Detection of Counter-Forensic Incidents Using Security Information and Incident Management (SIEM) Systems

Mustafa Çağrı Fanuscu, Aynur Koçak, Mustafa Alkan · 2022

Cyber criminals can use many different methods to completely lose their traces after their actions or to complicate the work of forensic experts. Detection of such suspected anti-forensic activities can guide the detection of cyber crimes that have been experienced but not yet detected. One of the tools that can be used for this purpose is SIEM (Security Information and Event Management) systems. With proper configuration and management, these systems facilitate the work of security analysts in attack detection and incident response stages. In addition, it facilitates the discovery of evidence after a cybercrime and reduces evidence collection times. In this study, logs and log collection methods that can be produced by systems that are likely to be found in an enterprise infrastructure were examined. It has been researched how to detect sample anti-forensics attack types with the help of a selected SIEM application and the results are shown on a created use case template.

Read the paper · More papers on PaperTik