Common cybersecurity tools Flashcards
What are logs?
A record of events that occurs within an organizations systems. Examples of security-related logs include records of employees signing into their computers or accessing web-based services. Logs help security professionals identify vulnerabilities and potential security breaches.
what does SIEM stand for?
security information and event management
what is an SIEM tool?
A SIEM tool is an application that collects and analyzes log data to monitor critical activities in an organization. SIEM tools collect real-time, or instant, information, and allow security analysts to identify potential breaches as they happen.
What are commonly used SIEM tools?
Splunk and Chronicle
what is Splunk?
Splunk is a data analysis platform. Splunk Enterprise is a self-hosted tool used to retain, analyze, and search an organization’s log data
What is Google’s Chronicle?
Chronicle is a cloud-native SIEM tool that stores security data for search and analysis. Cloud-native means that Chronicle allows for fast delivery of new features.
playbook meaning
A manual that provides details about any operational action, such as how to respond to an incident. Playlists can vary depending on the organization and they guide analysts in how to handle a security incident before, during, and after it has occurred.
what is a network protocol analyzer/packet sniffer
A packet sniffer is a tool designed to capture and analyze data traffic within a network. Common network protocol analyzers include tcpdump and Wireshark.