Skip to content

Latest commit

 

History

History
95 lines (74 loc) · 2.17 KB

File metadata and controls

95 lines (74 loc) · 2.17 KB

Alerting and Monitoring

Objectives

  • 4.4 - Explain security alerting and monitoring concepts and tools
  • Understand important log sources
  • Explain alert quality, tuning, and triage

Table of Contents

  1. Monitoring
  2. Alerting
  3. Log Sources
  4. SIEM
  5. Alert Examples
  6. Alert Tuning
  7. Triage
  8. Key Takeaways

Monitoring

  • Monitoring: Collecting and reviewing activity from systems, networks, applications, cloud platforms, and security tools.
  • Monitoring provides visibility into normal and abnormal behavior.

Alerting

  • Alert: A notification that specific activity may require investigation.
  • Alerts may come from SIEM, EDR, IDS/IPS, firewalls, cloud tools, or email security systems.

A good alert should include:

  • Alert name
  • Severity
  • User
  • Host
  • IP address
  • Timestamp
  • Source log
  • Reason it triggered
  • Suggested triage steps

Log Sources

Important log sources:

  • Authentication logs
  • Firewall logs
  • DNS logs
  • VPN logs
  • Proxy logs
  • Endpoint logs
  • Cloud audit logs
  • Email security logs
  • Web server logs

SIEM

  • SIEM: Security Information and Event Management.
  • A SIEM collects, stores, searches, and correlates logs from multiple sources.
  • SIEM tools help analysts investigate activity across systems.

Alert Examples

  • Multiple failed logons
  • Successful login after repeated failures
  • Impossible travel
  • Malware detection
  • Suspicious PowerShell command
  • New administrator account
  • Public cloud storage change
  • Large outbound data transfer

Alert Tuning

  • Tuning: Adjusting alert logic to improve accuracy and reduce noise.

Tuning may include:

  • Thresholds
  • Allow lists
  • Suppression windows
  • Asset criticality
  • User context
  • Correlation with related alerts

Triage

Basic triage questions:

  • What triggered the alert?
  • Is this expected activity?
  • What user and system are involved?
  • What happened before and after?
  • Is containment needed?

Key Takeaways

  • Monitoring provides visibility.
  • Alerting turns important activity into investigation work.
  • Tuning helps reduce false positives and analyst fatigue.