Indicator of Attacks Detected with SureLog SIEM

Ertugrul Akbas
1 min readJan 12, 2020

--

In an article for DarkReading [1], Ericka Chickowski highlights 15 key indicators of compromise:

  • Unusual Outbound Network Traffic
  • Anomalies in Privileged User Account Activity
  • Geographical Irregularities
  • Log-In Red Flags
  • Increases in Database Read Volume
  • HTML Response Sizes
  • Large Numbers of Requests for the Same File
  • Mismatched Port-Application Traffic
  • Suspicious Registry or System File Changes
  • Unusual DNS Requests
  • Unexpected Patching of Systems
  • Mobile Device Profile Changes
  • Bundles of Data in the Wrong Place
  • Web Traffic with Unhuman Behavior
  • Signs of DDoS Activity

References

  1. https://www.darkreading.com/attacks-breaches/top-15-indicators-of-compromise/d/d-id/1140647

--

--

Ertugrul Akbas
Ertugrul Akbas

Written by Ertugrul Akbas

Entrepreneur,Security Analyst,Research.

No responses yet