SIEM - Alienvault OSSIM

Asphyxia

Owner
Administrator
Apr 25, 2015
1,844
2
2,197
327
So, this is a pretty sick tool:
AlienVault OSSIM

1587882636453.png

As you can quickly see, we are able to realize the need for a SIEM - and perhaps a firewall to actually block these attackers.

The problem?

Over 15,000 attack events occurred from a single Russian host.

The solution?

Using this AlienVault OSSIM tool, trigger a block on a firewall to get the IP(s) banned from the network. Waste of networking resources, ignore!

Download the ISO here: https://cybersecurity.att.com/products/ossim/download
 
Top