Learning Outcome
4
Describe challenges and best practices for effective security monitoring.
3
Identify types of security monitoring and their use cases.
2
Differentiate between security events, alerts, and incidents.
1
Explain the purpose and importance of security monitoring.
A shopping mall has CCTV cameras that continuously watch different areas to keep the mall safe.
Continuous watching = Security Monitoring
The camera detects a person behaving suspiciously and alerts a security guard.
Suspicious activity = Security Event; Notification = Security Alert
The guard reviews the CCTV footage and checks what the person is doing.
Checking the activity = Investigation and Analysis
The guard confirms that the person is stealing and informs the security team.
Confirmed malicious activity = Security Incident
The security team responds quickly and stops the person before further damage occurs.
Stopping the threat = Incident Response
Introduction to Security Monitoring
Security Monitoring is the continuous process of observing and analyzing systems, networks, applications, and security events to detect potential threats and suspicious activities.
Purpose of Security Monitoring
The main purpose is to detect threats early and respond before they cause significant damage.
Prevent unauthorized access to information.
Confidentiality
Prevent unauthorized modification of data.
Integrity
Keep systems and services accessible.
Availability
Need for Security Monitoring
Organizations face threats such as malware, ransomware, phishing, insider threats, and unauthorized access.
Detect threats early
Protect sensitive information
Identify suspicious activities
Reduce incident impact
Support incident response
Maintain business continuity
Meet compliance requirements
Security monitoring helps to:
Key Concepts of Security Monitoring
Security Event
A security event is any observable activity occurring on a system, network, application, or device.
Examples:
User login
File access
Network connection
Software installation
Configuration change
Not every event is malicious.
Security Alert
A security alert is a notification generated when a monitoring system detects suspicious or unusual activity.
Examples:
Multiple failed logins
Malware detection
Unusual outbound traffic
Unexpected account creation
Security Incident
A security incident is a confirmed security violation or compromise that requires investigation and response.
Examples:
Malware infection
Data breach
Confirmed unauthorized access
Indicators of Compromise (IOCs)
IOCs are pieces of evidence that may indicate malicious activity.
Common IOCs include:
Malicious IP Addresses – IPs linked to known malicious activity
Suspicious Domains – Domains used for phishing or malware
File Hashes – Unique identifiers of files
Unauthorized User Activity – Unexpected account or privilege changes
Malware Signatures – Patterns used to identify known malware
Types of Security Monitoring
Security Monitoring
Monitor systems and networks for suspicious activities.
1
Alert Analysis
Review alerts and identify genuine threats.
2
Log Analysis
Analyze server, firewall, application, and security logs.
3
Threat Detection
Identify IOCs and signs of malicious activity.
4
Incident Investigation
Determine the cause and impact of incidents.
5
Incident Escalation
Escalate complex incidents to senior teams.
6
Daily Activities
Review security dashboards
Monitor SIEM alerts
Analyze logs
Investigate suspicious activities
Communicate with security teams
Security Team Hierarchy
Executive Leadership
CEO: Leads overall business strategy.
CFO: Manages finances and security budgets.
Company Owner: Sets organizational objectives and supports security initiatives.
Security Leadership
CISO: Leads cybersecurity strategy, policies, and risk management.
CIO: Oversees IT operations and technology investments.
CTO: Leads technology innovation and infrastructure.
Security Management
SOC Manager:
Manages SOC analysts
Oversees incident response
Reports security metrics
Improves SOC operations
Security Team Lead:
Coordinates daily activities
Supports analysts during investigations
Security Operations Team
SOC Analyst: Monitors and investigates security events.
Security Engineer: Designs and maintains security solutions.
Incident Responder: Handles active incidents and recovery.
Threat Hunter: Searches for hidden threats.
Penetration Tester: Tests systems for security weaknesses.
GRC Specialist: Manages Governance, Risk, and Compliance.
SOC Analyst Tier Structure
Tier 1 (L1): First point of contact for security alerts.
Monitor alerts
Perform initial investigation
Create and document ticketsa
Tier 2 (L2): Handles more complex investigations.
Analyze incidents
Validate threats
Support containment and remediation
Tier 3 (L3): Senior analysts handling advanced threats.
Investigate sophisticated attacks
Perform malware analysis
Conduct threat hunting
Skills Required for a SOC Analyst
Technical Skills
Soft Skills
Networking: IP, DNS, HTTP, protocols, and network communication
Log Analysis: Identify suspicious activities in logs
Operating Systems: Windows, Linux, and servers
Analytical thinking
Attention to detail
Problem-solving
Communication
Tools Used by SOC Analysts
Splunk,
IBM QRadar, Microsoft Sentinel
CrowdStrike Falcon, Microsoft Defender for Endpoint
Snort, Suricata
Palo Alto Networks, Fortinet,
Cisco Firepower
ServiceNow, Jira
SIEM
EDR
IDS/IPS
Firewalls
Ticketing
Challenges Faced by SOC Analysts
Alert Fatigue: Large numbers of alerts make genuine threats harder to identify.
False Positives: Alerts may indicate suspicious activity without being actual incidents.
Large Data Volumes: Massive amounts of logs require continuous analysis.
Evolving Threats: New attack techniques require analysts to stay updated.
Career Path of a SOC Analyst
Summary
5
SOC Analysts support cybersecurity and business continuity.
4
Analysts are divided into L1, L2, and L3 based on expertise.
3
SOC teams have leadership, management, and operational levels.
2
They protect digital assets and reduce cybersecurity risks.
1
SOC Analysts monitor, detect, investigate, and respond to threats.
Quiz
Which SOC Analyst tier performs the initial investigation of alerts?
B. L2 Analyst
C. L1 Analyst
D. SOC Manager
A. L3 Analyst
Quiz-Answer
C. L1 Analyst
Which SOC Analyst tier performs the initial investigation of alerts?
A. L3 Analyst
B. L2 Analyst
D. SOC Manager