NordRiot Sentinel SIEM
CONTAINMENT
Security Operations
Detection · Intelligence · Behavior · Response · Evidence
Sigma Rules
–
Active IOC
–
Open Cases
–
Endpoint Events
–
Endpoints
–
Ekle / yönet
Endpoint Vault
Recovery secret yalnız aktif admin oturumu + güncel TOTP ile gösterilir.
| Endpoint | OS | Son Görülme |
|---|
Son Endpoint Olayları
| Zaman | Host | Detection | Hedef | Case |
|---|
Security Policy
–
Detections / Sigma
Sigma kurallarını içe aktar, ATT&CK mapping'i gör ve kuralı aktif/pasif yönet.
| Kural | Level | Status | MITRE | Aktif |
|---|
MITRE ATT&CK
Sigma kuralları ve vakalardan görülen tactic/technique mapping.
Techniques
Tactics
Mapping Kaynakları
| Kaynak | Başlık | Mapping |
|---|
Threat Intel / IOC
IP, domain, URL ve hash IOC yönetimi.
| Indicator | Type | Source | Confidence | Expires |
|---|
UEBA
Kullanıcı/host davranış baseline'ları ve istatistiksel sapmalar.
| Entity | Metric | Samples | Mean | StdDev | Last | Updated |
|---|
Case Management
Vakaları aç, ata, durum/severity değiştir ve timeline incele.
| Case | Başlık | Severity | Status | Assignee | MITRE |
|---|
Endpoints
Windows/Linux agent ekle, kayıt kodu üret, bağlantı durumunu gör ve erişimi kapat.
Yeni endpoint için global token gösterilmez. Panel yalnız tek kullanımlık, süreli kayıt kodu üretir.
| Durum | Endpoint | OS | IP | Agent | Son Görülme | Yetki |
|---|
Bekleyen / Son Kayıt Kodları
Kodun kendisi DB'de tutulmaz; yalnız fingerprint saklanır.
| Fingerprint | OS | Endpoint Pin | Oluşturan | Expires | Durum |
|---|
Endpoint File Guard
Dosya yolu, hash, entropy, bağlantı ve hard containment kanıtları.
| Zaman | Endpoint | Detection | Dosya / Hedef | Containment | Case |
|---|
Endpoint Vault
Her endpoint için recovery secret, fingerprint ve agent durumu.
Secret DB'de AES-GCM ile şifrelidir. Görüntüleme TOTP ister ve audit kaydı oluşturur.
| Endpoint | OS | IP | Agent | Son Görülme | Fingerprint |
|---|
Security Policy
Kurulum profili ve merkezi endpoint containment politikası.
–