Learning Outcome
4
Explain its use in SOC and threat detection.
3
Describe the Threat Intelligence Lifecycle.
2
Identify common Threat Intelligence sources.
1
Explain the purpose of Threat Intelligence.
5
Apply Threat Intelligence to improve security and defense.
Before a festival, police receive information that a group of thieves may target crowded markets. They learn who the thieves are, where they may attack, and how they usually operate.
Information about threats = Threat Intelligence
Using this information, the police increase patrols and closely monitor the areas that may be targeted.
Preparing defenses based on intelligence = Threat-Informed Defense
During the festival, officers watch for activities that match the information they received and investigate anything suspicious.
Identifying attacker activity = Threat Detection
Because the police already understand the possible threat, they can respond quickly and prevent or reduce the impact of a crime.
Taking action against the threat = Incident Response
In cybersecurity, Threat Intelligence provides information about attackers, their tactics, techniques, indicators, and emerging threats. Security teams use this information to strengthen defenses, improve detection, and respond more effectively.
Introduction to Logs
Logs are records of system, application, user, network, and security activities. They provide details about what happened, when, where, and who performed the action.
Importance
Detect cyberattacks
Investigate incidents
Monitor user activity
Identify system errors
Meet compliance requirements
Logs help organizations:
Goals of Incident Response
Identify incidents
Minimize disruption
Contain and eliminate threats
Recover systems
Preserve evidence
Prevent future incidents
Security Incident
A security incident is an event that threatens the confidentiality, integrity, or availability of systems or data.
Examples:
Malware, phishing, unauthorized access.
Event vs Alert vs Incident
Security Event: Observable activity, such as login or file access.
Security Alert: Notification of suspicious activity.
Security Event: Observable activity, such as login or file access.
Common Security Incidents
Malware
Phishing
Unauthorized access
Insider threats
Data breaches
DoS attacks
Need for Incident Response
Reducing Business Impact
Security incidents can interrupt business operations and affect productivity.
Faster Recovery
Organizations with established response procedures can restore affected systems more efficiently.
Protecting Sensitive Data
Incidents involving customer records, financial information, or intellectual property can have serious consequences.
Regulatory and Compliance Requirements
An effective response process helps organizations meet compliance obligations and demonstrate due diligence.
Incident Response Lifecycle
Preparation
Prepare people, processes, plans, teams, policies, and tools such as SIEM, EDR, and forensic tools.
Detection & Analysis
Identify suspicious activity
Classify incidents
Classify incidents
Categorize threats
Investigate affected systems
Containment
Limit the incident using short-term and long-term controls and isolate affected systems.
Eradication
Remove malware
Eliminate attacker access
Fix vulnerabilities
Recovery
Restore affected systems
Monitor for recurrence
Resume normal operations
Lessons Learned
Review the incident
Perform root cause analysis
Update security controls
Improve response procedures
Incident Classification
Unauthorized Access
Access to systems, applications, or data by unauthorized individuals.
1
Malware Infection
Incidents involving viruses, ransomware, spyware, or other malicious software.
2
Phishing
Attempts to deceive users into revealing credentials or sensitive information.
3
Insider Threat
Security incidents caused by employees, contractors, or trusted individuals.
4
Data Breach
Unauthorized exposure, disclosure, or theft of sensitive information.
5
DoS Attack
Attempts to disrupt system availability by overwhelming resources.
6
Incident Severity Levels
Critical: Major disruption or widespread compromise
High: Serious incident requiring immediate response
Medium: Moderate impact requiring timely investigation
Low: Minor impact with lower urgency
Severity Factors:
Business impact
Data sensitivity
Number of affected systems.
Roles in Incident Response
SOC Analyst:
Monitor, validate, investigate, and escalate.
Smart Layouts
AI arranges content beautifully for better flow and impact
SOC Analyst:
Monitor, validate, investigate, and escalate.
Incident Responder: Contain, eradicate, and coordinate response.
Threat Hunter:
Find hidden threats and attacker activity.
Security Manager:
Manage response, resources, and decisions.
System Administrator: Support containment, recovery, and patching.
Documentation
Incident tickets
Incident reports
Evidence collection
Track incident status, actions taken, and assigned personnel.
Provide detailed summaries of incidents and response activities.
Preserve logs, screenshots, files, and other evidence required for investigations.
Timeline documentation
Record important events and actions in chronological order.
Communication
Internal Communication :- Security teams share information about ongoing investigations and response activities.
Management Notification :- Management is informed about incident severity, business impact, and response progress.
Technical Team Coordination :- Security teams work closely with system administrators, network engineers, and other technical personnel.
External Communication :- Organizations may communicate with customers, regulators, partners, or law enforcement when necessary.
Challenges
Delayed detection
Limited information
False Positives
Resource constraints
Sophisticated threats
Incidents that remain undetected for long periods can cause greater damage.
Limited visibility may make investigations more difficult.
Organizations may lack sufficient personnel, tools, or expertise.
Analysts may spend time investigating alerts that do not represent actual threats.
Advanced attackers often use techniques designed to evade detection and response.
Best Practices
Maintain an Incident Response Plan
Conduct regular training
Keep security tools updated
Document all activities
Perform regular testing and simulations
Summary
5
Secure log storage and retention preserve security evidence.
4
Correlation, timeline, and IOC analysis improve investigations.
3
Logs support threat detection, investigation, and threat hunting.
2
Log collection centralizes data for monitoring and analysis.
1
Logs record system, user, application, and network activities.
Quiz
Which type of Threat Intelligence is mainly intended for executives and senior management?
B. Tactical Threat Intelligence
C. Technical Threat Intelligence
D. Operational Threat Intelligence
A. Strategic Threat Intelligence
Quiz-Answer
A. Strategic Threat Intelligence
Which type of Threat Intelligence is mainly intended for executives and senior management?
B. Tactical Threat Intelligence
C. Technical Threat Intelligence
D. Operational Threat Intelligence