Hacker News new | ask | show | jobs
by rando444 2604 days ago
For some clients we use tools that alert if large amounts of data are transferred outside the network in a single flow.

So even if it's someone with valid access, it would be investigated immediately.

1 comments

Which tools do you use? I have been looking for something that does this.
In the Marriot hack post-mortem, they shared that one of the tools they used (which successfully identified the attack) was IBM Guardium.

> Accenture told Marriott's IT staff that one of their security products, a database monitoring system called IBM Guardium, had detected an anomaly on the Starwood guest reservation database

https://www.zdnet.com/article/marriott-ceo-shares-post-morte...

I'm guessing snort or one on the similar products.