惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
Vercel News
Vercel News
F
Fortinet All Blogs
月光博客
月光博客
G
Google Developers Blog
博客园 - Franky
GbyAI
GbyAI
The Cloudflare Blog
I
InfoQ
雷峰网
雷峰网
WordPress大学
WordPress大学
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
小众软件
小众软件
腾讯CDC
B
Blog
量子位
V
V2EX
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Monitor your Windows event logs with Datadog Cloud SIEM
2024-10-22 · via Datadog | The Monitor blog

Windows event logs are a key source of important information about your Windows environments, including detailed records of user activities, system performance, and potential security issues. However, with the sheer volume of logs modern environments generate, it can be overwhelming for security teams to efficiently detect, triage, and respond to threats in real time.

Datadog’s Windows event log integration enables you to ingest and process all of these events so you can analyze, generate metrics, and alert on them from a centralized platform. In this post, we’ll explore how you can then use Datadog Cloud SIEM to automatically detect suspicious Windows activity with out-of-the-box (OOTB) threat detection rules and gain an at-a-glance overview of threat activity with enhanced dashboards.

Centralize your Windows event logs

Datadog’s content pack for Windows event logs provides a unified starting point for monitoring your Windows environment by deploying threat detection rules and accessing customizable dashboards. Using the content pack, you can easily enable the integration and begin ingesting event logs. Datadog Log Management’s OOTB log-processing pipeline will automatically normalize and enrich these logs, allowing for efficient searching, and analysis at any scale. You can enrich them further with custom reference data for added context.

Datadog Log Management processes, parses, and enriches your Windows event logs

Detect threats with out-of-the-box detection rules

With threat detection rules, Datadog will continuously scan your Windows event logs for potentially malicious activity as it ingests and processes them. Create your own detection rules or use our built-in rules, which are aligned with the MITRE ATT&CK® framework. Next, we’ll look at some examples of the pre-configured detection rules that our security research team has built.

Detect Windows Domain Admins group changes

Detecting changes to the Windows Domain Admins group is critical for maintaining network security. Unauthorized modifications to this group can signal an attempt at privilege escalation, where an attacker gains elevated permissions to access sensitive systems and data. This detection rule helps organizations maintain a strong security posture, ensuring that any modifications to key administrative groups are legitimate and intentional. This proactive monitoring also assists in compliance efforts, as organizations need to maintain strict control over who has administrative access to their systems.

Detect PsExec execution

Detecting the use of PsExec is essential because it’s a popular tool used by both administrators for legitimate remote execution and also by attackers for lateral movement within compromised networks. PsExec allows execution of processes on remote systems, often without leaving traces, making it a favored tool in sophisticated attacks like ransomware or credential theft campaigns. Our security research team built this detection for teams to monitor for PsExecution and identify malicious use of the tool earlier in the attack chain.

By distinguishing between legitimate administrative use and unauthorized access, this rule offers critical context for security investigations. Early detection helps contain threats, reducing their ability to spread across the network and minimizing potential damage. It also safeguards infrastructure from the misuse of remote execution tools like PsExec. Additionally, this detection aids in post-incident analysis, providing valuable insights into how an attacker moved through your environment—crucial for strengthening defenses and refining response strategies.

In addition to these, other built-in detection rules include:

If Datadog detects any of this activity, it automatically generates a security signal that includes additional context around the issue, as well as actions and remediation steps. These signals are available from a unified explorer, enabling security teams to easily triage and prioritize issues across their environment.

OOTB detection rules alert you to possibly malicious behavior.
OOTB detection rules alert you to possibly malicious behavior.

Visualize and track Windows event logs

Datadog’s customizable OOTB dashboard visualizes your Windows event logs to provide a high-level overview of activity across your environment. Widgets display key information including top lists of most frequent events and most common security, application, and system events along with which hosts are emitting them. For more comprehensive security coverage, Cloud SIEM customers also have access to a visual summary of how many detections Datadog has made within their environment, including a top list of the most critical security signals. You can easily pivot to related security signals in the Signal Explorer to investigate further.

Access a customizable ootb dashboard to monitor Windows event activity.
Access a customizable ootb dashboard to monitor Windows event activity.

Get deeper security visibility into your Windows environment with Datadog Cloud SIEM

Monitoring Windows event logs is critical for identifying potential security threats across your Windows services. With OOTB detection rules and enhanced dashboard visualizations, Datadog Cloud SIEM helps teams get deep security visibility into their event logs so they can easily detect, triage, and respond to threats. Get started today with the Windows event logs content pack.

For more information, you can also view our documentation and get started with the content pack, or read more details on how to Monitor Windows event logs with Datadog. And if you’re not a customer, get started today with a 14-day free trial.