ManageEngine reengineers threat detection for unified security platform
ManageEngine, a division of Zoho Corporation and a provider of enterprise IT management solutions, has strengthened its security information and event management (SIEM) solution, Log360 with a reengineered threat detection approach.
Over 60% of modern-day security operations centre (SOC) teams are overwhelmed with irrelevant threat data, of which a majority (53%) of cloud security alerts can be considered noise, according to the 2025 Threat Intelligence Benchmark study commissioned by Google. ManageEngine's latest release bolsters Log360’s position as a unified security platform by filtering out the noise caused by a deluge of security alerts, thereby enabling faster triage and reducing burnout issues faced by security analysts.
“The biggest challenge for security teams today isn’t collecting data—it’s separating genuine signals from overwhelming noise,” said Manikandan Thangaraj, VP at ManageEngine.
"We’ve reengineered our detection system to not just build more complex rules, but to deliver true efficiency and empower (the) SOC with flexible, granular rule-tuning capabilities that go beyond simple thresholds. With this advancement, SOC analysts can filter out benign noise without sacrificing the ability to catch a true compromise. This shifts our focus to a targeted pursuit of genuine threats—ensuring we’re effectively protecting and not just monitoring twenty-four seven."
The new capabilities include a centralised detection console, object-level rule filters, and over 1,500 prebuilt detection rules that are continuously delivered and updated from the cloud. This upgrade also lays the foundation for enterprise-grade scalability—with a multi-tier architecture, role-specialised log processing, and centralised multisite collection—ensuring performance and resilience as data sources and log volumes grow.
Feature highlights include:
- A unified detection console that consolidates all detection content, including MITRE ATT&CK-aligned rules, correlation logic, user and entity behaviour analytics (UEBA) insights, and threat intelligence feeds—into a single pane of glass.
- Security teams can create standard, anomaly-based, or advanced detection rules through an interactive user interface (UI), without writing complex queries. Object-level filters across Active Directory users, groups, and organisational units (OUs) ensure that high-value identities are continuously monitored while suppressing low-priority noise.
- Cloud-delivered content: More than 1,500 prebuilt rules cover a wide range of use cases from privilege escalation and lateral movement to endpoint tampering and software-as-a-service (SaaS) attacks. These rules are researched, curated, and tested by ManageEngine’s in-house threat research team to ensure accuracy and low false positives, and are delivered through a cloud-based update mechanism so users always stay current.
SIGMA-based detection rules are also included in the package.
- Multi-tier enterprise architecture: Log360’s architecture enhancements enable horizontal scalability with log processor clusters and role-based processing (correlation, enrichment, alerting)—as well as centralised collection from distributed sites—ensuring performance continuity even in large, geographically distributed enterprises.
Log360 is a unified SIEM solution with integrated data loss prevention (DLP) and cloud access security broker (CASB) capabilities that detects, prioritises, investigates, and responds to security threats. The solution provides holistic visibility across on-premises, cloud, and
hybrid environments with intuitive security analytics and monitoring.
Vigil IQ, the solution’s threat detection, investigation and response (TDIR) module, combines threat intelligence, an analytical Incident Workbench, machine learning-based anomaly detection, and rule-based attack detection techniques to detect sophisticated attacks.
Comments
Post a Comment