Kalos Cybersecurity LLC

List of Figures

Figure 1-1. Core Functions of a Security Operations Center 18
Figure 1-2. Evolution of Enterprise Cyber Defense 23
Figure 1-3. Events Become Alerts 27
Figure 1-4. Event → Alert → Incident 30
Figure 1-5. Telemetry Is Observation 35
Figure 1-6. From Data to Intelligence 37
Figure 1-7. Security Monitoring Pipeline 39
Figure 1-8. The Three Pillars of a Security Operations Center 41
Figure 1-9. Typical SOC Structure 42
Figure 1-10. The Analyst Workflow 47
Figure 1-11. Daily SOC Startup Checklist 49
Figure 1-12. Multi-Sensor Investigation 53
Figure 1-13. Laboratory Architecture 57
Figure 1-14. Endpoint Telemetry Pipeline 62
Figure 1-15. Network Detection Pipeline 62
Figure 1-16. Laboratory Method 71
Figure 2-1. Evolution of SIEM 77
Figure 2-2. Security Before SIEM 78
Figure 2-3. Security After SIEM 78
Figure 2-4. Event Generation 83
Figure 2-5. Multiple Sensors Observe One System 84
Figure 2-6. Secure Telemetry Transport 85
Figure 2-7. Decoding 87
Figure 2-8. Complete Wazuh Processing Pipeline 89
Figure 2-9. Did Nmap Generate Traffic? — Decision Flow 89
Figure 2-10. Before Normalization 91
Figure 2-11. After Normalization 92
Figure 2-12. Data Enrichment 95
Figure 2-13. Correlation Timeline 99
Figure 2-14. Correlation Dimensions 104
Figure 2-15. Security Event — Decision Flow 108
Figure 2-16. Rule Logic 109
Figure 2-17. Rule Tuning 112
Figure 2-18. The Investigation Mindset 117
Figure 2-19. From Hostname to Specific Process 117
Figure 2-20. Investigation Timeline — Authentication Events 118
Figure 2-21. Investigation Timeline — Ordering Events by Time 119
Figure 2-22. Timeline Investigation 120
Figure 2-23. Alert — Decision Flow 123
Figure 2-24. Wazuh Architecture 125
Figure 2-25. Responsibilities of Each Component 129
Figure 2-26. Wazuh as the Central Hub 131
Figure 2-27. From Begin Shift to Continuous Improvement 134
Figure 2-28. Operational Monitoring vs. Security Monitoring 136
Figure 2-29. From Alert to Conclusion 137
Figure 2-30. Dashboard vs. Investigation 139
Figure 2-31. Continuous Improvement Cycle 141
Figure 2-32. Dashboard Responsibilities 144
Figure 2-33. Alert Investigation Workflow 147
Figure 2-34. Investigation Methodology 154
Figure 2-35. Evidence Correlation 157
Figure 2-36. Questions Drive Investigations 162
Figure 2-37. Corroborating Evidence 165
Figure 2-38. From Entire Environment to Specific Event 167
Figure 2-39. SIEM Maturity Level 1 172
Figure 2-40. Correlation 173
Figure 2-41. Continuous Improvement 175
Figure 2-42. From User Login to Alert 184
Figure 3-1. Complete Laboratory Topology 204
Figure 3-2. Secure Agent Communication 204
Figure 3-3. From Network Packet to SOC Analyst 205
Figure 3-4. Laboratory Address Plan 211
Figure 3-5. Physical vs. Virtual Infrastructure 215
Figure 3-6. Snapshot Workflow 219
Figure 3-7. VMware Virtual Switch 223
Figure 3-8. VMware Networking Modes 224
Figure 3-9. Dual-Homed Ubuntu Sensor 226
Figure 3-10. From Windows Browser to Dashboard 227
Figure 3-11. Packet Visibility 229
Figure 3-12. Wazuh Service Architecture 232
Figure 3-13. Simplified Directory Tree 235
Figure 3-14. The Dashboard as the SOC Instrument Panel 241
Figure 3-15. Daily SOC Startup Workflow 246
Figure 3-16. Ubuntu Sensor Responsibilities 249
Figure 3-17. Ubuntu Agent Communication 257
Figure 3-18. From Install to Document 258
Figure 3-19. Telemetry Validation 262
Figure 3-20. Endpoint vs. Network Visibility 267
Figure 3-21. Suricata Processing Pipeline 269
Figure 3-22. From Client to HTTP Response 270
Figure 3-23. Suricata to Wazuh 273
Figure 3-24. Software Deployment Lifecycle 276
Figure 3-25. Suricata Directory Tree 278
Figure 3-26. Initial Validation 281
Figure 3-27. Detection Pipeline 284
Figure 3-28. Rule Management 288
Figure 3-29. Complete Network Detection Pipeline 292
Figure 3-30. Validation Stage 1 296
Figure 3-31. Validation Stage 2 297
Figure 3-32. Operational Validation 301
Figure 3-33. Multi-Source Correlation 305
Figure 4-1. The Investigation Lifecycle 317
Figure 4-2. Investigation Funnel 322
Figure 4-3. From PowerShell to Suricata HTTP Detection 323
Figure 4-4. The Discover Workflow 325
Figure 4-5. Discover Layout 326
Figure 4-6. Progressive Filtering 328
Figure 4-7. From Phishing Email to Data Exfiltration 334
Figure 4-8. Timeline Thinking 334
Figure 4-9. From PowerShell to Defender Detection 335
Figure 4-10. From Defender Detection to Update Service 335
Figure 4-11. Timeline Expansion 337
Figure 4-12. Attack Timeline 340
Figure 4-13. Investigation Timeline — Endpoint Compromise 341
Figure 4-14. Individual Visibility 344
Figure 4-15. From PowerShell to Suricata Alert 345
Figure 4-16. From Student01 to Remote Login 347
Figure 4-17. From Download to Defender Detection 348
Figure 4-18. Confidence Pyramid 348
Figure 4-19. Investigation Process 353
Figure 4-20. Hypothesis Testing 356
Figure 4-21. From Observations to Conclusion 362
Figure 4-22. Evidence Sources 371
Figure 4-23. From Original File to Integrity Verified 373
Figure 4-24. IOC vs. IOA 382
Figure 4-25. From WINWORD.EXE to Beaconing 382
Figure 4-26. From PowerShell to Persistence 383
Figure 4-27. ATT&CK Philosophy 389
Figure 4-28. Mapping Events to ATT&CK 391
Figure 4-29. Detection Coverage Concept 396
Figure 4-30. Example Coverage Matrix 398
Figure 4-31. From Identify Gap to Repeat 401
Figure 5-1. Detection Engineering Lifecycle 410
Figure 5-2. From WINWORD.EXE to Executable Download 412
Figure 5-3. Detection Quality 413
Figure 5-4. From Define Behavior to Deploy 414
Figure 5-5. Wazuh Event Processing Pipeline 416
Figure 5-6. Decoder Function 418
Figure 5-7. Decoder and Rule Relationship 420
Figure 5-8. From Sysmon Event to PowerShell Download Rule 420
Figure 5-9. Rule Hierarchy 425
Figure 5-10. From Parent to Encoded PowerShell 427
Figure 5-11. From Event Received to Download Rule 428
Figure 5-12. Progressive Evaluation 428
Figure 5-13. Rule Organization 430
Figure 5-14. Detection Engineering 434
Figure 5-15. From Observe Behavior to Document 435
Figure 5-16. Rule Anatomy 437
Figure 5-17. Validation Workflow 439
Figure 5-18. Detection Validation Lifecycle 443
Figure 5-19. Positive vs Negative Testing 446
Figure 5-20. Debugging Flowchart 448
Figure 5-21. Detection Outcomes 450
Figure 5-22. False Positive 455
Figure 5-23. Detection Balance 456
Figure 5-24. From WINWORD.EXE to Outbound HTTP 457
Figure 5-25. Context Improves Detection 458
Figure 5-26. Frequency Detection 459
Figure 5-27. Continuous Detection Improvement 464
Figure 5-28. Precision and Recall 467
Figure 5-29. Rule Lifecycle 469
Figure 5-30. Multi-Layer Detection 475
Figure 5-31. Packet Processing Pipeline 475
Figure 5-32. Rule Structure 478
Figure 5-33. Signature Validation 479
Figure 5-34. Correlation Improves Confidence 485
Figure 5-35. From Sysmon to Wazuh Correlation 485
Figure 5-36. Investigation Timeline — Correlated Sysmon Events 486
Figure 5-37. From WIN11 to Scheduled Task 487
Figure 5-38. From WINWORD.EXE to curl.exe 487
Figure 5-39. Behavioral Chain 488
Figure 5-40. Detection Engineering Workflow 490
Figure 5-41. Continuous Measurement 495
Figure 5-42. SOC Efficiency 498
Figure 5-43. From Windows 11 to Dashboard 505
Figure 5-44. From Network to Correlation Rule 505
Figure 5-45. From PowerShell to Correlated Alert 506
Figure 6-1. Monitoring vs Threat Hunting 517
Figure 6-2. Threat Hunting Lifecycle 519
Figure 6-3. Hunt Development 521
Figure 6-4. Building a Hypothesis 526
Figure 6-5. Hunt Prioritization 529
Figure 6-6. From PowerShell to Defender 531
Figure 6-7. Hypothesis Validation 532
Figure 6-8. From PowerShell to Timeline 536
Figure 6-9. Hunt Refinement 536
Figure 6-10. DNS Hunt — Endpoint Event Chain (Wazuh Discover) 539
Figure 6-11. From PowerShell to Timeline 541
Figure 6-12. Investigative Pivoting 542
Figure 6-13. From WINWORD.EXE to Windows Defender Detection 546
Figure 6-14. Sysmon Visibility 547
Figure 6-15. From Explorer to payload.exe 548
Figure 6-16. Command-Line Analysis 549
Figure 6-17. From PowerShell to Download 549
Figure 6-18. Endpoint Timeline 551
Figure 6-19. Dual Perspective Investigation 556
Figure 6-20. DNS Hunt — Network Perspective (Suricata) 558
Figure 6-21. Network Investigation Pyramid 560
Figure 6-22. From Every 60 Seconds to Same Packet Size 561
Figure 6-23. From Word to Incident Confirmed 564
Figure 6-24. ATT&CK-Driven Hunting 567
Figure 6-25. ATT&CK Hunting Matrix 570
Figure 6-26. Threat Hunting Playbook Workflow 577
Figure 6-27. PowerShell Found? — Decision Flow 579
Figure 6-28. Hunt Review Cycle 581
Figure 6-29. Continuous Security Validation 587
Figure 6-30. From Execution to Validate Detection 588
Figure 6-31. From Initial Access to Exfiltration 589
Figure 6-32. Atomic vs Caldera 590
Figure 6-33. From Execute Atomic Test to Improve Detection 591
Figure 6-34. Detection Validation Pipeline 593
Figure 6-35. Telemetry Validation 601
Figure 7-1. Defensive Operations 614
Figure 7-2. Sources of Evidence 616
Figure 7-3. Chain of Custody 617
Figure 7-4. Incident Response Lifecycle 618
Figure 7-5. Evidence Lifecycle 624
Figure 7-6. Evidence Priority 627
Figure 7-7. Integrity Verification 628
Figure 7-8. Windows Artifact Ecosystem 636
Figure 7-9. Registry Persistence 638
Figure 7-10. From Browser Download to Timeline 641
Figure 7-11. Volatile Evidence 646
Figure 7-12. Process Investigation 649
Figure 7-13. Live Correlation 651
Figure 7-14. Network Evidence 657
Figure 7-15. Network Conversation 659
Figure 7-16. Encrypted Communications 660
Figure 7-17. Multi-Source Correlation 662
Figure 7-18. From Scope to Conclusion 663
Figure 7-19. From Incident Report to Lessons Learned 665
Figure 7-20. Timeline Reconstruction 669
Figure 7-21. Event Correlation 671
Figure 7-22. Layered Timeline 672
Figure 7-23. Investigation Timeline — Forensic Reconstruction 674
Figure 7-24. Investigation Lifecycle 680
Figure 7-25. Root Cause Analysis 684
Figure 7-26. Continuous Improvement 687
Figure 7-27. From Detect to Improve 690
Figure 7-28. From Volatile Evidence to Chain of Custody 693
Figure 7-29. From Sysmon to Timeline 695
Figure 7-30. Enterprise Investigation 695
Figure 7-31. From Containment to Lessons Learned 696
Figure 8-1. Manual vs Automated Workflow 706
Figure 8-2. Human Decision Point 709
Figure 8-3. Automated Enrichment 711
Figure 8-4. SIEM vs SOAR 716
Figure 8-5. Enterprise SOAR Architecture 718
Figure 8-6. From High-Severity Malware Alert to Isolate Endpoint 718
Figure 8-7. SOAR Playbook 720
Figure 8-8. AI-Assisted Investigation 726
Figure 8-9. AI Hunting Workflow 729
Figure 8-10. Human Validation 731
Figure 8-11. AI-Assisted Detection Development 737
Figure 8-12. AI Detection Workflow 740
Figure 8-13. From Existing Detections to Engineering Priorities 741
Figure 8-14. Evolution of the SOC 748
Figure 8-15. XDR 751
Figure 9-1. Building Versus Operating 762
Figure 9-2. Index Lifecycle 763
Figure 9-3. Silent Failure — Disk Exhaustion 763
Figure 9-4. Retention Decision 764
Figure 9-5. Security Configuration Assessment 765
Figure 9-6. Two Different Questions 766
Figure 9-7. Vulnerability Detection 767
Figure 9-8. Wazuh API Request Flow 767
Figure 9-9. What the API Enables 768
Figure 9-10. Centralized Configuration with Agent Groups 769
Figure 9-11. Onboarding a New Log Source 769
Figure 9-12. Where Onboarding Fails 771
Figure 9-13. Capture Health Check 771
Figure 9-14. Packet Loss Produces Silent Blindness 772
Figure 9-15. Detection as Code 772
Figure 9-16. Operational Cadence 773
Figure A-1. Enterprise SOC Laboratory Topology 1009
Figure D-1. SOC Troubleshooting Sequence 1073