Front Matter
List of Figures
| Figure 1-1. Core Functions of a Security Operations Center | 18 |
| Figure 1-2. Evolution of Enterprise Cyber Defense | 23 |
| Figure 1-3. Events Become Alerts | 27 |
| Figure 1-4. Event → Alert → Incident | 30 |
| Figure 1-5. Telemetry Is Observation | 35 |
| Figure 1-6. From Data to Intelligence | 37 |
| Figure 1-7. Security Monitoring Pipeline | 39 |
| Figure 1-8. The Three Pillars of a Security Operations Center | 41 |
| Figure 1-9. Typical SOC Structure | 42 |
| Figure 1-10. The Analyst Workflow | 47 |
| Figure 1-11. Daily SOC Startup Checklist | 49 |
| Figure 1-12. Multi-Sensor Investigation | 53 |
| Figure 1-13. Laboratory Architecture | 57 |
| Figure 1-14. Endpoint Telemetry Pipeline | 62 |
| Figure 1-15. Network Detection Pipeline | 62 |
| Figure 1-16. Laboratory Method | 71 |
| Figure 2-1. Evolution of SIEM | 77 |
| Figure 2-2. Security Before SIEM | 78 |
| Figure 2-3. Security After SIEM | 78 |
| Figure 2-4. Event Generation | 83 |
| Figure 2-5. Multiple Sensors Observe One System | 84 |
| Figure 2-6. Secure Telemetry Transport | 85 |
| Figure 2-7. Decoding | 87 |
| Figure 2-8. Complete Wazuh Processing Pipeline | 89 |
| Figure 2-9. Did Nmap Generate Traffic? — Decision Flow | 89 |
| Figure 2-10. Before Normalization | 91 |
| Figure 2-11. After Normalization | 92 |
| Figure 2-12. Data Enrichment | 95 |
| Figure 2-13. Correlation Timeline | 99 |
| Figure 2-14. Correlation Dimensions | 104 |
| Figure 2-15. Security Event — Decision Flow | 108 |
| Figure 2-16. Rule Logic | 109 |
| Figure 2-17. Rule Tuning | 112 |
| Figure 2-18. The Investigation Mindset | 117 |
| Figure 2-19. From Hostname to Specific Process | 117 |
| Figure 2-20. Investigation Timeline — Authentication Events | 118 |
| Figure 2-21. Investigation Timeline — Ordering Events by Time | 119 |
| Figure 2-22. Timeline Investigation | 120 |
| Figure 2-23. Alert — Decision Flow | 123 |
| Figure 2-24. Wazuh Architecture | 125 |
| Figure 2-25. Responsibilities of Each Component | 129 |
| Figure 2-26. Wazuh as the Central Hub | 131 |
| Figure 2-27. From Begin Shift to Continuous Improvement | 134 |
| Figure 2-28. Operational Monitoring vs. Security Monitoring | 136 |
| Figure 2-29. From Alert to Conclusion | 137 |
| Figure 2-30. Dashboard vs. Investigation | 139 |
| Figure 2-31. Continuous Improvement Cycle | 141 |
| Figure 2-32. Dashboard Responsibilities | 144 |
| Figure 2-33. Alert Investigation Workflow | 147 |
| Figure 2-34. Investigation Methodology | 154 |
| Figure 2-35. Evidence Correlation | 157 |
| Figure 2-36. Questions Drive Investigations | 162 |
| Figure 2-37. Corroborating Evidence | 165 |
| Figure 2-38. From Entire Environment to Specific Event | 167 |
| Figure 2-39. SIEM Maturity Level 1 | 172 |
| Figure 2-40. Correlation | 173 |
| Figure 2-41. Continuous Improvement | 175 |
| Figure 2-42. From User Login to Alert | 184 |
| Figure 3-1. Complete Laboratory Topology | 204 |
| Figure 3-2. Secure Agent Communication | 204 |
| Figure 3-3. From Network Packet to SOC Analyst | 205 |
| Figure 3-4. Laboratory Address Plan | 211 |
| Figure 3-5. Physical vs. Virtual Infrastructure | 215 |
| Figure 3-6. Snapshot Workflow | 219 |
| Figure 3-7. VMware Virtual Switch | 223 |
| Figure 3-8. VMware Networking Modes | 224 |
| Figure 3-9. Dual-Homed Ubuntu Sensor | 226 |
| Figure 3-10. From Windows Browser to Dashboard | 227 |
| Figure 3-11. Packet Visibility | 229 |
| Figure 3-12. Wazuh Service Architecture | 232 |
| Figure 3-13. Simplified Directory Tree | 235 |
| Figure 3-14. The Dashboard as the SOC Instrument Panel | 241 |
| Figure 3-15. Daily SOC Startup Workflow | 246 |
| Figure 3-16. Ubuntu Sensor Responsibilities | 249 |
| Figure 3-17. Ubuntu Agent Communication | 257 |
| Figure 3-18. From Install to Document | 258 |
| Figure 3-19. Telemetry Validation | 262 |
| Figure 3-20. Endpoint vs. Network Visibility | 267 |
| Figure 3-21. Suricata Processing Pipeline | 269 |
| Figure 3-22. From Client to HTTP Response | 270 |
| Figure 3-23. Suricata to Wazuh | 273 |
| Figure 3-24. Software Deployment Lifecycle | 276 |
| Figure 3-25. Suricata Directory Tree | 278 |
| Figure 3-26. Initial Validation | 281 |
| Figure 3-27. Detection Pipeline | 284 |
| Figure 3-28. Rule Management | 288 |
| Figure 3-29. Complete Network Detection Pipeline | 292 |
| Figure 3-30. Validation Stage 1 | 296 |
| Figure 3-31. Validation Stage 2 | 297 |
| Figure 3-32. Operational Validation | 301 |
| Figure 3-33. Multi-Source Correlation | 305 |
| Figure 4-1. The Investigation Lifecycle | 317 |
| Figure 4-2. Investigation Funnel | 322 |
| Figure 4-3. From PowerShell to Suricata HTTP Detection | 323 |
| Figure 4-4. The Discover Workflow | 325 |
| Figure 4-5. Discover Layout | 326 |
| Figure 4-6. Progressive Filtering | 328 |
| Figure 4-7. From Phishing Email to Data Exfiltration | 334 |
| Figure 4-8. Timeline Thinking | 334 |
| Figure 4-9. From PowerShell to Defender Detection | 335 |
| Figure 4-10. From Defender Detection to Update Service | 335 |
| Figure 4-11. Timeline Expansion | 337 |
| Figure 4-12. Attack Timeline | 340 |
| Figure 4-13. Investigation Timeline — Endpoint Compromise | 341 |
| Figure 4-14. Individual Visibility | 344 |
| Figure 4-15. From PowerShell to Suricata Alert | 345 |
| Figure 4-16. From Student01 to Remote Login | 347 |
| Figure 4-17. From Download to Defender Detection | 348 |
| Figure 4-18. Confidence Pyramid | 348 |
| Figure 4-19. Investigation Process | 353 |
| Figure 4-20. Hypothesis Testing | 356 |
| Figure 4-21. From Observations to Conclusion | 362 |
| Figure 4-22. Evidence Sources | 371 |
| Figure 4-23. From Original File to Integrity Verified | 373 |
| Figure 4-24. IOC vs. IOA | 382 |
| Figure 4-25. From WINWORD.EXE to Beaconing | 382 |
| Figure 4-26. From PowerShell to Persistence | 383 |
| Figure 4-27. ATT&CK Philosophy | 389 |
| Figure 4-28. Mapping Events to ATT&CK | 391 |
| Figure 4-29. Detection Coverage Concept | 396 |
| Figure 4-30. Example Coverage Matrix | 398 |
| Figure 4-31. From Identify Gap to Repeat | 401 |
| Figure 5-1. Detection Engineering Lifecycle | 410 |
| Figure 5-2. From WINWORD.EXE to Executable Download | 412 |
| Figure 5-3. Detection Quality | 413 |
| Figure 5-4. From Define Behavior to Deploy | 414 |
| Figure 5-5. Wazuh Event Processing Pipeline | 416 |
| Figure 5-6. Decoder Function | 418 |
| Figure 5-7. Decoder and Rule Relationship | 420 |
| Figure 5-8. From Sysmon Event to PowerShell Download Rule | 420 |
| Figure 5-9. Rule Hierarchy | 425 |
| Figure 5-10. From Parent to Encoded PowerShell | 427 |
| Figure 5-11. From Event Received to Download Rule | 428 |
| Figure 5-12. Progressive Evaluation | 428 |
| Figure 5-13. Rule Organization | 430 |
| Figure 5-14. Detection Engineering | 434 |
| Figure 5-15. From Observe Behavior to Document | 435 |
| Figure 5-16. Rule Anatomy | 437 |
| Figure 5-17. Validation Workflow | 439 |
| Figure 5-18. Detection Validation Lifecycle | 443 |
| Figure 5-19. Positive vs Negative Testing | 446 |
| Figure 5-20. Debugging Flowchart | 448 |
| Figure 5-21. Detection Outcomes | 450 |
| Figure 5-22. False Positive | 455 |
| Figure 5-23. Detection Balance | 456 |
| Figure 5-24. From WINWORD.EXE to Outbound HTTP | 457 |
| Figure 5-25. Context Improves Detection | 458 |
| Figure 5-26. Frequency Detection | 459 |
| Figure 5-27. Continuous Detection Improvement | 464 |
| Figure 5-28. Precision and Recall | 467 |
| Figure 5-29. Rule Lifecycle | 469 |
| Figure 5-30. Multi-Layer Detection | 475 |
| Figure 5-31. Packet Processing Pipeline | 475 |
| Figure 5-32. Rule Structure | 478 |
| Figure 5-33. Signature Validation | 479 |
| Figure 5-34. Correlation Improves Confidence | 485 |
| Figure 5-35. From Sysmon to Wazuh Correlation | 485 |
| Figure 5-36. Investigation Timeline — Correlated Sysmon Events | 486 |
| Figure 5-37. From WIN11 to Scheduled Task | 487 |
| Figure 5-38. From WINWORD.EXE to curl.exe | 487 |
| Figure 5-39. Behavioral Chain | 488 |
| Figure 5-40. Detection Engineering Workflow | 490 |
| Figure 5-41. Continuous Measurement | 495 |
| Figure 5-42. SOC Efficiency | 498 |
| Figure 5-43. From Windows 11 to Dashboard | 505 |
| Figure 5-44. From Network to Correlation Rule | 505 |
| Figure 5-45. From PowerShell to Correlated Alert | 506 |
| Figure 6-1. Monitoring vs Threat Hunting | 517 |
| Figure 6-2. Threat Hunting Lifecycle | 519 |
| Figure 6-3. Hunt Development | 521 |
| Figure 6-4. Building a Hypothesis | 526 |
| Figure 6-5. Hunt Prioritization | 529 |
| Figure 6-6. From PowerShell to Defender | 531 |
| Figure 6-7. Hypothesis Validation | 532 |
| Figure 6-8. From PowerShell to Timeline | 536 |
| Figure 6-9. Hunt Refinement | 536 |
| Figure 6-10. DNS Hunt — Endpoint Event Chain (Wazuh Discover) | 539 |
| Figure 6-11. From PowerShell to Timeline | 541 |
| Figure 6-12. Investigative Pivoting | 542 |
| Figure 6-13. From WINWORD.EXE to Windows Defender Detection | 546 |
| Figure 6-14. Sysmon Visibility | 547 |
| Figure 6-15. From Explorer to payload.exe | 548 |
| Figure 6-16. Command-Line Analysis | 549 |
| Figure 6-17. From PowerShell to Download | 549 |
| Figure 6-18. Endpoint Timeline | 551 |
| Figure 6-19. Dual Perspective Investigation | 556 |
| Figure 6-20. DNS Hunt — Network Perspective (Suricata) | 558 |
| Figure 6-21. Network Investigation Pyramid | 560 |
| Figure 6-22. From Every 60 Seconds to Same Packet Size | 561 |
| Figure 6-23. From Word to Incident Confirmed | 564 |
| Figure 6-24. ATT&CK-Driven Hunting | 567 |
| Figure 6-25. ATT&CK Hunting Matrix | 570 |
| Figure 6-26. Threat Hunting Playbook Workflow | 577 |
| Figure 6-27. PowerShell Found? — Decision Flow | 579 |
| Figure 6-28. Hunt Review Cycle | 581 |
| Figure 6-29. Continuous Security Validation | 587 |
| Figure 6-30. From Execution to Validate Detection | 588 |
| Figure 6-31. From Initial Access to Exfiltration | 589 |
| Figure 6-32. Atomic vs Caldera | 590 |
| Figure 6-33. From Execute Atomic Test to Improve Detection | 591 |
| Figure 6-34. Detection Validation Pipeline | 593 |
| Figure 6-35. Telemetry Validation | 601 |
| Figure 7-1. Defensive Operations | 614 |
| Figure 7-2. Sources of Evidence | 616 |
| Figure 7-3. Chain of Custody | 617 |
| Figure 7-4. Incident Response Lifecycle | 618 |
| Figure 7-5. Evidence Lifecycle | 624 |
| Figure 7-6. Evidence Priority | 627 |
| Figure 7-7. Integrity Verification | 628 |
| Figure 7-8. Windows Artifact Ecosystem | 636 |
| Figure 7-9. Registry Persistence | 638 |
| Figure 7-10. From Browser Download to Timeline | 641 |
| Figure 7-11. Volatile Evidence | 646 |
| Figure 7-12. Process Investigation | 649 |
| Figure 7-13. Live Correlation | 651 |
| Figure 7-14. Network Evidence | 657 |
| Figure 7-15. Network Conversation | 659 |
| Figure 7-16. Encrypted Communications | 660 |
| Figure 7-17. Multi-Source Correlation | 662 |
| Figure 7-18. From Scope to Conclusion | 663 |
| Figure 7-19. From Incident Report to Lessons Learned | 665 |
| Figure 7-20. Timeline Reconstruction | 669 |
| Figure 7-21. Event Correlation | 671 |
| Figure 7-22. Layered Timeline | 672 |
| Figure 7-23. Investigation Timeline — Forensic Reconstruction | 674 |
| Figure 7-24. Investigation Lifecycle | 680 |
| Figure 7-25. Root Cause Analysis | 684 |
| Figure 7-26. Continuous Improvement | 687 |
| Figure 7-27. From Detect to Improve | 690 |
| Figure 7-28. From Volatile Evidence to Chain of Custody | 693 |
| Figure 7-29. From Sysmon to Timeline | 695 |
| Figure 7-30. Enterprise Investigation | 695 |
| Figure 7-31. From Containment to Lessons Learned | 696 |
| Figure 8-1. Manual vs Automated Workflow | 706 |
| Figure 8-2. Human Decision Point | 709 |
| Figure 8-3. Automated Enrichment | 711 |
| Figure 8-4. SIEM vs SOAR | 716 |
| Figure 8-5. Enterprise SOAR Architecture | 718 |
| Figure 8-6. From High-Severity Malware Alert to Isolate Endpoint | 718 |
| Figure 8-7. SOAR Playbook | 720 |
| Figure 8-8. AI-Assisted Investigation | 726 |
| Figure 8-9. AI Hunting Workflow | 729 |
| Figure 8-10. Human Validation | 731 |
| Figure 8-11. AI-Assisted Detection Development | 737 |
| Figure 8-12. AI Detection Workflow | 740 |
| Figure 8-13. From Existing Detections to Engineering Priorities | 741 |
| Figure 8-14. Evolution of the SOC | 748 |
| Figure 8-15. XDR | 751 |
| Figure 9-1. Building Versus Operating | 762 |
| Figure 9-2. Index Lifecycle | 763 |
| Figure 9-3. Silent Failure — Disk Exhaustion | 763 |
| Figure 9-4. Retention Decision | 764 |
| Figure 9-5. Security Configuration Assessment | 765 |
| Figure 9-6. Two Different Questions | 766 |
| Figure 9-7. Vulnerability Detection | 767 |
| Figure 9-8. Wazuh API Request Flow | 767 |
| Figure 9-9. What the API Enables | 768 |
| Figure 9-10. Centralized Configuration with Agent Groups | 769 |
| Figure 9-11. Onboarding a New Log Source | 769 |
| Figure 9-12. Where Onboarding Fails | 771 |
| Figure 9-13. Capture Health Check | 771 |
| Figure 9-14. Packet Loss Produces Silent Blindness | 772 |
| Figure 9-15. Detection as Code | 772 |
| Figure 9-16. Operational Cadence | 773 |
| Figure A-1. Enterprise SOC Laboratory Topology | 1009 |
| Figure D-1. SOC Troubleshooting Sequence | 1073 |