Introduction to Cybersecurity and the SOC
What is Cybersecurity?
Why Cybersecurity Matters
The CIA Triad: Confidentiality
The CIA Triad: Integrity
The CIA Triad: Availability
What is a SOC?
Why Organizations Need a SOC
SOC Analyst: Your Role
SOC Analyst: Key Skills
Cybersecurity Career Paths
SOC Career Progression
Certifications for SOC
Getting Your First SOC Job
Fundamentals of Networking for Security
What's a Network Anyway?
Network Devices: The Basics
Network Devices: Hubs & Switches
Network Devices: Routers
Network Devices: Firewalls
Network Layouts: Topologies
OSI Model: The 7 Layers
TCP/IP Model: The Practical Side
OSI & TCP/IP for Security
IP Addresses: Your Network ID
IPv6: The Next Generation
Ports: The Digital Doors
Common Protocols: Web & Mail
Common Protocols: File & Remote
Protocols: The Security Angle
Understanding Common Cyberattack Types: Malware
What is Malware?
How Malware Spreads
Malware's Digital Footprint
Viruses: The Old School
Worms: Self-Replicators
Trojans: Disguised Threats
Ransomware: Data Hostage
Spyware: Secret Surveillance
Adware: Unwanted Ads
Rootkits: Deep Hiding
Bots and Botnets
Fileless Malware
Logic Bombs
Antivirus & Anti-Malware
Safe Browsing Habits
Software Updates & Patches
Understanding Common Cyberattack Types: Phishing and Social Engineering
What is Social Engineering?
Why We Fall for It
The Social Engineer's Toolkit
Phishing: The Basics
Spotting a Phishy Email
Malicious Websites & Links
Spear Phishing: Targeted Attacks
Whaling: The Big Fish
Vishing: Voice Phishing
Smishing: SMS Phishing
Think Before You Click!
Verify, Verify, Verify
Report and Learn
Technical Defenses
Understanding Common Cyberattack Types: Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS)
What is a DoS Attack?
What is a DDoS Attack?
Why Do They Attack?
Flooding the Network
UDP Flood Attacks
HTTP Flood Attacks
ICMP Flood Attacks
Amplification Attacks
Impact on Availability
Other Impacts
Basic Mitigation: Rate Limiting
Basic Mitigation: Blackholing
Basic Mitigation: Scrubbing
Basic Mitigation: WAFs
Basic Mitigation: CDNs
Understanding Common Cyberattack Types: Insider Threats and Advanced Persistent Threats (APTs)
What's an Insider Threat?
Types of Malicious Insiders
Why Do Insiders Do It?
How Insiders Attack
Spotting Insider Red Flags
What's an APT?
Who's Behind APTs?
APT Phase 1: Reconnaissance
APT Phase 2: Initial Access
APT Phase 3: Persistence & Lateral
APT Phase 4: Collection & Exfil
APT Phase 5: Maintain & Clean
Why Insiders are Tricky
Why APTs are Tricky
SOC's Role: Insiders & APTs
Understanding Common Cyberattack Types: Password Attacks and Brute Force
What's a Password Anyway?
Why Passwords Fail
The Brute Force Basics
Dictionary Attacks
Rainbow Tables Explained
Credential Stuffing
Other Password Attacks
Login Failures: A Red Flag
Account Lockouts
Unusual Login Patterns
Crafting Strong Passwords
Password Policies
Password Managers
Beyond Passwords: MFA
User Awareness & Training
Understanding Common Cyberattack Types: Man-in-the-Middle (MitM) and Replay Attacks
What is MitM?
How MitM Attacks Work
Why MitM Matters to You
ARP Poisoning Explained
DNS Spoofing Demystified
Other MitM Tricks
What is a Replay Attack?
How Replay Attacks Work
Impact of Replay Attacks
The Power of Encryption
Secure Protocols
Authentication & Nonces
Network Defenses
User Awareness
Understanding Common Cyberattack Types: Zero-Day Exploits and Supply Chain Attacks
What's a Zero-Day?
Why Zero-Days are Scary
How Zero-Days Happen
What's a Supply Chain Attack?
Why Supply Chains are Targets
Real-World Supply Chain Examples
Detecting Zero-Days
Detecting Supply Chain Attacks
Mitigating Zero-Days
Mitigating Supply Chain Attacks
Vulnerability Management
Patching & Updates
Vendor Risk Assessment
Third-Party Security Audits
Building Resilience
Security Tools: Firewalls
What's a Firewall?
The Firewall's Job
Where Firewalls Live
Packet-Filtering Firewalls
Stateful Firewalls
Next-Gen Firewalls (NGFW)
Software vs. Hardware
Rules of the Firewall
Crafting Firewall Policies
Common Firewall Rules
NAT and Firewalls
VPNs and Firewalls
Firewall Logs & Alerts
Firewall Best Practices
Firewalls in the Cloud
Security Tools: Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
What is an IDS?
IDS: How it Works
IDS: Network vs. Host
What is an IPS?
IPS: How it Works
IPS: Network vs. Host
Signature-Based Detection
Anomaly-Based Detection
IDS vs. IPS: Key Differences
Interpreting IDS/IPS Alerts
Common Alert Types
IDS/IPS in the SOC
Tuning IDS/IPS
Limitations of IDS/IPS
IDS/IPS: Your Security Allies
Security Tools: Security Information and Event Management (SIEM)
What is a SIEM?
Why SIEM Matters
Logs: The SIEM's Food
Log Collection & Aggregation
Normalization & Parsing
Correlation: Connecting Dots
Alerting & Dashboards
SIEM for Threat Detection
SIEM for Incident Response
SIEM for Compliance
SIEM Components
On-Prem vs. Cloud SIEM
SIEM Data Flow
SIEM Challenges
SIEM in the SOC
Security Tools: Endpoint Detection and Response (EDR)
What is an Endpoint?
Antivirus: The Basics
Meet EDR: AV's Smarter Cousin
EDR's Eye on Endpoints
Behavioral Detection
Threat Context & Correlation
Alerts and Investigations
Threat Hunting with EDR
Incident Response with EDR
Visibility & Data Collection
Detection Techniques
Response Actions
EDR & the SOC Analyst
EDR vs. SIEM: A Team Effort
The Future of EDR: XDR
Security Tools: Vulnerability Scanners and Penetration Testing Tools
Why Proactive Security?
Finding Weaknesses Early
What's a Vulnerability Scan?
How Scanners Work
Types of Vulnerability Scans
Popular Vulnerability Scanners
Scan Results: What to Do?
What's Pen Testing?
Pen Testing vs. Scanning
Types of Pen Tests
Meet Nmap
Meet Metasploit
The Proactive SOC Analyst
SOC's Role in Proactive Sec
Continuous Improvement
Security Tools: Data Loss Prevention (DLP) and Web Application Firewalls (WAF)
What is DLP?
Sensitive Data: What to Protect?
How DLP Works: The Basics
DLP for Data In Use
DLP for Data In Motion
DLP for Data At Rest
What is a WAF?
WAF Placement and Operation
WAF Rules and Policies
SQL Injection Protection
Cross-Site Scripting (XSS) Defense
Broken Authentication & Session
DDoS Protection by WAFs
Other Common WAF Defenses
DLP & WAF: SOC Synergy
Security Tools: Cloud Security Tools and Concepts
What is Cloud Computing?
The Shared Responsibility Model
Cloud Security Challenges
Cloud Identity & Access
Network Security in Cloud
Data Protection in Cloud
Cloud Access Security Brokers
Cloud Security Posture Mgmt
Cloud Workload Protection
Cloud Security Monitoring
Cloud Incident Response
Cloud Compliance & Auditing
Serverless Security
Container Security
Cloud Security Best Practices
Interpreting Security Logs: Introduction and Log Sources
What are Security Logs?
Why Logs are Important
Log Data: What's Inside?
Operating System Logs
Network Device Logs
Application Logs
Security Tool Logs
Cloud Environment Logs
The Log Volume Challenge
Log Aggregation
Log Centralization
Why Centralize Logs?
Log Management Best Practices
Interpreting Security Logs: Network Device Logs
Firewall Logs: The Basics
Source & Destination IPs
Ports and Protocols
Decoding Allowed Traffic
Decoding Denied Traffic
Firewall Log Anomalies
Router Logs: The Basics
Switch Logs: The Basics
Spotting Suspicious Activity
Connectivity Issues
Authentication Failures
Configuration Changes
Log Correlation Basics
Log Severity Levels
Network Log Best Practices
Interpreting Security Logs: Endpoint Logs (Windows)
What are Windows Logs?
Log Categories: The Big 3
Other Log Categories
Event Viewer Tour
Anatomy of an Event
Filtering for Focus
Logins and Logoffs
Account Changes
Privilege Use
Process Execution
System Startup/Shutdown
Service Control
Auditing Policies
Spotting Malware Signs
Unauthorized Access Clues
Interpreting Security Logs: Endpoint Logs (Linux)
Why Linux Logs Matter
Meet the Log Daemon
Where Logs Live
Authentication Logs: auth.log
Kernel Logs: kern.log
System Logs: syslog/messages
Decoding Log Fields
Log Levels & Priorities
The Power of 'grep'
Viewing Logs with 'tail'
Failed Logins & Brute Force
User & Process Activity
Unauthorized Access Clues
Malware & System Compromise
Log Management Best Practices
Interpreting Security Logs: Application Logs
Why App Logs Matter
Common App Log Sources
Anatomy of a Web Log
Apache Log Dive
Nginx Log Insights
Spotting Web Errors
SQL Injection in Logs
XSS in Logs
Path Traversal in Logs
Command Injection in Logs
File Upload Attacks
Brute Force on Apps
App Logs & Vulnerabilities
Log Aggregation for Apps
App Log Best Practices
Interpreting Security Logs: Cloud Environment Logs
Why Cloud Logs Matter
Cloud Control Plane Logs
AWS CloudTrail Explained
Azure Activity Logs Explained
Google Cloud Audit Logs
Anatomy of a Cloud Log
Spotting Suspicious API Calls
Resource Changes & Access
Identity & Access Logs
Network & Security Group Logs
Cloud Logs in Your SIEM
Cloud Log Alerting
Cloud Log Forensics
Cloud Log Best Practices
Cloud Log Challenges
Security Alerts: Understanding and Prioritization
Logs vs. Alerts
Why Alerts Matter
Alerts from SIEM
Alerts from IDS/IPS
Alerts from EDR
Other Alert Sources
What's in an Alert?
Severity Levels
Source and Destination
Event Type and Description
Why Prioritize Alerts?
Risk and Impact
Context is King
Prioritization Frameworks
The Prioritization Flow
Security Alerts: Initial Triage and False Positives
What is Initial Triage?
Why Triage Matters
Your Triage Toolkit
What's a True Positive?
What's a False Positive?
The Validation Process
Misconfigured Tools
Baseline Blues
Expected Legitimate Activity
Signature Overlaps
Environmental Changes
Alert Fatigue
Wasted Time & Resources
Missed Threats
Trust Erosion
Security Incidents: Definition and Characteristics
What's a Security Event?
Events vs. Incidents
Why Events Matter
What's a Security Incident?
Unauthorized Access
Data Breaches
Service Disruptions
Malware Infections
Impact: Financial & Reputational
Impact: Operational & Legal
Why a Plan Matters
The Incident Lifecycle
Incident Response Process: Preparation Phase
Why Prepare for Incidents?
Building Your IR Team
Essential IR Policies
Setting Up Your IR Lab
Training Your Team
What are Playbooks?
Playbook Components
Runbooks vs. Playbooks
Crafting Your Playbooks
Who Needs to Know?
External Communications
Internal Communications
Legal & Regulatory Prep
Vendor & Third-Party Prep
Continuous Improvement
Incident Response Process: Detection and Analysis Phase
How Incidents Are Found
Alerts: Your First Clue
Log Monitoring Basics
Correlation: Connecting Dots
User Reports & Other Sources
First Steps: Triage
Is It Real? Validating Alerts
What's the Scope?
How Bad Is It? Severity
Key Info to Gather
Timeline Creation
Understanding Attack Chains
Threat Intelligence Use
Why Timely Detection Matters
Continuous Improvement
Incident Response Process: Containment Phase
What is Containment?
Why Containment Matters
Short-Term Containment
Long-Term Containment
Network Segmentation
System Isolation
Blocking Malicious IPs/Domains
Disabling Services/Ports
Account Disabling/Lockout
Password Resets
Data Loss Prevention (DLP)
Impact on Business Ops
Evidence Preservation
Communication During Containment
Containment Challenges
Incident Response Process: Eradication Phase
What is Eradication?
Why Eradicate Thoroughly?
Eradication vs. Containment
Malware Removal
Vulnerability Patching
Configuration Changes
Account Disabling/Resetting
Removing Backdoors
Forensic Analysis for Eradication
Verifying Eradication
Documentation in Eradication
Communication During Eradication
Preventing Re-infection
Eradication Challenges
Eradication Tools
Incident Response Process: Recovery Phase
What is Recovery?
Why Recovery Matters
Recovery Planning Basics
Restoring from Backups
Rebuilding Systems
Applying Patches & Updates
Testing Restored Systems
Verifying Security Controls
Monitoring Post-Recovery
Phased Recovery Approach
Minimizing Disruption
Communicating Recovery Status
Documentation in Recovery
Recovery Team Roles
Recovery Challenges
Incident Response Process: Post-Incident Activity (Lessons Learned)
Why Review Incidents?
Beyond Just Fixing It
The Continuous Loop
Gathering the Facts
The Incident Report
Who Needs to Know?
Finding the Root Cause
Updating Playbooks
Patching the Gaps
Training the Team
Policy Power-Up
Building Resilience
SOC Analyst's Growth
Beyond the Exam
Authentication, Authorization, and Accounting (AAA) Overview
What is AAA?
Why AAA Matters
Authentication: Who Are You?
Authorization: What Can You Do?
Accounting: What Did You Do?
AAA Protocols: RADIUS
AAA Protocols: TACACS+
Identity & Access Management
Centralized AAA Systems
AAA in the Real World
AAA and Least Privilege
AAA and Zero Trust
AAA and Compliance
Challenges in AAA
AAA for SOC Analysts
Authentication Methods: Factors and Types
What is Authentication?
Something You Know
Something You Have
Something You Are
Passwords & PINs
Smart Cards & Tokens
Biometrics: Fingerprints
Biometrics: Facial & Iris
Single-Factor Authentication
Strengths of Each Factor
Weaknesses of Each Factor
Choosing the Right Method
Authentication Methods: Multi-Factor Authentication (MFA)
What is MFA?
Why MFA Matters
MFA: More Than One Factor
Time-Based OTP (TOTP)
HMAC-Based OTP (HOTP)
Push Notifications
Biometric Authentication
SMS and Email OTPs
Hardware Tokens
Choosing the Right MFA
MFA Best Practices
MFA and SOC Analysts
Authorization and Access Control Models
What is Authorization?
Permissions and Privileges
The Least Privilege Rule
Discretionary Access Control
Mandatory Access Control
Role-Based Access Control
Comparing Access Models
Access Control Lists (ACLs)
Group Policies
User and Group Accounts
Attribute-Based Access
Policy-Based Access
Authorization in Cloud
Authorization Best Practices
Authorization for SOC Analysts
Identity Management and Federation
What is Identity?
What is Identity Mgmt?
IdM Components: Users
IdM Components: Systems
IdM Components: Policies
Why Centralize IdM?
Enhanced Security
Improved User Experience
Compliance & Auditing
Cost Savings
What is Identity Federation?
Single Sign-On (SSO)
SSO & Federation in Action
SAML: The Standard
OAuth & OpenID Connect
Basic Cryptographic Principles: Hashing
What is Hashing?
The Hash Value
Hashing in Action
One-Way Street
Collision Resistance
Avalanche Effect
MD5: The Old Guard
SHA-1: Still Around?
SHA-2: The Workhorse
SHA-3: The New Kid
Ensuring Data Integrity
File Integrity Checks
Password Storage
Digital Signatures & Hashing
Hashing vs. Encryption
Basic Cryptographic Principles: Symmetric Encryption
What is Symmetric Crypto?
The Symmetric Key
How Symmetric Crypto Works
Symmetric Crypto's Superpower
Symmetric Crypto's Weakness
DES: The Old Guard
3DES: Triple the Security?
AES: The Modern Standard
Block vs. Stream Ciphers
Symmetric Modes of Operation
Confidentiality Achieved
Encrypting Files & Disks
Securing Your Wi-Fi
VPNs and Symmetric Crypto
Symmetric Crypto in HTTPS
Basic Cryptographic Principles: Asymmetric Encryption
What is Asymmetric Crypto?
How Asymmetric Crypto Works
Why Use Two Keys?
Asymmetric Crypto Drawbacks
RSA: The Classic Algorithm
ECC: The Efficient Choice
Secure Key Exchange
What's a Digital Signature?
How Digital Signatures Work
Digital Signatures vs. Encrypt
Public Key Infrastructure
Certificate Authorities
Digital Certificates
TLS/SSL Handshake
Asymmetric Crypto in Action
Basic Cryptographic Principles: Digital Signatures and Certificates
What's a Digital Signature?
How Digital Signatures Work
Authenticity & Non-Repudiation
What's a Digital Certificate?
Binding Public Keys to Identity
Certificate Components
What is PKI?
Certificate Authorities (CAs)
Trust Chains and Root CAs
Certificate Revocation
TLS/SSL and PKI
Code Signing
Email Security (S/MIME)
VPNs and PKI
Certificate Management
Trust Models & Attacks
Data Confidentiality and Integrity in Transit and At Rest
Data in Transit: What & Why?
Encryption for Transit
TLS/SSL: The Web's Shield
VPNs: Secure Tunnels
Other Transit Protections
Data at Rest: What & Why?
Encryption for At Rest
Full Disk Encryption
Database Encryption
Cloud Storage Encryption
Data Integrity: What & Why?
Hashing for Integrity
Digital Signatures for Trust
Integrity in Transit
Integrity at Rest
Security Governance: Policies, Standards, and Procedures
What is Security Governance?
Why Governance Matters
Policies: The Big Picture
Standards: The How-To
Guidelines: Best Practices
Procedures: Step-by-Step
Policies vs. Standards vs. Procedures
Policies for SOC Operations
Procedures for SOC Success
Creating Effective Policies
Implementing Standards
Writing Clear Procedures
The Policy Lifecycle
Governance in Action: SOC
Continuous Improvement
Risk Management Fundamentals
What is Cybersecurity Risk?
Threats: The Bad Guys
Vulnerabilities: Weak Spots
Impact: What Happens?
Risk: Threat x Vulnerability
Risk Management Overview
Step 1: Identify Risks
Step 2: Assess Risks
Step 3: Mitigate Risks
Step 4: Monitor Risks
Strategy 1: Risk Avoidance
Strategy 2: Risk Transfer
Strategy 3: Risk Acceptance
Strategy 4: Risk Reduction
Why Monitor Risks?
Compliance Frameworks: NIST and ISO 27001
Why Frameworks Matter
What is NIST CSF?
NIST CSF: Identify
NIST CSF: Protect
NIST CSF: Detect
NIST CSF: Respond
NIST CSF: Recover
NIST CSF in the SOC
What is ISO 27001?
ISO 27001: The ISMS
ISO 27001 Controls
ISO 27001 in the SOC
NIST vs. ISO 27001
Frameworks & Your SOC Role
Staying Current
Compliance Frameworks: GDPR and HIPAA
Why Data Privacy Matters
What is GDPR?
GDPR: Key Principles
GDPR: Data Subject Rights
GDPR: Data Controllers & Processors
GDPR: Consent & Legal Basis
GDPR: Breach Notification
GDPR: Security Measures
GDPR: Penalties & Fines
What is HIPAA?
HIPAA: PHI and ePHI
HIPAA: Privacy Rule
HIPAA: Security Rule
HIPAA: Breach Notification
GDPR vs. HIPAA for SOC
Security Awareness and Training
Why People Matter
What is Security Awareness?
Why Train Employees?
Spotting Phishing
Password Power-Up
Handling Sensitive Data
Clean Desk, Clear Mind
Safe Browsing Habits
Culture of Security
Reporting is Key
Staying Updated
SOC's Training Role
Alerts from the SOC
Phishing Drills
Feedback Loop
Professional Ethics and Legal Considerations for SOC Analysts
Why Ethics Matter
Core Ethical Principles
Professional Codes of Conduct
Confidentiality Challenges
Scope & Authority Issues
Reporting & Transparency
Conflict of Interest
Ethical Decision-Making
Cybercrime Laws
Data Breach Notification
Privacy Regulations
Evidence Handling Basics
Chain of Custody
Legal Hold & Preservation
Reporting to Authorities