• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    weekly roundup

    The Cyber Express Weekly Roundup: EU AI Act Updates, Malware Expansion, Critical Vulnerabilities, and Rising Cybercrime Trends

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    Dirty Frag

    Dirty Frag Linux Vulnerability Exposes Major Distributions to Root Access Attacks

    EU AI Act

    Europe Moves to Tighten AI Rules While Easing Compliance Burden

    QLearn Cybersecurity Incident

    Global Instructure Breach Hits Queensland Schools Through QLearn Platform

    Operation Epic Fury

    Operation Epic Fury Exposes Critical OT Security Gaps in U.S. Oil and Gas Sector

    Salesforce AMPScript

    Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    Claude AI, Antropic, AI, Artificial Intelligence

    U.S. Will Now Examine National Security Implications of New AI Models, Pre-Release

    U.S. Government Sues TikTok, TikTok

    UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

    vulnerability patch wave

    NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface

    APRA AI risk warning

    Australia’s APRA Issues AI Risk Warning to Banks and Insurers

    Norway social media age limit

    Norway to Introduce Social Media Age Limit of 16, Platforms to Enforce Verification

    Facial Recognition Policy

    High Court Backs UK Police Use of Live Facial Recognition Technology

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    weekly roundup

    The Cyber Express Weekly Roundup: EU AI Act Updates, Malware Expansion, Critical Vulnerabilities, and Rising Cybercrime Trends

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    Dirty Frag

    Dirty Frag Linux Vulnerability Exposes Major Distributions to Root Access Attacks

    EU AI Act

    Europe Moves to Tighten AI Rules While Easing Compliance Burden

    QLearn Cybersecurity Incident

    Global Instructure Breach Hits Queensland Schools Through QLearn Platform

    Operation Epic Fury

    Operation Epic Fury Exposes Critical OT Security Gaps in U.S. Oil and Gas Sector

    Salesforce AMPScript

    Salesforce Marketing Cloud Vulnerabilities Expose Cross-Tenant Subscriber Data Risks

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    Claude AI, Antropic, AI, Artificial Intelligence

    U.S. Will Now Examine National Security Implications of New AI Models, Pre-Release

    U.S. Government Sues TikTok, TikTok

    UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

    vulnerability patch wave

    NCSC Warns Organisations to Act Fast as Hidden Software Flaws Surface

    APRA AI risk warning

    Australia’s APRA Issues AI Risk Warning to Banks and Insurers

    Norway social media age limit

    Norway to Introduce Social Media Age Limit of 16, Platforms to Enforce Verification

    Facial Recognition Policy

    High Court Backs UK Police Use of Live Facial Recognition Technology

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

ACSC, CISA, FBI and NSA Unite for New Event Logging and Threat Detection Guide

Ashish Khaitan by Ashish Khaitan
August 22, 2024
in Firewall Daily, Cyber News
0
Best Practices for Event Logging and Threat Detection
684
SHARES
3.8k
VIEWS
Share on LinkedInShare on Twitter

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the United States Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and several international partners released a new guide titled “Best Practices for Event Logging and Threat Detection,” which aims to help organizations establish a robust baseline for event logging to counteract the rise of malicious cyber threats.

According to CISA, the prevalence of sophisticated attacks such as Living Off the Land (LOTL) techniques and fileless malware highlights the critical need for effective event logging. LOTL techniques involve using existing tools and processes within the system to carry out malicious activities, making them particularly challenging to detect. To address these threats, the newly released guide focuses on enhancing event logging strategies and threat detection capabilities.

Importance of Event Logging and Threat Detection

Event logging is essential for maintaining operational continuity and enhancing the security and resilience of critical systems. By improving network visibility through comprehensive event logging, organizations can better identify and respond to potential security incidents, including those involving LOTL techniques. The “Best Practices for Event Logging and Threat Detection” guide, crafted through a collaborative effort of prominent global cybersecurity agencies, outlines essential strategies for enhancing event logging practices. 

This guide was developed by key organizations, including CISA, FBI, and NSA from the United States; the National Cyber Security Centre (NCSC-UK) from the United Kingdom; the Canadian Centre for Cyber Security (CCCS); New Zealand’s National Cyber Security Centre (NCSC-NZ) and CERT NZ; Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) and JPCERT/CC; South Korea’s National Intelligence Services (NIS) and NIS’s National Cyber Security Center (NCSC-Korea); Singapore’s Cyber Security Agency (CSA); and the Netherlands’ General Intelligence and Security Service (AIVD) and Military Intelligence and Security Service (MIVD).

The guide highlights several key objectives for effective event-logging solutions. It advocates for generating alerts for significant cybersecurity events, such as critical software changes or new deployments, to aid network defenders. It also stresses the importance of detecting potential incidents, including those involving Living Off the Land (LOTL) techniques and lateral movements within networks. 

Additionally, the guide highlights the need for effective incident response by providing detailed insights into compromises, ensuring policy compliance, managing alerts to reduce noise and associated costs, and optimizing logs and logging platforms for enhanced usability and analytical performance.

report-ad-banner

Best Practices for Event Logging and Threat Detection

Effective event logging and threat detection are crucial for safeguarding organizational systems against cyber threats. Implementing best practices in these areas can significantly enhance an organization’s ability to detect and respond to malicious activities. 

Several key practices are essential for effective event logging and threat detection. First, developing a comprehensive enterprise-approved event logging policy is crucial for maintaining consistent and effective monitoring. This policy should clearly define the types of events to be logged, the facilities and methods for logging, and the procedures for monitoring these logs. It should also specify how long logs will be retained and establish regular intervals for reassessing and updating logging practices. A well-structured policy ensures that logging is thorough and uniform across the organization, which is vital for detecting and responding to security threats.

Additionally, focusing on the quality of event logs is essential for accurate threat detection. High-quality logs capture relevant and actionable data, helping to distinguish true positives from false positives. For example, on Linux-based systems, logs should include common Living Off the Land (LOTL) binaries such as curl and systemctl, while on Windows systems, logs should cover tools like wmic.exe and PowerShell. High-quality logging improves the ability to detect subtle indicators of LOTL techniques and other sophisticated attacks.

Event logs should also capture comprehensive details to support effective threat detection and incident response. According to the US Office of Management and Budget’s M-21-31 guidelines, logs should include accurate timestamps, event types, device identifiers, source and destination IP addresses, status codes, response times, user IDs, and executed commands. Detailed logs provide a thorough view of system activities, which is crucial for identifying and analyzing potential security incidents.

For Operational Technology (OT) environments, which often involve devices with limited logging capabilities, it is important to supplement logging with additional sensors or methods. Organizations should balance the volume of logged data with the performance constraints of OT devices, ensuring that critical events are captured without negatively impacting device functionality.

Centralizing event logs from various systems facilitates better analysis and correlation. Employing structured log formats and maintaining consistent timestamping streamline log management, enabling more efficient data analysis and improving overall threat detection and response.

Securing the storage and integrity of event logs is critical to prevent unauthorized access and tampering. Organizations should implement secure storage solutions and use robust transport mechanisms like Transport Layer Security (TLS) 1.3 to protect logs both in transit and at rest. Access to logs should be restricted to authorized personnel only, with measures in place to prevent unauthorized modifications or deletions.

Timely ingestion of event logs is essential for early detection and response to cybersecurity events. Delays in log generation, collection, or ingestion can hinder the ability to identify and address security incidents promptly. Ensuring logs are ingested and analyzed promptly helps detect potential threats before they escalate.

Lastly, developing a detection strategy for relevant threats by implementing user and entity behavior analytics can enhance threat detection. Comparing event logs against a baseline of normal behavior helps identify deviations that may indicate malicious activity. This approach is particularly useful for detecting anomalies and LOTL techniques, which often involve sophisticated methods to evade traditional security measures.

Additional Resources and Recommendations

Organizations seeking further guidance can refer to several valuable resources. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) Information Security Manual (ISM) provides detailed recommendations on event log recording. CISA’s Guidance for Implementing M-21-31 offers insights on prioritizing log collection, while NIST’s Guide to OT Security outlines specific considerations for OT event logging. 

For detection strategies, the MITRE ATT&CK framework offers useful use cases. Regularly reviewing and optimizing log storage capacities and retention periods is also recommended to support ongoing cybersecurity investigations and improve overall security posture.

The “Best Practices for Event Logging and Threat Detection” guide represents a crucial step towards enhancing organizational cybersecurity. By following the recommended practices, organizations can improve their ability to detect and respond to cyber threats, including sophisticated LOTL techniques. Implementing these practices will not only help in mitigating current threats but also in building a more resilient cybersecurity posture for the future.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: ACSCBest Practices for Event Logging and Threat DetectionCISAEvent Logging and Threat DetectionFBINSAThe Cyber ExpressThe Cyber Express News
Previous Post

Equiniti Trust Company Settles with SEC Over $6.6 Million Cybersecurity Failures

Next Post

Fidelity Bank Data Breach: Nigerian Bank Denies Allegations, Contests ₦555.8 Million Fine

Next Post
Fidelity Bank data breach

Fidelity Bank Data Breach: Nigerian Bank Denies Allegations, Contests ₦555.8 Million Fine

Sectoral Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

National Technology Day 2026
Cyber News

National Technology Day 2026: India’s AI Growth Puts Security in Focus

May 11, 2026
California Privacy Settlement
Cyber News

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

May 11, 2026
weekly roundup
Cyber News

The Cyber Express Weekly Roundup: EU AI Act Updates, Malware Expansion, Critical Vulnerabilities, and Rising Cybercrime Trends

May 8, 2026
Online Safety Act
Firewall Daily

Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

May 8, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information