Fortinet FortiProxy
FortiProxy is a web proxy that protects clients against internet threats. In this documentation, we will explain one way to collect and send FortiProxy logs to Sekoia.io.
Fortinet FortiMail
Fortinet cybersecurity solutions sell physical products such as firewalls, plus software and services such as anti-virus protection, intrusion prevention systems, and endpoint security components.
Microsoft Entra ID - playbooks
Microsoft Entra ID (Azure AD) is an enterprise identity service that provides single sign-on, multifactor authentication, and conditional access to guard against 99.9 percent of cybersecurity attacks.
Azure Front Door
Microsoft Azure Front Door is a scalable and secure entry point for fast delivery of your global web applications.
AWS WAF
AWS WAF is a web application firewall that lets you monitor the HTTP(S) requests that are forwarded to your protected web application resources.
Elastic Auditbeat Linux
Auditbeat communicates directly with the Linux audit framework, collects the same data as auditd, then the data can be stored in JSON inside a log file before being sent to a log concentrator.
Apache SpamAssassin
SpamAssassin is a computer program used for e-mail spam filtering.
AWS VPC Flow Logs
Amazon VPC Flow Logs is a feature that provides the ability to capture information about IP network traffic as it enters or exits from network interface in your Amazon VPC (Amazon Virtual Private Cloud).
Forcepoint Management Server
The Management Server is the central component for system administration.
CEF
ArcSight's Common Event Format (CEF) is an open log management standard.
Bind
BIND is an implementation of the Domain Name System (DNS) of the Internet.
BinaryEdge
BinaryEdge is Cybersecurity/Data Science company that focuses its effort on acquiring, analyzing and classifying internet wide data.
Azure Windows
Azure Virtual Machines service is developed and managed by Microsoft Corp.
Azure Network Watcher (NSG Flow Logs)
Azure Network Watcher provides tools to monitor, diagnose, view metrics, and enable or disable logs for resources in an Azure virtual network.
AWS S3
AWS is a one of the main cloud provider, supported by Amazon.
Tenable Identity Exposure / Alsid
Tenable Identity Exposure / Alsid is an automated security solution that monitors the components of Active Directory infrastructures by detecting attacks in real time, identifying existing weaknesses and vulnerabilities.
Apache HTTP Server
The Apache HTTP Server, colloquially called Apache, is free and open-source cross-platform web server software, released under the terms of Apache License 2.
Anomali ThreatStream
Sekoia's CTI feed is available in Anomali's market place, in the Threat Intelligence Feeds category.