SYDNEY, AUSTRALIA โ 30 Nov 2023 โย ManageEngine, the enterprise IT management division of Zoho Corporation, today unveiled the industry’s first dual-layered threat detection system in its security information and event management (SIEM) solution, Log360. The new feature, available in Log360’s threat detection, investigation and response (TDIR) component, Vigil IQ, empowers security operations centre (SOC) teams in organisations with improved accuracy and enhanced precision in threat detection.
A quality SOC ensures people, processes, and cutting-edgeย technology function well. However, enterprise security is made difficult by staffing shortages and solution orchestration complexities. Following recent upgrades to the security analytics module of Log360ย designed to facilitate SOC optimisation through key performance metric monitoring, the company has focused on addressing pressing challenges in security operations.
“In a recent ManageEngine study, a majority of respondents revealed that their SOCs are understaffed. These resource-constrained SOCs grapple with significant obstacles, such asย process silos and manual investigation of alerts, which are often non-threats, low-priority issues or false positives. These lead to extended detection and response times for actual threats. To overcome these challenges, we recognise the imperative adoption of AI & ML for contextual event enrichment and rewiring threat detection logic,” said Manikandan Thangaraj, vice president at ManageEngine.
“We pioneered a dual-layered,ย MLย approach to heighten the precision and consistency of threat detection.ย First, Vigil IQ ensures genuine threats are discerned from false positives. Second, the system facilitates targeted threat identification and response.ย This advanced system significantly improves the accuracy of identifying threats, streamlining the detection process and allowing SOC analysts to focus their valuable time on investigating real threats.”
Key Features of the Dual-Layered Threat Detection System of Vigilย IQ in Log360
Smart Alerts: Vigil IQ, the TDIR module of Log360, now combines the power of both accuracy and precision in threat detection. With its dynamic learning capability, Vigil IQ adapts to the changing nature of network behaviour to cover more threat instances accurately. It will spot threats that get overlooked due to manual threshold settings, thereby improving the detection system’s reliability.
Proactive Predictive Analytics: Leveraging predictive analytics based on historical data patterns, Vigil IQ predicts potential security threats, facilitating the implementation of proactive measures before incidents occur. This predictive intelligence drastically reduces the mean time to detect (MTTD) threats.
Contextual Intelligence:ย Vigil IQ enriches alerts with deep contextual information, providing security analysts with comprehensive threat insights. This enrichment of alerts with non-event context accelerates the mean time to respond (MTTR) by delivering pertinent, precise information.
About Log360
Log360 is a unified SIEM solution with integrated DLP and CASB capabilities that detects, prioritises, investigates, and responds to security threats. Vigil IQ, the solution’s TDIR module, combines threat intelligence, ML-based anomaly detection and rule-based attack detection techniques to detect sophisticated attacks, and offers an incident management console for effectively remediating detected threats. Log360 provides holistic security visibility across on-premises, cloud, and hybrid networks with its intuitive and advanced security analytics and monitoring capabilities. For more information about Log360, visit manageengine.com/log-management/ and follow the LinkedIn page for regular updates.
About ManageEngine
ManageEngine is the enterprise IT management division of Zoho Corporation, catering to a wide range of enterprises, MSPs and MSSPs. Established and emerging enterprisesโincluding 9 of every 10 Fortune 100 organisationsโrely on ManageEngine’s real-time IT management tools to ensure optimal performance of their IT infrastructure, including networks, servers, applications, endpoints and more. ManageEngine has offices worldwide, including in the United States, the United Arab Emirates, the Netherlands, India, Colombia, Mexico, Brazil, Singapore, Japan, China, Australia, and the United Kingdom as well as 200+ global partners to help organisations tightly align their business and IT. For more information, please visit the company site, follow the company blog and get connected on LinkedIn, Facebook, Instagram and Twitter.
- Adopt dual-layer ML for improved automation, correctness and reliability in threat detection
- Smart and dynamic learning enhances threat detection precision by spotting overlooked threats due to manual configurations
- Explore Log360’s TDIR module, Vigil IQ: https://mnge.it/lCg