Blog

Insights, Recommendations, and Opinions

Correlation, Detection, and Alerting in Real-Time for Active Directory

Published on August 19, 2015 by kmaibaum
Imagine how much damage a hacker could do by compromising your Active Directory. Active Directory, which is used by an estimated 95% of Fortune 5000 companies, forms the core services for security and permissions management. It allows IT... Read More

Simple Cross-Device Correlation is No Longer Enough

Published on August 14, 2015 by kmaibaum
In today’s demanding security environment, companies are more than ever challenged to identify serious threats before they lead to a data breach. Using a SIEM tool to correlate security events is a good start, but an effective defense... Read More

The Vulnerability Remediation Challenge

Published on June 10, 2015 by Matthew Lewis
For the past twelve years, Microsoft’s Patch Tuesday has been a monthly reminder of the challenges with vulnerability remediation. For IT and security teams, Patch Tuesday means it's time to assess another batch of security updates and... Read More

Takeaways from the Penn State Security Breach

Published on May 17, 2015 by John Humphreys
An official at Penn State stated, "In fact, on an average day last year, Penn State alone repelled more than 22 million overtly hostile cyber attacks from around the world”. This is an interesting number. However, we would surmise that... Read More

Wire Transfer Scams on the Rise

Published on April 23, 2015 by John Humphreys
While not new, targeted wire transfer scams are alive and well and we recommend that you check your processes to guard against them. These scams start by targeting corporate executives and attempt to convince their targets to wire funds to... Read More

Using SIEM Technology to Streamline HIPAA Compliance

Published on March 23, 2015 by John Humphreys
There are 154 separate risks underlying the HIPAA security standard. Addressing and continually monitoring each of these risks individually can be an enormous task for a security officer. SIEM technology allows most of these risks to be... Read More

Using a SIEM to Detect Cryptolocker Attacks

Published on February 26, 2015 by Bryan Borra
By Bryan Borra As cybercriminals continue to use ransomware as a means for profit such as Cryptolocker and Cryptowall, organizations must develop detection capabilities around this threat. SIEM technology combined with threat intelligence... Read More

Anthem Inc. Security Breach - Healthcare Increasingly Target of Hackers

Published on February 10, 2015 by Proficio
Impact Overview On January 27th, Anthem discovered that the login information for database administrators had been compromised. The investigation is ongoing, but the data breach could affect up to 80 million Anthem customers. Information... Read More

Proficio 2015 Security Summit

Published on February 05, 2015 by Proficio
Proficio will hold its annual Security Summit on March 19th and 20th in Napa, California this year. Participants will discuss the practical challenges of meeting their security goals and hear from industry experts. George Kurtz, President... Read More

Sandworm - Microsoft Windows Zero-day Vulnerability

Published on October 15, 2014 by Proficio
What is it? CVE-2014-4114 (aka “Sandworm”): A zero-day vulnerability that allows an attacker to remotely execute arbitrary code. Who is vulnerable? Sandworm is a zero-day impacting all versions of Microsoft Windows from Vista SP2 up to... Read More