Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • Book Overview & Buying Effective Threat Investigation for SOC Analysts
  • Table Of Contents Toc
  • Feedback & Rating feedback
Effective Threat Investigation for SOC Analysts

Effective Threat Investigation for SOC Analysts

By : Mostafa Yahia
4.8 (21)
close
close
Effective Threat Investigation for SOC Analysts

Effective Threat Investigation for SOC Analysts

4.8 (21)
By: Mostafa Yahia

Overview of this book

Effective threat investigation requires strong technical expertise, analytical skills, and a deep understanding of cyber threats and attacker techniques. It's a crucial skill for SOC analysts, enabling them to analyze different threats and identify security incident origins. This book provides insights into the most common cyber threats and various attacker techniques to help you hone your incident investigation skills. The book begins by explaining phishing and email attack types and how to detect and investigate them, along with Microsoft log types such as Security, System, PowerShell, and their events. Next, you’ll learn how to detect and investigate attackers' techniques and malicious activities within Windows environments. As you make progress, you’ll find out how to analyze the firewalls, flows, and proxy logs, as well as detect and investigate cyber threats using various security solution alerts, including EDR, IPS, and IDS. You’ll also explore popular threat intelligence platforms such as VirusTotal, AbuseIPDB, and X-Force for investigating cyber threats and successfully build your own sandbox environment for effective malware analysis. By the end of this book, you’ll have learned how to analyze popular systems and security appliance logs that exist in any environment and explore various attackers' techniques to detect and investigate them with ease.
Table of Contents (22 chapters)
close
close
1
Part 1: Email Investigation Techniques
In Progress | 0 / 1 sections completed | 0%
3
Chapter 2: Email Flow and Header Analysis
In Progress | 0 / 5 sections completed | 0%
4
Part 2: Investigating Windows Threats by Using Event Logs
In Progress | 0 / 1 sections completed | 0%
6
Chapter 4: Tracking Accounts Login and Management
In Progress | 0 / 5 sections completed | 0%
8
Chapter 6: Investigating PowerShell Event Logs
In Progress | 0 / 5 sections completed | 0%
10
Part 3: Investigating Network Threats by Using Firewall and Proxy Logs
In Progress | 0 / 1 sections completed | 0%
11
Chapter 8: Network Firewall Logs Analysis
In Progress | 0 / 4 sections completed | 0%
14
Chapter 11: Investigating Suspicious Outbound Communications (C&C Communications) by Using Proxy Logs
In Progress | 0 / 4 sections completed | 0%
15
Part 4: Investigating Other Threats and Leveraging External Sources to Investigate Cyber Threats
In Progress | 0 / 1 sections completed | 0%
16
Chapter 12: Investigating External Threats
In Progress | 0 / 4 sections completed | 0%
chevron up
20
Index
In Progress | 0 / 2 sections completed | 0%

Investigating External Threats

An attacker may gain initial access to the target environment by exploiting one of the published web applications or by using valid credentials such as an RDP, VPN, mailbox, and web services credentials. After successful exploitation, the threat actor will have the opportunity to control the whole environment and achieve their objectives, such as disrupting the digital life, espionage, or exfiltrating the data. As an SOC analyst, you should be aware of this and take advantage of the logs provided by the Web Application Firewall (WAF), firewalls, IPS logs, and custom applications logs to investigate such threats.

The objective of this chapter is to learn about some of the most common web attacks, such as code injection, SQL injection, path traversal, and cross-site scripting attacks, and how to investigate web application threats by analyzing the WAF logs. We will also learn how to detect and investigate suspicious external access to remote services...

Unlock full access

Continue reading for free

A Packt free trial gives you instant online access to our library of over 7000 practical eBooks and videos, constantly updated with the latest in tech
bookmark search playlist font-size

Change the font size

margin-width

Change margin width

day-mode

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Delete Bookmark

Modal Close icon
Are you sure you want to delete it?
Cancel
Yes, Delete

Confirmation

Modal Close icon
claim successful

Buy this book with your credits?

Modal Close icon
Are you sure you want to buy this book with one of your credits?
Close
YES, BUY