SOC and SIEM
SOC (Security Operations Center)
A Security Operations Center (SOC) is a centralized unit that deals with security issues on an organizational and technical level. It houses the security team responsible for monitoring, detecting, and responding to cybersecurity incidents.
- Goal: To identify and respond to threats as quickly as possible to minimize impact.
- Monitoring Design: Modern SOCs map their detections to the MITRE ATT&CK framework to ensure comprehensive coverage of adversary tactics and techniques.
SIEM (Security Information and Event Management)
Security Information and Event Management (SIEM) is a technology that supports threat detection, compliance, and security incident management through the collection and analysis (both near real-time and historical) of security events from a wide variety of event and contextual data sources.
- Correlation: A SIEM correlates logs from disparate sources—such as endpoint, identity, and cloud—to identify complex attack patterns that wouldn’t be visible in isolation.
- Tuning: Effective SIEM management requires weekly alert tuning to reduce false positives and ensure that the SOC team focuses on high-fidelity alerts.
Advanced Concepts
- Automation (SOAR): Security Orchestration, Automation, and Response is often used alongside SIEM to automate repetitive containment tasks.
- Staying Current with Threats
- Phishing