Attack detection with Log360

Detect known and emerging attacks across your environment with real time alerts, contextual threat analysis, and automated response workflows built into Log360.

Attack detection with Log360
 

Attack detection with Log360

 

What you can do with Log360

 

Detect known attacks with predefined correlation rules and real time threat intelligence.

 

Uncover sophisticated attack patterns with MITRE ATT&CK aligned security analytics.

 

Spot insider misuse, compromised accounts, and risky behavior with machine learning based behavior analytics.

 

Accelerate containment by linking detections with alerting and automated incident response workflows.

  • Rule based attack detection
  • MITRE ATT&CK implementation to detect advanced attacks
  • Machine learning based behavior analytics

Rule based attack detection

Analyze threats with contextual data obtained from Log360's powerful correlation engine integrated with a comprehensive threat intelligence platform that reduces false positives and features:

  • A built-in real-time correlation engine that includes over 30 predefined rules to detect known attacks such as SQL injection, denial of service, and firewall attacks.
  • A custom correlation rule builder with an intuitive drag-n-drop interface to build new correlation rules.
  • Real-time email and SMS notifications delivered promptly to security admins when incidents are detected.
  • An easy way to associate workflow profiles with correlation rules for instant remediation.
Get your free Correlation Resource Kit!  
Rule based attack detection

MITRE ATT&CK implementation to detect advanced attacks

Sophisticated attacks require visibility into attacker behavior across multiple stages. Log360 supports MITRE ATT&CK aligned detection to help security analysts trace attacker tactics and techniques more effectively.

  • A real-time security analytics dashboard tied to the MITRE's TTPs database to quickly investigate suspicious activities.
  • A correlation rule builder equipped with prebuilt actions mapped to MITRE's techniques to trace attackers' movements.
  • An easy way to associate workflow profiles with MITRE ATT&CK actions for immediate incident response.
Try this feature  
MITRE ATT&CK implementation to detect advanced attacks

Machine learning based behavior analytics

Not all attacks follow known patterns. Log360 uses behavior analytics to uncover malicious insiders, compromised accounts, privilege misuse, unauthorized data access, and exfiltration behavior that might be missed by static rules.

  • Automatic machine-learning actions that monitor user and entity behaviors, track anomalous and suspicious behavior, and promptly alert security admins about questionable activities.
  • Integrated risk management that assigns risk scores to every anomaly.
  • Real-time notifications for high risk scores and atypical behaviors.
  • The option to watchlist users and entities to closely monitor their activities.
Explore user entity behavior analytics (UEBA)  
Machine learning based behavior analytics

Security use cases Log360 attack detection can solve

Malware is one of the most persistent cyberthreats in the modern world. As new malware appears, detecting it remains a challenge. Log360 unmasks the presence of malware in the network utilizing its predefined correlation rules. It spots suspicious software or service installations by malicious actors, alerts security admins immediately, and provides detailed incident timelines for investigation. This solution also lets you associate a workflow profile to stop the service or process, facilitating an immediate incident response.

Often, attackers executing advanced and sophisticated attacks are detected when they try to leave your network perimeter with the stolen data. Log360 spots and alerts your security team to data extortion in real time. The solution monitors security events and uncovers techniques such as data exfiltration over alternative protocol (T1048), and unusual data flows in the network. If any of the applications send more traffic than they receive, this will be deemed suspicious, and an alert will be triggered to warn the security team of a possible security threat.

Read the complete use case here.

Leverage machine learning to spot malicious insiders It is more difficult to spot insider attacks as they are carried out with legitimate access. Log360's UEBA component ingests log data of the users over a period of time and profiles all of their behaviors. When a chain of suspicious behavior, such as odd logon times, unusual access to sensitive data, or multiple file downloads is detected, the user's risk score for insider threat increases and the security team is alerted. Log360 also provides detailed event timelines for further investigation.

Explore these interactive graphics to see how risk scores add up during threats.

  •  

    We wanted to make sure that one, we can check the box for different security features that our clients are looking for us to have, and two, we improve our security so that we can harden our security footprint.

    Carter Ledyard

  •  

    The drill-down options and visual dashboards make threat investigation much faster and easier. It’s a truly user-friendly solution.

    Sundaram Business Services

  •  

    Log360 helped detect insider threats, unusual login patterns, privilege escalations, and potential data exfiltration attempts in real time.

    CIO, Northtown Automotive Companies

  •  

    Before Log360, we were missing a centralized view of our entire infrastructure. Now, we can quickly detect potential threats and respond before they escalate.Log360 has been invaluable for improving our incident response and ensuring compliance with audit standards. It’s a game-changer for our team.

    ECSO 911

 

Frequently Asked Questions

Attack detection is the process of identifying malicious activity, suspicious behavior, and indicators of compromise across an environment so security teams can investigate and respond.

Log360 uses correlation rules, threat intelligence, MITRE aligned analytics, behavior analytics, and real time alerts to detect attacks across users, endpoints, and network activity.

Log360 can help detect malware activity, SQL injection attempts, denial of service behavior, data exfiltration, insider misuse, compromised accounts, and other suspicious attack patterns.

Behavior analytics helps identify attacks that do not match known static rules by detecting anomalies, misuse, and suspicious patterns over time.

Log360 sends real time alerts, provides detailed incident context, and supports workflow driven remediation to help teams move from detection to containment faster.

Detect attacks before they turn into breaches

Use Log360 to uncover malicious activity, investigate incidents faster, and automate your response.