The GIAC
Detecting Malicious Activity in SMB Networks
Pages
24
Time to read
26 mins
Publication
Language
English
Pages
24
Time to read
26 mins
Publication
Language
English
This paper is a technical report that investigates the capabilities of a stand-alone Security Onion device in detecting malicious activity within small and medium-sized business (SMB) networks. It addresses the challenges SMBs face due to budget constraints and limited resources for advanced intrusion detection systems (IDS). The research focuses on using open-source software to enhance security monitoring by analyzing Windows Event Logs. The study outlines the implementation of various tools, including Wazuh and Microsoft Sysmon, to capture and analyze host alert data. It discusses the importance of configuring an appropriate Audit Policy to effectively detect insider threats and the methodologies employed to minimize complexity while ensuring adequate security measures. The paper also details the lab environment set up for testing, including the use of the MITRE ATT&CK framework for mapping attack techniques. Overall, it emphasizes the need for cost-effective solutions that can provide actionable alerts to help SMBs identify and respond to potential breaches in a timely manner.