SlideShare a Scribd company logo
1 of 22
Download to read offline
The Journey
from
Zero to SOCAugust 2020
Sean Lengyel
Head of Cyber Security
About ME
- 12 years experience in IT &
Cyber Security
- 10 years in the Australian
Department of Defence
- Royal Australian Air Force
Veteran
- Built Citadel’s SOC from the
ground up
About Us
3
text
Text
© Citadel Group | Journey from Zero to SOC |
Health Solutions
Keeping People &
Information SafeEnterprise Solutions Technology Services
Professional Services
About Us – Security Operations
4© Citadel Group | Journey from Zero to SOC |
Where does the
Citadel SOC fit in?
About Us – Mission
5© Citadel Group | Journey from Zero to SOC |
Protect Customer Data
M
FA
TrustedDevice
About Us – Zero Trust
6© Citadel Group | Journey from Zero to SOC |
MFATrustedDevice
M
FA
Trusted Device
M
FAAny Device
MFA
Trusted Device
MFA
Trusted Device
Credential Manager
Launcher
Tenable.io
ASD Essential Eight
InTune MDM
Citadel SOE
Windows 10
MFAAny Device Elastic Endgame
Elastic Beats
Web Proxy Agents
MSCT/CIS Hardening
ASD Essential Eight
MFA
Any Device
MFA
Any Device
Any Device
Locked down
GooglePlay Store
Device Hardening
InTune MDM
Locked down
Apple App Store
Device Hardening
InTune MDM
Apple IOS Android
MFA
Trusted Device
Customer
Environments
Where did Our
logging Journey start?
Where did our logging journey start?
Some of the problems we faced…
9© Citadel Group | Journey from Zero to SOC |
• Existing solution didn’t offer native SIEM capabilities
• SIEM capabilities were an expensive add-on
• Very expensive to ingest the all the logs we needed
• The licencing model meant that it would have made it
very costly to ingest the following logs:
- Windows Sysmon Events (Security & Observability)
- Windows Perfmon Events (Observability)
- Azure SQL Database Audit Events (Security)
- Azure NSG Firewall Events (Security)
- Endpoint Protection Agent Logs (Security)
- Azure Diagnostics (Observability)
The positives…
10© Citadel Group | Journey from Zero to SOC |
I was very lucky to be working with some very security conscious
Developers, Cloud Engineers & Application Specialists
Why Elastic?
Why Elastic?
12© Citadel Group | Journey from Zero to SOC |
Cost: Perfect for a growing organisation
Security Features: Great out of the box features that a SOC needs
Observability: Allows us to met our service operations needs
Scalability: The SOC can easily grow as the company grows
Machine Learning: Detecting outliers without needing complicated rules
Customisation: Building alerts tailored to our environments
Fast forward to Today
Where are we now?
14© Citadel Group | Journey from Zero to SOC |
Where are we now?
15© Citadel Group | Journey from Zero to SOC |
ü Windows 10 Endpoint Logs
ü Azure AD Audit & Sign-in Logs
ü Azure Resources Audit Logs
ü SaaS Cloud Application Logs
ü Windows Customer Server Logs
ü Linux Customer Server Logs
ü SQL Database Audit Logs
ü On-prem & Cloud-based Firewall Logs
ü Web Application Firewall Logs
ü Office365 ATP Logs
ü MS Defender ATP Logs
ü Elastic Endgame Logs
SIEM Signals
16© Citadel Group | Journey from Zero to SOC |
SIEM Signals
17© Citadel Group | Journey from Zero to SOC |
Custom SIEM Signal
18© Citadel Group | Journey from Zero to SOC |
Elastic Endgame
19© Citadel Group | Journey from Zero to SOC |
Elastic Endgame – Custom Rule
20© Citadel Group | Journey from Zero to SOC |
Final Thoughts
21© Citadel Group | Journey from Zero to SOC |
We are in a good place now
Thank you!
sean.lengyel@citadelgroup.com.au

More Related Content

What's hot

What's hot (20)

Building Elastic into security operations
Building Elastic into security operationsBuilding Elastic into security operations
Building Elastic into security operations
 
October 2020 meetup
October 2020 meetupOctober 2020 meetup
October 2020 meetup
 
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructureCisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
Cisco Connect 2018 Singapore - Next generation hyperconverged infrastructure
 
Cisco Connect 2018 Singapore - Cisco Incident Response Services
Cisco Connect 2018 Singapore - Cisco Incident Response ServicesCisco Connect 2018 Singapore - Cisco Incident Response Services
Cisco Connect 2018 Singapore - Cisco Incident Response Services
 
Conferencia principal: Evolución y visión de Elastic Security
Conferencia principal: Evolución y visión de Elastic SecurityConferencia principal: Evolución y visión de Elastic Security
Conferencia principal: Evolución y visión de Elastic Security
 
Keynote: Elastic Security evolution and vision
Keynote: Elastic Security evolution and visionKeynote: Elastic Security evolution and vision
Keynote: Elastic Security evolution and vision
 
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
 
Cisco Connect 2018 Singapore - Cybersecurity strategy
Cisco Connect 2018 Singapore - Cybersecurity strategy  Cisco Connect 2018 Singapore - Cybersecurity strategy
Cisco Connect 2018 Singapore - Cybersecurity strategy
 
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
Cisco Connect 2018 Singapore - Secure data center building a secure zero trus...
 
Palestra de abertura: Evolução e visão do Elastic Security
Palestra de abertura: Evolução e visão do Elastic SecurityPalestra de abertura: Evolução e visão do Elastic Security
Palestra de abertura: Evolução e visão do Elastic Security
 
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud WorldCisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
Cisco Connect 2018 Singapore - Transforming Enterprises in a Multi-Cloud World
 
Tirez pleinement parti d'Elastic grâce à Elastic Cloud
Tirez pleinement parti d'Elastic grâce à Elastic CloudTirez pleinement parti d'Elastic grâce à Elastic Cloud
Tirez pleinement parti d'Elastic grâce à Elastic Cloud
 
Cisco Connect 2018 Singapore - Do more than keep the lights on
Cisco Connect 2018 Singapore - Do more than keep the lights onCisco Connect 2018 Singapore - Do more than keep the lights on
Cisco Connect 2018 Singapore - Do more than keep the lights on
 
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
Cisco Connect 2018 Singapore -  Data center transformation a customer perspec...Cisco Connect 2018 Singapore -  Data center transformation a customer perspec...
Cisco Connect 2018 Singapore - Data center transformation a customer perspec...
 
Cisco Connect 2018 Singapore - delivering intent for data center networking
Cisco Connect 2018 Singapore -   delivering intent for data center networkingCisco Connect 2018 Singapore -   delivering intent for data center networking
Cisco Connect 2018 Singapore - delivering intent for data center networking
 
Cisco Connect 2018 Singapore - Cisco CMX
Cisco Connect 2018 Singapore - Cisco CMXCisco Connect 2018 Singapore - Cisco CMX
Cisco Connect 2018 Singapore - Cisco CMX
 
Managing Compliance in Container Environments
Managing Compliance in Container EnvironmentsManaging Compliance in Container Environments
Managing Compliance in Container Environments
 
Elastic Security: Proteção Empresarial construída sobre o Elastic Stack
Elastic Security: Proteção Empresarial construída sobre o Elastic StackElastic Security: Proteção Empresarial construída sobre o Elastic Stack
Elastic Security: Proteção Empresarial construída sobre o Elastic Stack
 
Keynote: Looping through data, insight, and action
Keynote: Looping through data, insight, and actionKeynote: Looping through data, insight, and action
Keynote: Looping through data, insight, and action
 
Secure Data Sharing in OpenShift Environments
Secure Data Sharing in OpenShift EnvironmentsSecure Data Sharing in OpenShift Environments
Secure Data Sharing in OpenShift Environments
 

Similar to The Journey from Zero to SOC: How Citadel built its Security Operations from the Ground Up on Elastic

Smart & Secure City Solutions by Rupinder Singh
Smart & Secure City Solutions by Rupinder SinghSmart & Secure City Solutions by Rupinder Singh
Smart & Secure City Solutions by Rupinder Singh
IPPAI
 

Similar to The Journey from Zero to SOC: How Citadel built its Security Operations from the Ground Up on Elastic (20)

Cloud Security by CK
Cloud Security by CKCloud Security by CK
Cloud Security by CK
 
智慧市政大未來 主題一
智慧市政大未來 主題一智慧市政大未來 主題一
智慧市政大未來 主題一
 
IoT World Forum Press Conference - 10.14.2014
IoT World Forum Press Conference - 10.14.2014IoT World Forum Press Conference - 10.14.2014
IoT World Forum Press Conference - 10.14.2014
 
Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
MT81 Keys to Successful Enterprise IoT Initiatives
MT81 Keys to Successful Enterprise IoT InitiativesMT81 Keys to Successful Enterprise IoT Initiatives
MT81 Keys to Successful Enterprise IoT Initiatives
 
IoT Security: Problems, Challenges and Solutions
IoT Security: Problems, Challenges and SolutionsIoT Security: Problems, Challenges and Solutions
IoT Security: Problems, Challenges and Solutions
 
SwitchIT-02.2018-Company-overview.pptx
SwitchIT-02.2018-Company-overview.pptxSwitchIT-02.2018-Company-overview.pptx
SwitchIT-02.2018-Company-overview.pptx
 
Softwide Security Company Introduction 2024
Softwide Security Company Introduction 2024Softwide Security Company Introduction 2024
Softwide Security Company Introduction 2024
 
Tomorrow Starts Here - Security Everywhere
Tomorrow Starts Here - Security Everywhere Tomorrow Starts Here - Security Everywhere
Tomorrow Starts Here - Security Everywhere
 
I Syed, Sr. Consultant - Enterprise Information Security Governance, Risk, Co...
I Syed, Sr. Consultant - Enterprise Information Security Governance, Risk, Co...I Syed, Sr. Consultant - Enterprise Information Security Governance, Risk, Co...
I Syed, Sr. Consultant - Enterprise Information Security Governance, Risk, Co...
 
2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar
 
Emc World Keynote Mirchandani
Emc World Keynote MirchandaniEmc World Keynote Mirchandani
Emc World Keynote Mirchandani
 
MILCOM 2013 Keynote Presentation: Larry Payne
MILCOM 2013 Keynote Presentation: Larry Payne MILCOM 2013 Keynote Presentation: Larry Payne
MILCOM 2013 Keynote Presentation: Larry Payne
 
Cloud technology for hospitality
Cloud technology for hospitalityCloud technology for hospitality
Cloud technology for hospitality
 
SAMSUNG SDS.pdf
SAMSUNG SDS.pdfSAMSUNG SDS.pdf
SAMSUNG SDS.pdf
 
Digital Transformation in a World of Connected Devices
Digital Transformation in a World of Connected DevicesDigital Transformation in a World of Connected Devices
Digital Transformation in a World of Connected Devices
 
Smart & Secure City Solutions by Rupinder Singh
Smart & Secure City Solutions by Rupinder SinghSmart & Secure City Solutions by Rupinder Singh
Smart & Secure City Solutions by Rupinder Singh
 
Sutedjo - open banking may 27, 2021
Sutedjo - open banking may 27, 2021Sutedjo - open banking may 27, 2021
Sutedjo - open banking may 27, 2021
 
#ITSitioEnRSA - Presentacion de Jeef Reed de Cisco
#ITSitioEnRSA - Presentacion de Jeef Reed de Cisco #ITSitioEnRSA - Presentacion de Jeef Reed de Cisco
#ITSitioEnRSA - Presentacion de Jeef Reed de Cisco
 

More from Elasticsearch

More from Elasticsearch (20)

An introduction to Elasticsearch's advanced relevance ranking toolbox
An introduction to Elasticsearch's advanced relevance ranking toolboxAn introduction to Elasticsearch's advanced relevance ranking toolbox
An introduction to Elasticsearch's advanced relevance ranking toolbox
 
From MSP to MSSP using Elastic
From MSP to MSSP using ElasticFrom MSP to MSSP using Elastic
From MSP to MSSP using Elastic
 
Cómo crear excelentes experiencias de búsqueda en sitios web
Cómo crear excelentes experiencias de búsqueda en sitios webCómo crear excelentes experiencias de búsqueda en sitios web
Cómo crear excelentes experiencias de búsqueda en sitios web
 
Te damos la bienvenida a una nueva forma de realizar búsquedas
Te damos la bienvenida a una nueva forma de realizar búsquedas Te damos la bienvenida a una nueva forma de realizar búsquedas
Te damos la bienvenida a una nueva forma de realizar búsquedas
 
Comment transformer vos données en informations exploitables
Comment transformer vos données en informations exploitablesComment transformer vos données en informations exploitables
Comment transformer vos données en informations exploitables
 
Plongez au cœur de la recherche dans tous ses états.
Plongez au cœur de la recherche dans tous ses états.Plongez au cœur de la recherche dans tous ses états.
Plongez au cœur de la recherche dans tous ses états.
 
Modernising One Legal Se@rch with Elastic Enterprise Search [Customer Story]
Modernising One Legal Se@rch with Elastic Enterprise Search [Customer Story]Modernising One Legal Se@rch with Elastic Enterprise Search [Customer Story]
Modernising One Legal Se@rch with Elastic Enterprise Search [Customer Story]
 
An introduction to Elasticsearch's advanced relevance ranking toolbox
An introduction to Elasticsearch's advanced relevance ranking toolboxAn introduction to Elasticsearch's advanced relevance ranking toolbox
An introduction to Elasticsearch's advanced relevance ranking toolbox
 
Welcome to a new state of find
Welcome to a new state of findWelcome to a new state of find
Welcome to a new state of find
 
Building great website search experiences
Building great website search experiencesBuilding great website search experiences
Building great website search experiences
 
Keynote: Harnessing the power of Elasticsearch for simplified search
Keynote: Harnessing the power of Elasticsearch for simplified searchKeynote: Harnessing the power of Elasticsearch for simplified search
Keynote: Harnessing the power of Elasticsearch for simplified search
 
Cómo transformar los datos en análisis con los que tomar decisiones
Cómo transformar los datos en análisis con los que tomar decisionesCómo transformar los datos en análisis con los que tomar decisiones
Cómo transformar los datos en análisis con los que tomar decisiones
 
Explore relève les défis Big Data avec Elastic Cloud
Explore relève les défis Big Data avec Elastic Cloud Explore relève les défis Big Data avec Elastic Cloud
Explore relève les défis Big Data avec Elastic Cloud
 
Comment transformer vos données en informations exploitables
Comment transformer vos données en informations exploitablesComment transformer vos données en informations exploitables
Comment transformer vos données en informations exploitables
 
Transforming data into actionable insights
Transforming data into actionable insightsTransforming data into actionable insights
Transforming data into actionable insights
 
Opening Keynote: Why Elastic?
Opening Keynote: Why Elastic?Opening Keynote: Why Elastic?
Opening Keynote: Why Elastic?
 
Empowering agencies using Elastic as a Service inside Government
Empowering agencies using Elastic as a Service inside GovernmentEmpowering agencies using Elastic as a Service inside Government
Empowering agencies using Elastic as a Service inside Government
 
The opportunities and challenges of data for public good
The opportunities and challenges of data for public goodThe opportunities and challenges of data for public good
The opportunities and challenges of data for public good
 
Enterprise search and unstructured data with CGI and Elastic
Enterprise search and unstructured data with CGI and ElasticEnterprise search and unstructured data with CGI and Elastic
Enterprise search and unstructured data with CGI and Elastic
 
What's new at Elastic: Update on major initiatives and releases
What's new at Elastic: Update on major initiatives and releasesWhat's new at Elastic: Update on major initiatives and releases
What's new at Elastic: Update on major initiatives and releases
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 

The Journey from Zero to SOC: How Citadel built its Security Operations from the Ground Up on Elastic

  • 1. The Journey from Zero to SOCAugust 2020 Sean Lengyel Head of Cyber Security
  • 2. About ME - 12 years experience in IT & Cyber Security - 10 years in the Australian Department of Defence - Royal Australian Air Force Veteran - Built Citadel’s SOC from the ground up
  • 3. About Us 3 text Text © Citadel Group | Journey from Zero to SOC | Health Solutions Keeping People & Information SafeEnterprise Solutions Technology Services Professional Services
  • 4. About Us – Security Operations 4© Citadel Group | Journey from Zero to SOC | Where does the Citadel SOC fit in?
  • 5. About Us – Mission 5© Citadel Group | Journey from Zero to SOC | Protect Customer Data
  • 6. M FA TrustedDevice About Us – Zero Trust 6© Citadel Group | Journey from Zero to SOC | MFATrustedDevice M FA Trusted Device M FAAny Device MFA Trusted Device MFA Trusted Device Credential Manager Launcher Tenable.io ASD Essential Eight InTune MDM Citadel SOE Windows 10 MFAAny Device Elastic Endgame Elastic Beats Web Proxy Agents MSCT/CIS Hardening ASD Essential Eight MFA Any Device MFA Any Device Any Device Locked down GooglePlay Store Device Hardening InTune MDM Locked down Apple App Store Device Hardening InTune MDM Apple IOS Android MFA Trusted Device Customer Environments
  • 7. Where did Our logging Journey start?
  • 8. Where did our logging journey start?
  • 9. Some of the problems we faced… 9© Citadel Group | Journey from Zero to SOC | • Existing solution didn’t offer native SIEM capabilities • SIEM capabilities were an expensive add-on • Very expensive to ingest the all the logs we needed • The licencing model meant that it would have made it very costly to ingest the following logs: - Windows Sysmon Events (Security & Observability) - Windows Perfmon Events (Observability) - Azure SQL Database Audit Events (Security) - Azure NSG Firewall Events (Security) - Endpoint Protection Agent Logs (Security) - Azure Diagnostics (Observability)
  • 10. The positives… 10© Citadel Group | Journey from Zero to SOC | I was very lucky to be working with some very security conscious Developers, Cloud Engineers & Application Specialists
  • 12. Why Elastic? 12© Citadel Group | Journey from Zero to SOC | Cost: Perfect for a growing organisation Security Features: Great out of the box features that a SOC needs Observability: Allows us to met our service operations needs Scalability: The SOC can easily grow as the company grows Machine Learning: Detecting outliers without needing complicated rules Customisation: Building alerts tailored to our environments
  • 14. Where are we now? 14© Citadel Group | Journey from Zero to SOC |
  • 15. Where are we now? 15© Citadel Group | Journey from Zero to SOC | ü Windows 10 Endpoint Logs ü Azure AD Audit & Sign-in Logs ü Azure Resources Audit Logs ü SaaS Cloud Application Logs ü Windows Customer Server Logs ü Linux Customer Server Logs ü SQL Database Audit Logs ü On-prem & Cloud-based Firewall Logs ü Web Application Firewall Logs ü Office365 ATP Logs ü MS Defender ATP Logs ü Elastic Endgame Logs
  • 16. SIEM Signals 16© Citadel Group | Journey from Zero to SOC |
  • 17. SIEM Signals 17© Citadel Group | Journey from Zero to SOC |
  • 18. Custom SIEM Signal 18© Citadel Group | Journey from Zero to SOC |
  • 19. Elastic Endgame 19© Citadel Group | Journey from Zero to SOC |
  • 20. Elastic Endgame – Custom Rule 20© Citadel Group | Journey from Zero to SOC |
  • 21. Final Thoughts 21© Citadel Group | Journey from Zero to SOC | We are in a good place now