Description (eng)
Every day, companies and organizations worldwide are exposed to a variety of cyber attacks that pose a
serious threat to the security and integrity of their data. These attacks can come from a variety of sources,
including malware, phishing, ransomware and other sophisticated methods. The consequences of such
attacks can be devastating, ranging from financial loss and reputational damage to legal consequences and
business disruption, and in the face of these increasing threats, the use of a Security Information and Event
Management (SIEM) system is crucial. SIEM enables continuous monitoring, analysis and reaction to
security incidents in real time. By centrally collecting and analyzing security data from various sources,
potential threats can be detected early and responded to appropriately. Given the challenge of selecting the
most suitable solution for specific requirements, open source options were identified and implemented in a
test environment. In addition, an evaluation catalog was developed that includes criteria for the evaluation
of SIEM systems. A comprehensive evaluation of the systems was carried out by creating attack scenarios
and rules for detection.