← Back to Blog
CiberseguridadHerramientas

ALIEN VAULT, Open Source SIEM for Incident Response

ALIEN VAULT, Open Source SIEM for Incident Response

Alien Vault is an open-source security information and event management tool for real-time threat detection. According to ethical hacking specialists at the International Institute of Cyber Security, Alien Vault is used in hundreds of organizations to monitor websites, databases, data centers, servers, desktops, applications, and other information devices for suspicious activity in the environment in real time.

  • SIEM is a combination of two different types of technologies:
    • Security Information Management (SIM): Log collection and report generation
    • Security Event Manager (SEM): Real-time event analysis and event correlation
  • This application has the best features such as event collection, event normalization, and event correlation
    • Event Collection: this option is used to collect logs from information devices such as servers, firewalls, and routers in our environment
    • Event Normalization: this option extracts all log data files and stores them in folders containing all information such as IP address, hostname, usernames, ports, etc.
    • Event Correlation: this option is used to correlate all commonly collected events gathered from the environment

Installation

  • Download the OSSIM ISO from here
  • Here, choose OSSIM (Open Source Security Information Management) and press ENTER

OSSIM Installation Screen 1

  • Choose your preferred language and click continue

OSSIM Installation Screen 2

  • Choose your country and click continue

OSSIM Installation Screen 3

  • Choose the keyboard layout to use and click continue

OSSIM Installation Screen 4

  • Assign an IP address to this machine

 OSSIM Installation Screen 5

  • Set a password for root. After that, the tool will begin installing, according to ethical hacking experts

OSSIM Installation Screen 6

  • If installed correctly, we will be able to see this screen on our machine

OSSIM Installation Screen 7

  • Here, type login as root and password. Then open this URL in the browser https:/// for the web interface

OSSIM login screen

  • Now, enter a few details to create an account to access Alien Vault products

OSSIM login screen

  • Next, type the username and password to log in, then we will be able to see the following screen

OSSIM welcome page

  • Follow the steps to monitor the network, discover assets, collect logs, and monitor assets. Click the start option to launch Alien Vault OSSIM

OSSIM wizard

  • Follow the steps shown on the screen and click Register Now to create an OTX (Open Threat Exchange) account and log in to view all activity on our LAN (Local Area Network)

  • Here, we can see all activity

CONCLUSION

This tool can be used in your organization to monitor all websites, databases, data centers, servers, desktops, applications, and other information devices for threat detection and incident response in the environment in real time, according to ethical hacking experts.

Comments

No comments yet. Be the first to share your thoughts.

Leave a Comment

Comments are reviewed before publishing.