Home
News
Tech Grid
Data & Analytics
Data Processing Data Management Analytics Data Infrastructure Data Integration & ETL Data Governance & Quality Business Intelligence DataOps Data Lakes & Warehouses Data Quality Data Engineering Big Data
Enterprise Tech
Digital Transformation Enterprise Solutions Collaboration & Communication Low-Code/No-Code Automation IT Compliance & Governance Innovation Enterprise AI Data Management HR
Cybersecurity
Risk & Compliance Data Security Identity & Access Management Application Security Threat Detection & Incident Response Threat Intelligence AI Cloud Security Network Security Endpoint Security Edge AI
AI
Ethical AI Agentic AI Enterprise AI AI Assistants Innovation Generative AI Computer Vision Deep Learning Machine Learning Robotics & Automation LLMs Document Intelligence Business Intelligence Low-Code/No-Code Edge AI Automation NLP AI Cloud
Cloud
Cloud AI Cloud Migration Cloud Security Cloud Native Hybrid & Multicloud Cloud Architecture Edge Computing
IT & Networking
IT Automation Network Monitoring & Management IT Support & Service Management IT Infrastructure & Ops IT Compliance & Governance Hardware & Devices Virtualization End-User Computing Storage & Backup
Human Resource Technology Agentic AI Robotics & Automation Innovation Enterprise AI AI Assistants Enterprise Solutions Generative AI Regulatory & Compliance Network Security Collaboration & Communication Business Intelligence Leadership Artificial Intelligence Cloud
Finance
Insurance Investment Banking Financial Services Security Payments & Wallets Decentralized Finance Blockchain Cryptocurrency
HR
Talent Acquisition Workforce Management AI HCM HR Cloud Learning & Development Payroll & Benefits HR Analytics HR Automation Employee Experience Employee Wellness Remote Work Cybersecurity
Marketing
AI Customer Engagement Advertising Email Marketing CRM Customer Experience Data Management Sales Content Management Marketing Automation Digital Marketing Supply Chain Management Communications Business Intelligence Digital Experience SEO/SEM Digital Transformation Marketing Cloud Content Marketing E-commerce
Consumer Tech
Smart Home Technology Home Appliances Consumer Health AI
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Threat Intelligence

ManageEngine Enhances Log360 with Reengineered Threat Detection


ManageEngine Enhances Log360 with Reengineered Threat Detection
  • by: Source Logo
  • |
  • September 17, 2025

ManageEngine, a division of Zoho Corporation and a leading provider of enterprise IT management solutions, has strengthened its unified security platform Log360 with a reengineered threat detection approach. This major enhancement addresses the challenges faced by modern security operations center (SOC) teams, filtering out irrelevant alerts to enable faster triage and reduce analyst burnout in environments overwhelmed by data noise.

Quick Intel

  • ManageEngine reengineers Log360 threat detection to reduce alert fatigue.
  • Over 60% of SOC teams overwhelmed by irrelevant threat data.
  • Features 1,500+ prebuilt rules mapped to MITRE ATT&CK and SIGMA.
  • Includes centralized detection console and object-level rule filters.
  • Supports multi-tier architecture for enterprise scalability.
  • ECSO 911 reports 90% reduction in false positives during beta testing.

Addressing SOC Challenges with Advanced Detection

Over 60% of SOC teams struggle with irrelevant threat data, with 53% of cloud security alerts classified as noise according to the 2025 Threat Intelligence Benchmark study. ManageEngine's latest Log360 release tackles this by introducing a unified detection console that consolidates MITRE ATT&CK-aligned rules, correlation logic, user and entity behavior analytics (UEBA) insights, and threat intelligence feeds. Security teams can create standard, anomaly-based, or advanced detection rules via an interactive UI without complex queries. Object-level filters for Active Directory users, groups, and OUs ensure continuous monitoring of high-value identities while suppressing low-priority alerts, allowing analysts to prioritize genuine threats effectively.

Leadership Insights on Efficiency Gains

Manikandan Thangaraj, vice president at ManageEngine, explained the strategic focus: “The biggest challenge for security teams today isn’t collecting data—it’s separating genuine signals from overwhelming noise. We've reengineered our detection system to not just build more complex rules, but to deliver true efficiency and empower SOC with flexible, granular rule-tuning capabilities that go beyond simple thresholds. With this advancement, SOC analysts can filter out benign noise without sacrificing the ability to catch a true compromise. This shifts our focus to a targeted pursuit of genuine threats—ensuring we're effectively protecting and not just monitoring twenty-four seven.” This approach enhances signal quality, reduces false positives, and supports scalable operations as log volumes increase.

Cloud-Delivered Content and Scalability Features

Log360 now includes over 1,500 prebuilt detection rules covering privilege escalation, lateral movement, endpoint tampering, and SaaS attacks, curated by ManageEngine's threat research team for accuracy and low false positives. These rules, including SIGMA-based detections, are delivered via cloud updates to keep coverage current. The multi-tier enterprise architecture features log processor clusters, role-based processing for correlation, enrichment, and alerting, and centralized multi-site collection, ensuring resilience and performance in large, distributed environments. This foundation supports horizontal scalability to meet growing enterprise demands.

Real-World Validation from ECSO 911

Early beta testing by Emergency Communications of Southern Oregon (ECSO) 911, a Log360 customer serving Jackson County and Crater Lake National Park, demonstrated significant improvements. Corey Nelson, IT manager at ECSO 911, stated: “For a 911 emergency communications center, security is the foundation of public trust—and any failure has immediate, real-world consequences. The latest advanced detection capabilities are not optional—they are essential. With Log360's optimized detection rules and filtering techniques, we have reduced false or low-priority alerts by 90%, allowing our analysts to focus on the threats that matter most. This improvement has significantly accelerated our ability to identify and respond to real cyber incidents.” This validation highlights Log360's practical impact on threat detection-to-response cycles.

ManageEngine's enhancements to Log360 position it as a robust unified SIEM solution with integrated DLP and CASB capabilities, providing holistic visibility across on-premises, cloud, and hybrid environments. By prioritizing high-value signals and enabling efficient scaling, Log360 empowers SOC teams to protect enterprises more effectively, fostering resilience against evolving cyber threats while maintaining compliance and performance.

About Log360

Log360 is a unified SIEM solution with integrated DLP and CASB capabilities that detects, prioritizes, investigates, and responds to security threats. Vigil IQ, the solution's TDIR module, combines threat intelligence, an analytical Incident Workbench, ML-based anomaly detection, and rule-based attack detection techniques to detect sophisticated attacks, and it offers an incident management console for effective remediation. With reengineered detection—including a centralized detection console, multi-mode rule creation, tuning insights, and object-level filters—Log360 elevates signal quality and reduces false positives. The solution provides holistic visibility across on-premises, cloud, and hybrid environments with intuitive security analytics and monitoring. For more information about Log360, visit manageengine.com/log-management/ and follow the LinkedIn page for regular updates.

About ManageEngine

ManageEngine is a division of Zoho Corporation and a leading provider of IT management solutions for organizations across the world. With a powerful, flexible, and AI-powered digital enterprise management platform, we help businesses get their work done from anywhere and everywhere—better, safer, and faster.

  • Manage EngineLog360SIEMThreat DetectionCybersecurity
News Disclaimer
  • Share