SIEM solutions
ETC is a unit with strong capacity to deploy SIEM (Security Information and Event Management) systems for large organizations. With practical experience at Vietcombank, VietinBank, EVN, ETC has successfully deployed a large-scale SIEM system, meeting the requirements of 24/7 information security monitoring, supporting SOC operations and complying with legal regulations on information security
MAIN FEATURES OF SIEM SYSTEM
-
Centralized log collection and analysis
The system automatically collects logs from many sources (firewalls, servers, applications, users...) and analyzes to detect abnormalities
-
Early detection of attacks and malicious behavior
Applying AI/ML in user behavior analysis (UEBA), identifying attack behavior by pattern, supporting APT detection
-
Integration with other security solutions
It can connect to IDS/IPS systems, firewalls, endpoints, WAFs, etc., to aggregate data and enhance multi-dimensional detection capabilities
-
Build a dashboard for real-time monitoring and reporting
Intuitive administration interface, flexible alert configuration based on organizational policies
-
Assisting in incident investigation and tracing
Long-term log storage allows for tracing the relationships between events, which is crucial for forensic analysis and auditing