LOG CORRELATION ENGINE
Corrlation, Alerts and Automated Response
Powerfull Correlation Engine
The SGBox correlation engine allows you to interconnect a series of events chains coming from single or multiple sources, analyzing the values collected such as: timestamp, IP address, User names, etc …
Predefined Rules Set
It is possible to choose correlation rules from many predefined templates, constantly updated and guaranteed by the experience of our Security Engineers.
SGBox can be interoperable with SOAR solutions (Security Operation Automation Response ) to feed those platform providing meaningful information.
SGBox can engage automated response in case of threats by launching scripts or interacting with security components via API or APPs to mitigate theats.