Perform Real-Time Security Monitoring and Detect Suspicious Activities

Business Scenario

Welcome!

You are a SOC Analyst at CyberSecure Solutions. Your organization continuously monitors its systems and network for suspicious activities.

Your task is to monitor security events in real time, identify suspicious behavior, investigate alerts, and determine whether the activity requires a security response. 

Pre-Lab Preparation

Topic : SOC Fundamentals

1) Introduction to Security Operations Center (SOC) 

2) Roles and responsibilities of a SOC analyst

3) Security monitoring fundamentals

Task 1: Monitor Security Events

Learn how a SOC analyst monitors events in real time.

1

Steps

a

  • Start the test endpoint.

  • Open the SIEM dashboard.

  • Navigate to the Events/Alerts section.

  • Observe incoming security events.

  • Record:

    • Time

    • Source

    • Event type

    • Username

    • Severity

Expected Output

b

Task 2: Generate Suspicious Activity

Generate controlled security events in the lab environment.

1

a

  • Use the authorized test machine.

  • Perform activities such as:

  • Multiple failed login attempts.

Steps

  • Login using a test account.

  • Create/delete a test file.

  • Start or stop a test service.

  • Monitor the SIEM dashboard.

  • Identify the events generated by these activities.

Task 3: Detect and Analyze an Alert

Determine whether an alert represents suspicious activity.

1

a

  • Select a generated alert.

  • Examine:

    • Source IP

    • Username

    • Timestamp

    • Event type

    • Severity

    • Number of attempts

Steps

  • Select a generated alert.

  • Examine:

    • Source IP

    • Username

    • Timestamp

    • Event type

    • Severity

    • Number of attempts

  • heck related events.

  • Decide whether the activity is:

Normal

   OR

Suspicious

   OR

Potential Incident

Task 4: Take Basic Defensive Action

Understand how a SOC analyst responds to suspicious activity.

1

a

Based on the investigation, perform an appropriate action in the training environment, such as:

  • Disable a test account.

  • Reset a test password.

  • Block a test IP.

  • Isolate a test endpoint.

Steps

Based on the investigation, perform an appropriate action in the training environment, such as:

  • Disable a test account.

  • Reset a test password.

  • Block a test IP.

  • Isolate a test endpoint.

  1. Apply the selected action.

  2. Continue monitoring the SIEM.

  3. Verify whether the suspicious activity stops.

Task 5: Document the Security Event

Create a basic security monitoring report.

Record:

1

FieldExample
Event IDSOC-001
AlertMultiple Failed Logins
SourceTEST-PC01
SeverityMedium
InvestigationMultiple failed attempts detected
Action TakenTest account disabled
StatusResolved 
AnalystStudent Name

Click to view : SOC incident report

 

Great job!

You have successfully completed your Real-Time Security Monitoring lab.

In this lab, you have: Performed real-time security monitoring, Monitored security events, Identified suspicious activities, Analyzed potential threats

You are now ready to move to the next stage of SOC monitoring and threat detection.

Checkpoint

Next-Lab Preparation

Topic : SOC Fundamentals

1) Introduction to Security Operations Center (SOC) 

2) Roles and responsibilities of a SOC analyst

3) Security monitoring fundamentals

Perform Real-Time Security Monitoring and Detect Suspicious Activities

By Content ITV

Perform Real-Time Security Monitoring and Detect Suspicious Activities

  • 61