SOC Fundamentals

Security Monitoring Fundamentals

Learning Outcome

4

Describe challenges and best practices for effective security monitoring.

3

Identify types of security monitoring and their use cases.

2

Differentiate between security events, alerts, and incidents.

1

Explain the purpose and importance of security monitoring.

A shopping mall has CCTV cameras that continuously watch different areas to keep the mall safe.

Continuous watching = Security Monitoring

The camera detects a person behaving suspiciously and alerts a security guard.

Suspicious activity = Security Event; Notification = Security Alert

The guard reviews the CCTV footage and checks what the person is doing.

Checking the activity = Investigation and Analysis

The guard confirms that the person is stealing and informs the security team.

Confirmed malicious activity = Security Incident

The security team responds quickly and stops the person before further damage occurs.

Stopping the threat = Incident Response

Introduction to Security Monitoring

Security Monitoring is the continuous process of observing and analyzing systems, networks, applications, and security events to detect potential threats and suspicious activities.

Purpose of Security Monitoring

The main purpose is to detect threats early and respond before they cause significant damage.

Prevent unauthorized access to information.

Confidentiality

Prevent unauthorized modification of data.

Integrity

Keep systems and services accessible.

Availability

Need for Security Monitoring

Organizations face threats such as malware, ransomware, phishing, insider threats, and unauthorized access.

Detect threats early

 

Protect sensitive information

 

Identify suspicious activities

 

Reduce incident impact

 

Support incident response

 

Maintain business continuity

 

Meet compliance requirements

Security monitoring helps to:

Key Concepts of Security Monitoring

Security Event

A security event is any observable activity occurring on a system, network, application, or device.

Examples:

User login

File access

Network connection

Software installation

Configuration change

Not every event is malicious.

Security Alert

A security alert is a notification generated when a monitoring system detects suspicious or unusual activity.

Examples:

Multiple failed logins

Malware detection

Unusual outbound traffic

Unexpected account creation

Security Incident

A security incident is a confirmed security violation or compromise that requires investigation and response.

Examples:

Malware infection

Data breach

Confirmed unauthorized access

Indicators of Compromise (IOCs)

IOCs are pieces of evidence that may indicate malicious activity.

Common IOCs include:

Malicious IP Addresses â€“ IPs linked to known malicious activity

Suspicious Domains â€“ Domains used for phishing or malware

File Hashes â€“ Unique identifiers of files

Unauthorized User Activity â€“ Unexpected account or privilege changes

Malware Signatures â€“ Patterns used to identify known malware

Types of Security Monitoring

Security Monitoring

Monitor systems and networks for suspicious activities.

1

Alert Analysis

Review alerts and identify genuine threats.

2

Log Analysis

Analyze server, firewall, application, and security logs.

3

Threat Detection

Identify IOCs and signs of malicious activity.

4

Incident Investigation

Determine the cause and impact of incidents.

5

Incident Escalation

Escalate complex incidents to senior teams.

6

Daily Activities

Review security dashboards

Monitor SIEM alerts

Analyze logs

Investigate suspicious activities

Communicate with security teams

Security Team Hierarchy

Executive Leadership

CEO: Leads overall business strategy.

 

CFO: Manages finances and security budgets.

 

Company Owner: Sets organizational objectives and supports security initiatives.

Security Leadership

CISO: Leads cybersecurity strategy, policies, and risk management.

 

CIO: Oversees IT operations and technology investments.

 

CTO: Leads technology innovation and infrastructure.

Security Management

SOC Manager:

Manages SOC analysts

Oversees incident response

Reports security metrics

Improves SOC operations

Security Team Lead:

Coordinates daily activities

Supports analysts during investigations

Security Operations Team

SOC Analyst: Monitors and investigates security events.

Security Engineer: Designs and maintains security solutions.

Incident Responder: Handles active incidents and recovery.

Threat Hunter: Searches for hidden threats.

Penetration Tester: Tests systems for security weaknesses.

GRC Specialist: Manages Governance, Risk, and Compliance.

SOC Analyst Tier Structure

Tier 1 (L1): First point of contact for security alerts.

Monitor alerts

Perform initial investigation

Create and document ticketsa

Tier 2 (L2): Handles more complex investigations.

Analyze incidents

Validate threats

Support containment and remediation

Tier 3 (L3): Senior analysts handling advanced threats.

Investigate sophisticated attacks

Perform malware analysis

Conduct threat hunting

Skills Required for a SOC Analyst

Technical Skills

Soft Skills

Networking: IP, DNS, HTTP, protocols, and network communication

Log Analysis: Identify suspicious activities in logs

Operating Systems: Windows, Linux, and servers

Analytical thinking

Attention to detail

Problem-solving

Communication

Tools Used by SOC Analysts

Splunk,

IBM QRadar, Microsoft Sentinel

CrowdStrike Falcon, Microsoft Defender for Endpoint

Snort, Suricata

Palo Alto Networks, Fortinet,

Cisco Firepower

ServiceNow, Jira

SIEM

EDR

IDS/IPS

Firewalls

Ticketing

Challenges Faced by SOC Analysts

Alert Fatigue: Large numbers of alerts make genuine threats harder to identify.

 

 

False Positives: Alerts may indicate suspicious activity without being actual incidents.

 

 

Large Data Volumes: Massive amounts of logs require continuous analysis.

 

 

Evolving Threats: New attack techniques require analysts to stay updated.

Career Path of a SOC Analyst

Summary

5

SOC Analysts support cybersecurity and business continuity.

4

Analysts are divided into L1, L2, and L3 based on expertise.

3

SOC teams have leadership, management, and operational levels.

2

They protect digital assets and reduce cybersecurity risks.

1

SOC Analysts monitor, detect, investigate, and respond to threats.

Quiz

Which SOC Analyst tier performs the initial investigation of alerts?

 

B. L2 Analyst

C. L1 Analyst

D. SOC Manager

A. L3 Analyst

Quiz-Answer

C. L1 Analyst

Which SOC Analyst tier performs the initial investigation of alerts?

 

A. L3 Analyst

B. L2 Analyst

D. SOC Manager

Security Monitoring Fundamentals

By Content ITV

Security Monitoring Fundamentals

  • 20