Advanced Incident Response Tools
The incident response tools are vital in enabling organizations to quickly identify and address cyber-attacks, exploits, malware, and other…

Advanced Incident Response Tools
The incident response tools are vital in enabling organizations to quickly identify and address cyber-attacks, exploits, malware, and other internal and external security threats.
AlienVault

AlienVault
AlienVault OSSIM (Open Source Security Information and Event Management) is an open source security information and event management (SIEM) product. A SIEM collects event data from various security logs within the organization, such as those for enterprise security controls, operating systems and applications.
STRENGTHS
- AlienVault offers a variety of integrated security capabilities, including SIEM, file integrity monitoring, vulnerability assessment.

•It provides a well-designed interface for navigating events, assets and threat intelligence for exploring incidents based on the kill chain framework.
•A much lower cost is offered by the AlienVault with security monitoring technologies compared with products from most competitors in the SIEM as per the customer report.
- AlienVault offers a simplified licensing model based on utilized appliances, rather than based on event volume or the number of event sources.

Asset discovery

Asset discovery

Current Top 10 Lists

Threat detection, Behavioural monitoring
Splunk Enterprise A Security Intelligence Platform

Splunk Enterprise collects data from any source, including metrics, logs, clickstreams, sensors, stream network traffic, web servers, custom applications, hypervisors, containers, social media and cloud services.


Splunk App for Enterprise Security

Dashboards and Reports

Incident Investigations & Management

Incident Investigations & Management
Loggly

A log management device where the in-depth logs of the entire organisation can be brought into a particular site where they can be analysed along with the activity track.
It doesn’t require any complex deployment and maintenance strategy and eliminates resource drains and hassles.
It offers scalability and peak overtime protection where peak overtime protection means that the storage space will not run out and the data are not lost.
Loggly integrates with the existing tools and software infrastructure and also implements the best security standards.
It allows to write rules to retrieve logs of the infrastructure and also the alerts are produces on identifying threats.

Dashboard

Log management

Writing rules
GrayLog

Graylog is a fully integrated open source log management platform for collecting, indexing, and analyzing both structured and unstructured data from almost any source
STRENGTHS

•Collect and Process
•Analyze and Search
•Drill-Down and Visualize
•Alert and Trigger
•Several inputs: HTTP, TCP, SYSLOG, AMQP, …
•Classification for Log Messages (Streams)
•User Management and Access Control for the defined streams
•Simple Dashboards created from streams


Kibana

STRENGTHS

•Collect and Process
•Analyze and Search
•Drill-Down and Visualize
•Alert and Trigger
•Analyze Relationships with Graph
•Classification for Log Messages (Streams)
•User Management and Access Control for the defined streams
•Simple Dashboards created from streams
- Machine learning



SolarWinds

STRENGTHS

•SolarWinds LEM has a simple architecture and provides extensive out-of-the-box content suitable for a variety of SMB compliance and security operations use cases.
•The technology is also well-suited for organizations that have invested in other SolarWinds technology solutions, and these integrations can also provide collaborations.
•An automated response capability based on the endpoint agent for Windows provides some threat containment and quarantine control capabilities.
•SolarWinds offers a simplified licensing model based on count of assets and not on their consumption.
- The customers report high levels of satisfaction with LEM as the cost versus features are balanced.

Network Summary View

Current Top 10 Lists
yeti

Yeti is a platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repository. Yeti will also automatically enrich observables (e.g. resolve domains, geolocate IPs) so that you don’t have to. Yeti provides an interface for humans (shiny Bootstrap-based UI) and one for machines (web API) so that your other tools can talk nicely to it.
Yeti was born out of frustration of having to answer the question “where have I seen this artifact before?” or Googling shady domains to tie them to a malware family.
• Submit observables and get a pretty good guess on the nature of the threat.
• Inversely, focus on a threat and quickly list all TTPs, Observables, and associated malware.
• Let responders skip the “Google the artifact” stage of incident response.
• Let analysts focus on adding intelligence rather than worrying about machine-readable export formats.
• Visualize relationship graphs between different threats.
메타데이터
- post_id
- 8a4ec7d82080
- slug
- advanced-incident-response-tools-8a4ec7d82080
- url
- https://medium.com/@tojopthomas/advanced-incident-response-tools-8a4ec7d82080
- canonical_url
- https://medium.com/@tojopthomas/advanced-incident-response-tools-8a4ec7d82080
- author_url
- https://medium.com/@tojopthomas
- status
- ok
- fetched_at
- 2026-08-08 13:46:47