Activeboard: Collective Defense Overview
Purpose
Collective Defense is a threat intelligence feed that Devo provides to all of its customers that looks for trending threats across 1000s of customers and enriches them to provide early threat warnings and accelerate investigations. Â
The Collective Defense Activeboard gives an organization wide visualization of the hits against major log sources in an organization against the threat intelligence feed. If no hits are found then no actions are required, if there are hits then further investigation would be required. Â
Users can use the Activeboard as an example to build their own dashboards or add widgets to existing threat intelligence visualizations they have built.Â
Here's how to interpret the results:
If there are no findings, then Congratulations you have no malicious Collective Defense findings in your environment.
If there are findings with no enrichment, then multiple customers are seeing activity from the same source, but open source feeds have not found it to be malicious
If there are findings with enrichments then multiple customers are seeing activity from the same source and they have been found in open sources feeds. These require attention.
Prerequisites
To use this Activeboard, you must have the following data sources available in your domain:
auth.all
learn morefirewall.all.traffic
learn moresiem.logtrust.alert.info
learn moreproxy.all.access
learn moreweb.all.access
learn more
edr.all.threats
learn morecloud.aws.cloudtrail
learn morecloud.office365.management
learn morecloud.gsuite.reports
learn more
Â
Open Activeboard
Once you have installed the Activeboard, you can use the Open button at the top right of the card in Exchange to access it and see the different widgets populated with the relevant data. You can also access the Activeboard area via the Navigation pane.
Data loading takes too long?
Sometimes some widgets take time to upload the data, it is possible to speed up the process by creating aggregation tasks. Refer to the Aggregation tasks article to learn how to do it.
Use Activeboard
After installing and opening the Activeboard, you can use its widgets to visualize and monitor data. To do this, each widget offers a variety of customization and visualization options. Refer to Using widgets and Using inputs to know them all.