Optimizing endpoint detection and monitoring in enterprise solution : a cyber threat intelligence approach

dc.contributor.advisorSeraj, Mehnaz
dc.contributor.authorSarker, Apurba
dc.contributor.authorMondal, Joty Prokash
dc.contributor.authorPran, Suzaur Rashid
dc.contributor.authorIslam, AR Rafiu
dc.date.accessioned2025-06-29T08:45:13Z
dc.date.available2025-06-29T08:45:13Z
dc.date.issued2024-09
dc.descriptionCataloged from PDF version of project report.
dc.descriptionIncludes bibliographical references (pages 53-55).
dc.descriptionThis project report is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science and Engineering, 2024.
dc.description.abstractAdvanced cyber threat intelligence systems are crucial in a time when enterprise solutions are increasing and are being targeted by more sophisticated cyberattacks. This research aims to study ways to improve endpoint detection and monitoring in an enterprise company by installing a Security Information and Event Management (SIEM) system based on Wazuh with integration into ELK Stack. The report performs an inside-out examination of the integration and deployment capability for each technology, focusing on real-time anomaly detection and threat mitigation toolkits at complied states. Together, these techniques create a powerful combination of analytical security, intrusion detection, log data analysis, file integrity monitoring, and vulnerability management capabilities being adopted in a variety of industries that handle sensitive data. This infrastructure uses the Wazuh active response module to detect security threats and look for indications that one is starting up. Denial of Service (DoS), brute-force attacks, simulations, and integrity file delinquencies with tests as proofs tell stories about a good performance estimation when Elasticsearch and FileBeat application is used jointly. Wazuh provides a robust and cost-effective solution for enhancing the security posture of enterprise solutions. Wazuh instantly detects and monitors simulated attacks such as denial-of-service (DoS) attacks by spotting suspicious file changes in real-time, logging failure authentication attempts, and identifying the root source of the flood of requests. This study also provides useful insights on designing and deploying comprehensive cybersecurity solutions with opensource tools such as Wazuh, making visual insights for file integrity monitoring (FIM) in real time.
dc.identifier.otherID 18301256
dc.identifier.otherID 18301146
dc.identifier.otherID 18301223
dc.identifier.otherID 18301298
dc.identifier.otherhttps://dspace.bracu.ac.bd/server/api/core/items/cc2df543-b10f-420d-a895-0f73120f4276
dc.identifier.urihttp://hdl.handle.net/10361/26424
dc.language.isoen
dc.publisherBRAC University
dc.sourceBRAC University Institutional Repository
dc.subjectCyber threat
dc.subjectEvent management
dc.subjectVulnerability management
dc.subjectCost-effective solution
dc.subjectEndpoint detection
dc.subjectOpen-source security
dc.subjectReal-time monitoring
dc.subjectAnomaly detection
dc.titleOptimizing endpoint detection and monitoring in enterprise solution : a cyber threat intelligence approach
dc.typeProject Report

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
18301256,1830114618301223,18301298_CSE.pdf
Size:
3.1 MB
Format:
Adobe Portable Document Format