Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

AlienVault Installation and Configuration

11/26/2020

0 Comments

 
AlienVault Installation and Configuration

 AlienVault® OSSIM™, Open Source Security Information and Event Management (SIEM), is an open source SIEM solution to collect, normalize and correlate security events. Open Source SIEM (AlienVault OSSIM) addresses this reality by providing one unified platform with many of the essential security capabilities such as:

  • Asset discovery
  • Vulnerability assessment
  • Intrusion detection
  • Behavioral monitoring
  • SIEM event correlation

AlienVault OSSIM leverages the power of the AlienVault® Open Threat Exchange® (OTX™) by allowing users to both contribute and receive real-time information about malicious hosts.

AlienVault provides another commercial software with more advanced functionality, AlienVault USM Anywhere™, which provides unified essential security controls and continuous threat intelligence to IT security teams with limited resources. AlienVault USM Anywhere offers:

  • Centralized threat detection and incident response across cloud environments, on-premises infrastructure, and cloud apps
  • Log management for continuous compliance and forensics investigations
  • Advanced threat detection with real-time, prioritized alarms and minimal false positives
  • Continuous threat intelligence updates from AlienVault Labs Security Research team so you always stay up to date with emerging threats
  • Pre-built compliance reports for PCI DSS, HIPAA, NIST CSF, and more

In this post, the procedures for downloading, installing, and configuration OSSIM have been recorded and listed below:


Download

Download URL: https://ift.tt/3m7LWDF

Or direct download URL: https://ift.tt/2grcZcE

It is about 728 MB file. 

Installation

It can be installed into Hyper-V or VMWare environment. Both are working well. It needs at least 4G RAM to run it well. If you have more, that would be better. If you would like to monitor network traffic using stap or SPAN port, you will need to add one more network interface. 







After you set up network static ip configuration, network mask, gateway, name server, system will install all basic core components and software. It will take 30 minutes to an hour to get it completed depends on how fast is your system.



Configuration


After installation completed, you will get a log in URL in console:



First time to access AlienVault, you will have to set up admin user information including password and email. After that, the password for admin will be used to log in web GUI. Same password for root will be used to log in from command line. 




It will prompt you a AlienVault OSSIM Getting Started Wizard from Web GUI once you used admin account logged in.

You can have multiple interfaces for different purposes such as management, Network Monitoring, Log Collection & Scanning. 






You can have an option to deploy HIDS to servers found from previous asset scans. It supports windows and linux.

If there is any network devices found in asset scanning, we can enable data source plugin for each device. 


Last step is to join OTX , Open Threat Exchange , the world's first truly open threat intelligence community. You will need a OTX key to sign in.


After registered a free account in https://ift.tt/1JrYz5k, you will get a free OTX key to connect your AlienVault OSSIM to OTX. 


Dashboard:






YouTube Videos

Install AT&T Alien Vault OSSIM in VMWare Workstation


Basic Configuration for Alien Vault OSSIM Integrating with Sophos UTM





References














via Blogger https://ift.tt/3mbCe2X
November 25, 2020 at 10:40PM SIEM
0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org