04:42,780
and instant response workflows.
134

134

00:04:42,780  -->  00:04:44,940
Splunk is a big player in the marketplace
135

135

00:04:44,940  -->  00:04:47,460
and it is a great SIEM to consider.
136

136

00:04:47,460  -->  00:04:50,970
The next one we want to talk about is ELK or Elastic Stack.
137

137

00:04:50,970  -->  00:04:53,670
Now ELK and Elastic Stack is a collection of free
138

138

00:04:53,670  -->  00:04:56,250
and open-source SIEM tools that provides storage,
139

139

00:04:56,250  -->  00:04:58,410
search, and analysis functions.
140

140

00:04:58,410  -->  00:05:00,990
Now ELK and Elastic Stack is actually made up
141

141

00:05:00,990  -->  00:05:02,850
of four different components.
142

142

00:05:02,850  -->  00:05:04,500
These are the Elasticsearch
143

143

00:05:04,500  -->  00:05:07,110
which covers the query and analytics,
144

144

00:05:07,110  -->  00:05:10,800
Logstash which is your log collection and normalization,
145

145

00:05:10,800  -->  00:05:13,110
Kibana which does your visualization,
146

146

00:05:13,110  -->  00:05:15,330
and Beats which is your endpoint collection agents
147

147

00:05:15,330  -->  00:05:17,160
that are installed on the machines.
148

148

00:05:17,160  -->  00:05:18,450
The way these all work together
149

149

00:05:18,450  -->  00:05:20,100
is you're going to have the different Beats
150

150

00:05:20,100  -->  00:05:22,380
installed on different servers or hosts.
151

151

00:05:22,380  -->  00:05:24,420
And they can then send data either directly back
152

152

00:05:24,420  -->  00:05:28,590
to the Elastic Stack or it can go into Logstash first.
153

153

00:05:28,590  -->  00:05:30,510
Now when it goes into Logstash first
154

154

00:05:30,510  -->  00:05:33,060
it's going to do the parsing and the normalization for you
155

155

00:05:33,060  -->  00:05:35,100
and then send it into Elastic.
156

156

00:05:35,100  -->  00:05:36,450
If you go directly to Elastic,
157

157

00:05:36,450  -->  00:05:39,000
it has to be in a format that it already understands.
158

158

00:05:39,000  -->  00:05:41,640
Now Elastic is that centralized data store.
159

159

00:05:41,640  -->  00:05:44,640
But you don't really go into Elastic to look at the data,
160

160

00:05:44,640  -->  00:05:46,320
instead you use Kibana.
161

161

00:05:46,320  -->  00:05:49,680
And Kibana goes into Elastic and then visualizes that data
162

162

00:05:49,680  -->  00:05:52,140
in a way that you can see and understand.
163

163

00:05:52,140  -->  00:05:54,870
Just like Splunk, ELK Stack may be installed locally
164

164

00:05:54,870  -->  00:05:57,090
or as a cloud-based solution.
165

165

00:05:57,090  -->  00:06:00,000
Our third SIEM tool we're going to discuss is ArcSight.
166

166

00:06:00,000  -->  00:06:02,940
ArcSight is a SIEM log management and analytics software
167

167

00:06:02,940  -->  00:06:05,700
that can be used for compliance reporting, for legislation,
168

168

00:06:05,700  -->  00:06:09,870
and regulations like HIPPA, SOX, and PCI DSS.
169

169

00:06:09,870  -->  00:06:12,090
When you look at ArcSight, it looks like another dashboard.
170

170

00:06:12,090  -->  00:06:14,250
And again, you can drill down into that information
171

171

00:06:14,250  -->  00:06:16,410
and display it in lots of different ways.
172

172

00:06:16,410  -->  00:06:18,840
The fourth one we're going to talk about is QRadar.
173

173

00:06:18,840  -->  00:06:20,940
And QRadar is a SIEM log management,
174

174

00:06:20,940  -->  00:06:24,480
analytics, and compliance reporting platform created by IBM.
175

175

00:06:24,480  -->  00:06:26,730
It does a lot of the same stuff we've just talked about.
176

176

00:06:26,730  -->  00:06:29,220
And again, it comes with a nice dashboard.
177

177

00:06:29,220  -->  00:06:30,390
As you look at the dashboard,
178

178

00:06:30,390  -->  00:06:32,340
you get different things that you can be looking at
179

179

00:06:32,340  -->  00:06:34,860
and considering those for your network.
180

180

00:06:34,860  -->  00:06:37,950
Our fifth one is AlienVault and OSSIM,
181

181

00:06:37,950  -->  00:06:41,160
the Open-Source Security Information Management System.
182

182

00:06:41,160  -->  00:06:43,620
Now this is a SIEM solution that was originally developed
183

183

00:06:43,620  -->  00:06:46,050
by AlienVault, which is why it's called AlienVault
184

184

00:06:46,050  -->  00:06:47,880
but now it's owned by AT&amp;T
185

185

00:06:47,880  -->  00:06:49,320
and they've been rebranding it recently
186

186

00:06:49,320  -->  00:06:51,600
as AT&amp;T Cybersecurity,.
187

187

00:06:51,600  -->  00:06:52,560
Just like the other ones,
188

188

00:06:52,560  -->  00:06:54,960
it does come with a dashboard where you can search
189

189

00:06:54,960  -->  00:06:56,430
and dig into the different information
190

190

00:06:56,430  -->  00:06:58,080
that could be presented here.
191

191

00:06:58,080  -->  00:07:01,170
Now one of the nice things about AlienVault and OSSIM
192

192

00:07:01,170  -->  00:07:04,230
is that OSSIM can integrate other open-source tools
193

193

00:07:04,230  -->  00:07:07,620
such as Snort IDS and OpenVAS vulnerability scanners,
194

194

00:07:07,620  -->  00:07:10,620
and it can provide an integrated web administration tool
195

195

00:07:10,620  -->  00:07:13,020
for you to manage the entire security environment.
196

196

00:07:13,020  -->  00:07:15,870
So it does give you this nice all-in-one solution.
197

197

00:07:15,870  -->  00:07:18,240
Also, because you're using a lot of open-source tools here,
198

198

00:07:18,240  -->  00:07:20,280
it does keep your cost low.
199

199

00:07:20,280  -->  00:07:22,317
The final one we want to talk about is Graylog.
200

200

00:07:22,317  -->  00:07:24,510
And Graylog is an open-source SIEM
201

201

00:07:24,510  -->  00:07:26,850
with an enterprise version that's focused on compliance
202

202

00:07:26,850  -->  00:07:29,520
and supporting IT operations and DevOps.
203

203

00:07:29,520  -->  00:07:31,290
And again, it has a nice dashboard
204

204

00:07:31,290  -->  00:07:33,270
where you can drill down and search for things.
205

205

00:07:33,270  -->  00:07:34,740
The big difference with Graylog
206

206

00:07:34,740  -->  00:07:36,390
is that it's really focused on DevOps
207

207

00:07:36,390  -->  00:07:38,220
and supporting IT operations
208

208

00:07:38,220  -->  00:07:40,200
as opposed to doing more of the log analysis
209

209

00:07:40,200  -->  00:07:42,810
and the instant response that some of the things like Splunk
210

210

00:07:42,810  -->  00:07:44,850
are much better suited for.
211

211

00:07:44,850  -->  00:07:47,070
Now let's talk about the exam for just a moment.
212

212

00:07:47,070  -->  00:07:48,990
You do not need to know specific tools
213

213

00:07:48,990  -->  00:07:50,670
for the CySA+ exam
214

214

00:07:50,670  -->  00:07:52,650
like the ones I mentioned in this lesson.
215

215

00:07:52,650  -->  00:07:54,720
We covered them here simply to make sure you were introduced
216

216

00:07:54,720  -->  00:07:56,790
to the brand names and the different tools.
217

217

00:07:56,790  -->  00:07:58,170
If you hear any of these names,
218

218

00:07:58,170  -->  00:08:01,050
you should know they have the ability to act as a SIEM.
219

219

00:08:01,050  -->  00:08:03,300
But beyond that, you don't need to know how to use them
220

220

00:08:03,300  -->  00:08:05,460
or operate them for the exam.
221

221

00:08:05,460  -->  00:08:08,042
Now that said, a lot of these open-source tools
222

222

00:08:08,042  -->  00:08:10,710
make a great addition to your own practice labs
223

223

00:08:10,710  -->  00:08:12,150
and your own home networks.
224

224

00:08:12,150  -->  00:08:13,860
'Cause if you're building out your home network,
225

225

00:08:13,860  -->  00:08:17,070
this will give you experience using these tools hands-on.
226

226

00:08:17,070  -->  00:08:19,980
This will make you a much better analyst in the real world.
227

227

00:08:19,980  -->  00:08:22,980
Now in the real world, which of these tools should you use?
228

228

00:08:22,980  -->  00:08:24,600
Well, that depends,
229

229

00:08:24,600  -->  00:08:26,340
which company are you trying to get a job at
230

230

00:08:26,340  -->  00:08:28,350
or which company do you already work for?
231

231

00:08:28,350  -->  00:08:29,640
As I've worked at different companies
232

232

00:08:29,640  -->  00:08:30,870
and organizations over the years,
233

233

00:08:30,870  -->  00:08:33,000
we have used several of these different tools,
234

234

00:08:33,000  -->  00:08:36,030
including Splunk, ELK Stack, and AlienVault
235

235

00:08:36,030  -->  00:08:37,890
and some of the different organizations I've worked with.
236

236

00:08:37,890  -->  00:08:39,780
So I have experience with all of those.
237

237

00:08:39,780  -->  00:08:41,220
Is one better than the other?
238

238

00:08:41,220  -->  00:08:43,200
Well, it really does depend on your use case.
239

239

00:08:43,200  -->  00:08:44,580
But really when it comes down to it,
240

240

00:08:44,580  -->  00:08:45,600
it's what your boss likes
241

241

00:08:45,600  -->  00:08:47,500
and what your company's already using.
