Badges
95 Points
7 Years
User Activity
Over 7 years ago
Commented on The Alerting Module provides real-time event processing language on the logs/packets stream.
I agree, with Alireza's comment. It's always best practice regardless of the SIEM. Traditionally, we've used the Netwitness platform mainly for full packet capture and basic alerting. To make better use as a full SIEM, it's important for others to note that customers need to…
Over 7 years ago
Answered a question: Can I use VPN, firewall and IPS on one device?
Yes, but depends on your appliance. Sourcefire NGFW by itself is not a VPN device. It CAN serve as a traditional/L7 firewall + IPS. If you're using the new Cisco ASA modules + Sourcefire; you can do both but configuration is still separate. If you're looking for smaller…
Over 7 years ago
Answered a question: How to integrate Meraki MX Security appliances with other Switch brands?
It's the same networking stack concepts across. The only difference is Meraki has a GUI and your switches, I guess don't. I'm assuming by integrate you're probably looking at some form of VLAN extending and assigning management IP's, Just ensure everything matches the VLAN…
Projects
Over 7 years ago
Architect Threat Intelligence System for Nationwide Healthcare SystemArchitect Threat Intelligence System for Nationwide Healthcare System sponsored by U.S. Department of Health and Human Services
Over 7 years ago
Automated Self-Defending Network with Splunk, PowerShell, and SSH CertificatesAutomated Self-Defending Network
Answers
Comments
Over 7 years ago
Log Management
About me
Dennis is a multi-industry and seasoned cyber security operations lead. Dennis helps organizations achieve their maximum security potential through hybrid training, sec ops management, engineering, and cross-disciplinary integration. Published, licensed, certified, and above all else, professional. Dennis is also a veteran of the armed forces.