ACSC, CISA, FBI and NSA Unite for New Event Logging and Threat Detection Guide
ID: afe7c5cb-a5f1-55c1-8015-0f3a5161073a
STIX ID: report--afe7c5cb-a5f1-55c1-8015-0f3a5161073a
Feed Name: The Cyber Express
A coalition of cybersecurity authorities (ACSC, CISA, FBI, NSA, and global partners) released a guidance on establishing robust event logging and detection to counter LOTL and fileless threats. It recommends enterprise-wide logging policies, high-quality and comprehensive log collection (Windows, Linux, and OT), centralized and structured storage with secure transport (TLS 1.3) and access controls, timely ingestion, and the use of behavior analytics and MITRE ATT&CK for detection. The guide emphasizes balancing OT performance with logging needs, optimizing platforms for analysis, and maintaining retention and reassessment practices to improve detection, response, and resilience.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
