ManageEngine Enhances Its SIEM With Industry-first, Dual-layered System For Precise And Accurate Threat Detection
SOCs can leverage the dynamic learning capabilities of the company's reinforced TDIR module, Vigil IQ, to optimise threat detection and investigation
- Adopt dual-layer ML for improved automation, correctness and reliability in threat detection
- Smart and dynamic learning enhances threat detection precision by spotting overlooked threats due to manual configurations
- Explore Log360's TDIR module, Vigil IQ: https://mnge.it/lCg
SYDNEY, AUSTRALIA — 30 Nov 2023 — ManageEngine, the enterprise IT management division of Zoho Corporation, today unveiled the industry's first dual-layered threat detection system in its security information and event management (SIEM) solution, Log360. The new feature, available in Log360's threat detection, investigation and response (TDIR) component, Vigil IQ, empowers security operations centre (SOC) teams in organisations with improved accuracy and enhanced precision in threat detection.
A quality SOC ensures people, processes, and cutting-edge technology function well. However, enterprise security is made difficult by staffing shortages and solution orchestration complexities. Following recent upgrades to the security analytics module of Log360 designed to facilitate SOC optimisation through key performance metric monitoring, the company has focused on addressing pressing challenges in security operations.
"In a recent ManageEngine study, a majority of respondents revealed that their SOCs are understaffed. These resource-constrained SOCs grapple with significant obstacles, such as process silos and manual investigation of alerts, which are often non-threats, low-priority issues or false positives. These lead to extended detection and response times for actual threats. To overcome these challenges, we recognise the imperative adoption of AI & ML for contextual event enrichment and rewiring threat detection logic," said Manikandan Thangaraj, vice president at ManageEngine.
"We pioneered a dual-layered, ML approach to heighten the precision and consistency of threat detection. First, Vigil IQ ensures genuine threats are discerned from false positives. Second, the system facilitates targeted threat identification and response. This advanced system significantly improves the accuracy of identifying threats, streamlining the detection process and allowing SOC analysts to focus their valuable time on investigating real threats."
Key Features of the Dual-Layered Threat Detection System of Vigil IQ in Log360
Smart Alerts: Vigil IQ, the TDIR module of Log360, now combines the power of both accuracy and precision in threat detection. With its dynamic learning capability, Vigil IQ adapts to the changing nature of network behaviour to cover more threat instances accurately. It will spot threats that get overlooked due to manual threshold settings, thereby improving the detection system's reliability.
Proactive Predictive Analytics: Leveraging predictive analytics based on historical data patterns, Vigil IQ predicts potential security threats, facilitating the implementation of proactive measures before incidents occur. This predictive intelligence drastically reduces the mean time to detect (MTTD) threats.
Contextual Intelligence: Vigil IQ enriches alerts with deep contextual information, providing security analysts with comprehensive threat insights. This enrichment of alerts with non-event context accelerates the mean time to respond (MTTR) by delivering pertinent, precise information.
Log360 is a unified SIEM solution with integrated DLP and CASB capabilities that detects, prioritises, investigates, and responds to security threats. Vigil IQ, the solution's TDIR module, combines threat intelligence, ML-based anomaly detection and rule-based attack detection techniques to detect sophisticated attacks, and offers an incident management console for effectively remediating detected threats. Log360 provides holistic security visibility across on-premises, cloud, and hybrid networks with its intuitive and advanced security analytics and monitoring capabilities. For more information about Log360, visit manageengine.com/log-management/ and follow the LinkedIn page for regular updates.
ManageEngine is the enterprise IT management division of Zoho Corporation, catering to a wide range of enterprises, MSPs and MSSPs. Established and emerging enterprises—including 9 of every 10 Fortune 100 organisations—rely on ManageEngine's real-time IT management tools to ensure optimal performance of their IT infrastructure, including networks, servers, applications, endpoints and more. ManageEngine has offices worldwide, including in the United States, the United Arab Emirates, the Netherlands, India, Colombia, Mexico, Brazil, Singapore, Japan, China, Australia, and the United Kingdom as well as 200+ global partners to help organisations tightly align their business and IT. For more information, please visit the company site, follow the company blog and get connected on LinkedIn, Facebook, Instagram and Twitter.