Skip to content

SIEM

SIEM and incident detection sized for an SME

A traditional SIEM feeds on raw logs and needs weeks of tuning before it says anything useful. In an SME, the person who ought to read its alerts is often the one answering the phone as well. The FirstSI SIEM starts from data the other modules have already sorted, and presents complete incidents: what happened, on which machine, with which account, and in what order.

Open-access demo, no sign-up: 138 fictional machines and all twelve modules.

SIEM — open incidents

EXFILTRATION? 1,240 files read on the HR share, then 2.3 GB sent to a hosting provider

CAMPAIGN 46 accounts tried on the VPN from the same address range

DNS a computer is querying a domain known for phishing

CLOSED account locked this morning: a phone with the old password

Why it stays readable

correlation

Rules that cut across modules

Mass access to files followed by an outbound flow abroad, an account locked just after attempts on the VPN: the rules connect what the files, flows, firewall, DNS and directory each see.

incident

One incident, one story

Each incident groups its events in order, with the machine, the account and the address. You read a ten-line timeline, and the thousands of original events are one click away.

campaigns

Grouped attacks

Password spraying from a single address range or hosting provider becomes one incident. Each locked account opens its own, naming the real origin of the lockout.

dns

Early warning signs

Malicious domains, DNS tunnels, suspicious-looking names: a compromise often shows up first in DNS queries, sometimes hours before anything else.

tuning

You set the noise level

Maintenance windows, per-rule thresholds, exceptions approved once and for all. You decide what is worth waking you up for, and FirstSI sticks to it.

alerts

Alerted wherever you are

Console, email or webhook to your ticketing tool or team chat. The AI assistant can pick up the incident and write the report.

In the console

Screens from the live demo, with the data of a fictional company.

SIEM dashboard: open, critical and resolved incidents, their trend over time and their breakdown by severity. SIEM dashboard: open, critical and resolved incidents, their trend over time and their breakdown by severity.
The SIEM at a glance: how many incidents, how serious, since when. Demo data.
List of correlated security incidents with their severity, status and response-time tracking. List of correlated security incidents with their severity, status and response-time tracking.
Correlated incidents, from the most serious down. Demo data.

Tuesday, 6:12 pm

One last busy evening before the holidays

An employee is going on leave the next day. At 6:12 pm, his account reads 1,240 files on the HR share in six minutes, a folder he never normally opens. At 6:20 pm, his computer sends 2.3 GB to an online storage service.

Taken one at a time, these events say very little: people read files all day long and send attachments. Put together, they match exactly what the exfiltration rule is looking for. The alert arrives at 6:21 pm, with the list of files, the volume sent and the destination.

The next day, the IT team has everything it needs to raise the matter with HR, audit trail included, without having to piece anything back together.

SIEM — incident timeline

18:12 FILES reading begins on the HR share

18:18 FILES 1,240 files read in six minutes, unusual for this account

18:20 FLOWS 2.3 GB outbound to an online storage service

18:21 INCIDENT probable exfiltration, alert sent

How it works

1

The modules collect

Each module sorts its own events: files, flows, DNS, firewall, authentications. The SIEM starts from data that is already clean.

2

The rules join the dots

Ready-made cross-module rules that you can adjust. An event that arrives late from a site that was cut off still gets matched.

3

You handle an incident

An incident with its timeline, its evidence and its status. You assign it, comment on it and close it, and everything stays on record.

Frequently asked questions

Do I need a security team to use this SIEM?

No, it was designed to work without one. The rules are supplied and incidents read like a timeline. IT teams of two or three people use it every day.

Can I send my firewall logs to it?

Yes. The site agent receives logs and flows from firewalls and gateways, then forwards them encrypted. There is no port to open to the outside.

How long are events kept?

You choose, from 1 to 365 days, with 90 by default. File and DNS events are archived before deletion.

Can I write my own rules?

Yes, from the console, with no programming. You can also adjust the thresholds of the supplied rules and declare exceptions.

Does it work with an external SOC?

Yes. Incidents go out by webhook or through the API to your provider's tool, and every access is logged.

More questions about installation, hosting, GDPR or integrations? All frequently asked questions

Incidents you have time to read

Open the demo: correlated incidents are waiting for you there, across 138 fictional machines. Or request a guided demonstration.