Log Management and Analysis

Log collection and log analysis

Learning Outcome

4

Explain its use in SOC and threat detection.

3

Describe the Threat Intelligence Lifecycle.

2

Identify common Threat Intelligence sources.

1

Explain the purpose of Threat Intelligence.

5

Apply Threat Intelligence to improve security and defense.

Before a festival, police receive information that a group of thieves may target crowded markets. They learn who the thieves are, where they may attack, and how they usually operate.

Information about threats = Threat Intelligence

Using this information, the police increase patrols and closely monitor the areas that may be targeted.

Preparing defenses based on intelligence = Threat-Informed Defense

During the festival, officers watch for activities that match the information they received and investigate anything suspicious.

Identifying attacker activity = Threat Detection

Because the police already understand the possible threat, they can respond quickly and prevent or reduce the impact of a crime.

Taking action against the threat = Incident Response

In cybersecurity, Threat Intelligence provides information about attackers, their tactics, techniques, indicators, and emerging threats. Security teams use this information to strengthen defenses, improve detection, and respond more effectively.

Introduction to Logs

Logs are records of system, application, user, network, and security activities. They provide details about what happened, when, where, and who performed the action.

    Importance

Detect cyberattacks

Investigate incidents

Monitor user activity

Identify system errors

Meet compliance requirements

Logs help organizations:

Goals of Incident Response

Identify incidents

Minimize disruption

Contain and eliminate threats

Recover systems

Preserve evidence

Prevent future incidents

Security Incident

A security incident is an event that threatens the confidentiality, integrity, or availability of systems or data.

Examples:

Malware,           phishing,           unauthorized access.

Event vs Alert vs Incident

Security Event: Observable activity, such as login or file access.

Security Alert: Notification of suspicious activity.

Security Event: Observable activity, such as login or file access.

Common Security Incidents

Malware

Phishing

Unauthorized access

Insider threats

Data breaches

DoS attacks

Need for Incident Response

Reducing Business Impact

Security incidents can interrupt business operations and affect productivity.

Faster Recovery

Organizations with established response procedures can restore affected systems more efficiently.

Protecting Sensitive Data

Incidents involving customer records, financial information, or intellectual property can have serious consequences.

Regulatory and Compliance Requirements

An effective response process helps organizations meet compliance obligations and demonstrate due diligence.

Incident Response Lifecycle

Preparation

Prepare people, processes, plans, teams, policies, and tools such as SIEM, EDR, and forensic tools.

Detection & Analysis

Identify suspicious activity

Classify incidents

Classify incidents

Categorize threats

Investigate affected systems

Containment

Limit the incident using short-term and long-term controls and isolate affected systems.

Eradication

Remove malware

 

Eliminate attacker access

 

Fix vulnerabilities

Recovery

Restore affected systems

 

Monitor for recurrence

 

Resume normal operations

Lessons Learned

Review the incident

 

Perform root cause analysis

 

Update security controls

 

Improve response procedures

Incident Classification

Unauthorized Access

Access to systems, applications, or data by unauthorized individuals.

1

Malware Infection

Incidents involving viruses, ransomware, spyware, or other malicious software.

2

Phishing

Attempts to deceive users into revealing credentials or sensitive information.

3

Insider Threat

Security incidents caused by employees, contractors, or trusted individuals.

4

Data Breach

Unauthorized exposure, disclosure, or theft of sensitive information.

5

DoS Attack

Attempts to disrupt system availability by overwhelming resources.

6

Incident Severity Levels

Critical: Major disruption or widespread compromise

 

High: Serious incident requiring immediate response

 

Medium: Moderate impact requiring timely investigation

 

Low: Minor impact with lower urgency

Severity Factors: 

Business impact

Data sensitivity

Number of affected systems.

Roles in Incident Response

SOC Analyst: 

Monitor, validate, investigate, and escalate.

Smart Layouts

AI arranges content beautifully for better flow and impact

SOC Analyst: 

Monitor, validate, investigate, and escalate.

Incident Responder: Contain, eradicate, and coordinate response.

Threat Hunter: 

Find hidden threats and attacker activity.

Security Manager: 

Manage response, resources, and decisions.

System Administrator: Support containment, recovery, and patching.

Documentation

Incident tickets

Incident reports

Evidence collection

Track incident status, actions taken, and assigned personnel.

Provide detailed summaries of incidents and response activities.

Preserve logs, screenshots, files, and other evidence required for investigations.

Timeline documentation

Record important events and actions in chronological order.

Communication

Internal Communication :- Security teams share information about ongoing investigations and response activities.

Management Notification :- Management is informed about incident severity, business impact, and response progress.

Technical Team Coordination :- Security teams work closely with system administrators, network engineers, and other technical personnel.

External Communication :- Organizations may communicate with customers, regulators, partners, or law enforcement when necessary.

Challenges

Delayed detection

Limited information

False Positives

Resource constraints

Sophisticated threats

Incidents that remain undetected for long periods can cause greater damage.

Limited visibility may make investigations more difficult.

Organizations may lack sufficient personnel, tools, or expertise.

Analysts may spend time investigating alerts that do not represent actual threats.

Advanced attackers often use techniques designed to evade detection and response.

Best Practices

Maintain an Incident Response Plan

 

Conduct regular training

 

Keep security tools updated

 

Document all activities

 

Perform regular testing and simulations

Summary

5

Secure log storage and retention preserve security evidence.

4

Correlation, timeline, and IOC analysis improve investigations.

3

Logs support threat detection, investigation, and threat hunting.

2

Log collection centralizes data for monitoring and analysis.

1

Logs record system, user, application, and network activities.

Quiz

Which type of Threat Intelligence is mainly intended for executives and senior management?

 

B. Tactical Threat Intelligence

C. Technical Threat Intelligence

D. Operational Threat Intelligence

A. Strategic Threat Intelligence

Quiz-Answer

A. Strategic Threat Intelligence

Which type of Threat Intelligence is mainly intended for executives and senior management?

 

B. Tactical Threat Intelligence

C. Technical Threat Intelligence

D. Operational Threat Intelligence

Log Management and Analysis

By Content ITV

Log Management and Analysis

  • 4