SOC Workbook and Lookup

dwight-sheriff

This lesson we learn about how to use resource available to us to analyze SIEM event! Like a sheriff (sort of)

Idedity and Asset

Network diagram

Gives you an idea of the flow of traffic and help determine the meaning of an event

Alert Triage

Conclusion

Flow

  1. assign the task to self
  2. do initial checking (email sender, recipient, open port etc…)
  3. determine if the incident is TP or FP
  4. if TP -> gather more info to support my finding -> write report and escalate it to L2
  5. if FP -> write report to explain why this is a FP