Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

ManageEngine: Detecting Suspicious Software Installations with Log360

Manage Engine
07/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


with Log360. Unauthorized software installations are extremely suspicious events that require the system administrator's attention. This is because attackers often trick users into downloading malicious software onto their systems, which can then aid the attacker in launching an attack. Here's why detecting and containing unauthorized suspicious software installations is critical. Suspicious software installations are often used for multiple malicious goals. They can serve as a medium for malware that can launch and propagate large-scale attacks like ransomware in the network. They can also be used to exfiltrate data or cause system and server crashes. This is usually the case with malicious software that propagates DDoS attacks in the network. This software makes it difficult for the organization's employees and clients to access critical services and information that lead to business interruption. Furthermore, malicious software can also give an attacker full access and control over a system and can aid the attacker in wreaking havoc on the network. Here are some common attack vectors for suspicious software to infiltrate the network. Attackers in suspicious software can enter a network through phishing or social engineering tactics where users are tricked into installing remote access software. This software grants attackers control over the user's device. Alternatively, if an attacker has already gained access to the network, they might directly install the malicious software. To conceal their activities and avoid detection, attackers often use a VPN to mask their IP address. This VPN helps them evade network monitoring and security measures while they deploy the malicious software or manage their remote access tools. Users might also fall for fake pop-ups or notifications claiming that their software is out of date and needs an update. Clicking on this can lead to the installation of malware. Sometimes, malicious insiders can plug in an infected USB drive to install malicious software on the device automatically. Also, malware can be bundled with legitimate software. When the software is downloaded and installed, the malware gets installed along with it. Drive-by downloads trick users into visiting a compromised website, resulting in malicious software being downloaded and installed without the user's knowledge. Attackers could go about installing unauthorized software on devices through multiple ways. One way could be attackers may first attempt to access an organization's network remotely through a VPN. They often use automated tools to brute force their way into the VPN, gaining entry to the entire network. Once inside, the attacker targets user or device accounts seeking out weaknesses and vulnerabilities. They may employ brute force techniques or credential theft methods to log on to the devices. After successfully gaining access, the attackers may take a remote session on other machines before they proceed to install malicious software on the compromised devices. Let's see how Log360 detects suspicious software installations. Once you log into the solution, you can navigate to the SIM module or the Event Logged Analyzer module and then to the Correlation tab at the top. On the left, you can view all pre-defined correlation reports. In the search bar, you can look for the suspicious software installations report. This shows you all instances of suspicious software installations on the network. We will come back to examine this information in more detail in just a moment. Let's first understand how Log360 detected this threat. Log360 comes with pre-defined rules which look for a set of events that occur sequentially and indicate a possible threat. To understand how this rule is configured, navigate to Manage Rule and look for the name of the rule in the search bar. This pulls up the pre-configured detection rule to detect software installations. By clicking on Copy Correlation Rule, you can view how this rule is configured. As you can see, the rule is triggered when the following actions take place in a sequence. There are five failed logons within 10 minutes to connect to the network through the VPN by a particular user account on a particular device. This is followed by the same user account successfully logging into the same device through the VPN within the next two minutes. Within another short duration of 15 minutes, there is a logon registered on a Windows device from the same user account and the private IP address associated with the VPN login. If within the next 30 minutes, the user and device associated with the previous actions performs a software installation, the whole series of actions is treated as a suspicious and will need further investigation. We can now return to the pre-built report in NOC 360. Here you can view all events where suspicious software installations happened. Clicking on Event Timeline allows you to view the series of software installations. By clicking on Details, you can refer to the message field to understand additional details about the software that was installed. This will provide some insight into what the attacker was trying to do on the network. Now, here are some next steps to take if you notice suspicious software installations. Check if the suspicious software has spread to other devices or systems in the network. Disconnect the affected device from the network to prevent further spread of the malware and to protect other systems. You can use LOB360 SOAR capabilities to automate the disabling of affected user accounts and devices. Use network security tools to block any communication to and from known malicious IP addresses or domains associated with the suspicious software. Restore the affected device to a clean state, either from a known good backup or by performing a clean operating system installation if necessary. After removal, continue monitoring the device and network for any signs of residue issues or infection. Thank you for watching this video. For further queries, you can send us an email at log360-support at manageengine.com. You can also download a free version of a solution at the link provided. At no cost and zero risk, you can try LOG360 in your environment for 30 days.

TL;DR

  • Log360 uses pre-configured correlation rules to detect suspicious software installations by identifying attack patterns like repeated failed VPN logins followed by successful access and software installation within specific timeframes.
  • Unauthorized software installations pose critical risks including ransomware propagation, data exfiltration, DDoS attacks, and complete system compromise, making early detection essential for preventing business disruption.
  • Common attack vectors include phishing campaigns, social engineering tactics, drive-by downloads, malware bundled with legitimate software, and infected USB drives that trick users into installing malicious applications.
  • When suspicious installations are detected, recommended response steps include isolating affected devices, blocking malicious IP addresses, disabling compromised accounts through SOAR automation, and restoring systems from clean backups.

Why Unauthorized Software Detection Matters

This demonstration explains how ManageEngine's Log360 detects suspicious software installations that could indicate a security breach. Unauthorized software installations represent a critical security risk because attackers frequently trick users into downloading malicious applications that serve as entry points for larger attacks. These installations can facilitate ransomware propagation, enable data exfiltration, cause system crashes through DDoS attacks, or grant attackers complete control over compromised systems. The video emphasizes that detecting these installations early is essential for preventing business interruption and protecting critical services from compromise.

Attack Vectors and Detection Methodology

The presentation outlines common attack vectors including phishing campaigns that trick users into installing remote access tools, drive-by downloads from compromised websites, malware bundled with legitimate software, and infected USB drives. Log360 detects suspicious installations through pre-configured correlation rules that identify attack patterns: five failed VPN login attempts within 10 minutes, followed by a successful VPN login within two minutes, then a Windows logon from the VPN-associated IP address within 15 minutes, and finally a software installation within the next 30 minutes. This sequential pattern triggers an alert for investigation. The solution provides detailed event timelines and message fields that reveal what software was installed and help security teams understand the attacker's objectives and respond appropriately.

Chapters

0:00 - Introduction to Threat Detection
0:31 - Why Detection Is Critical
1:15 - Common Attack Vectors
2:40 - Attack Progression Methods
3:22 - Log360 Detection Capabilities
3:54 - Correlation Rule Configuration
6:00 - Response and Remediation Steps

Key Quotes

0:10 "Unauthorized software installations are extremely suspicious events that require the system administrator's attention. This is because attackers often trick users into downloading malicious software onto their systems, which can then aid the attacker in launching an attack."
0:37 "Suspicious software installations are often used for multiple malicious goals. They can serve as a medium for malware that can launch and propagate large-scale attacks like ransomware in the network."
1:43 "To conceal their activities and avoid detection, attackers often use a VPN to mask their IP address. This VPN helps them evade network monitoring and security measures while they deploy the malicious software or manage their remote access tools."
4:36 "The rule is triggered when the following actions take place in a sequence. There are five failed logons within 10 minutes to connect to the network through the VPN by a particular user account on a particular device. This is followed by the same user account successfully logging into the same device through the VPN within the next two minutes."

FAQ

How does Log360 differentiate between legitimate and suspicious software installations?

Log360 uses correlation rules that analyze the sequence of events leading to a software installation. When an installation is preceded by suspicious patterns like multiple failed VPN login attempts, successful authentication from an unusual location, and rapid progression through the network, the system flags it for investigation. The solution examines the context and timing of events rather than just the installation itself.

What immediate actions should be taken when Log360 detects a suspicious software installation?

First, disconnect the affected device from the network to prevent malware spread. Use Log360's SOAR capabilities to automatically disable compromised user accounts and devices. Block communication to malicious IP addresses or domains associated with the suspicious software. Check if the malware has spread to other systems, then restore affected devices from clean backups or perform fresh OS installations. Continue monitoring for residual issues after remediation.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • How-To
  • Technical Deep Dive
  • Suspicious software detection
  • Unauthorized software installations
  • VPN brute force attacks
  • Correlation rules
  • Malware detection
  • SIEM event correlation
  • Incident response automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: ManageEngine: Detecting Suspicious Software Installations with Log360

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance: Safeguarding App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-safeguarding-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version