Front Matter
Table of Contents
| Chapter 1 — Introduction to Security Operations Centers | 16 |
| 1.1 What Is a Security Operations Center? | 18 |
| 1.2 Why Organizations Need a SOC | 19 |
| 1.3 The Evolution of Cyber Defense | 20 |
| 1.4 Events, Alerts, and Incidents | 25 |
| 1.5 Security Telemetry — The Lifeblood of the Security Operations | 33 |
| 1.6 Security Operations Center Organization and Analyst Roles | 40 |
| 1.7 A Day in the Life of a SOC Analyst | 48 |
| 1.8 Building Your First Security Operations Center Laboratory | 55 |
| 1.9 Chapter Summary | 64 |
| Chapter 2 — Understanding Security Information and Event | 64 |
| 2.1 What Is a SIEM? | 76 |
| 2.2 The SIEM Data Pipeline | 82 |
| 2.3 Event Normalization and Data Enrichment | 90 |
| 2.4 Correlation — Turning Data into Intelligence | 97 |
| 2.5 Detection Rules — How a SIEM Recognizes Suspicious Activity | 107 |
| 2.6 Searching, Investigating, and Thinking Like a SOC Analyst | 115 |
| 2.7 Wazuh — An Enterprise SIEM Platform | 124 |
| 2.8 Operating a SIEM — From Monitoring to Investigation | 133 |
| 2.9 The Wazuh Dashboard — Your Window into the Security | 143 |
| 2.10 Conducting a SIEM Investigation Using Wazuh | 153 |
| 2.11 Building an Investigation Mindset | 161 |
| 2.12 SIEM Maturity — From Log Collection to Threat Hunting | 170 |
| 2.13 Chapter Summary | 188 |
| Chapter 3 — Building the Wazuh Security Operations Center | 198 |
| 3.1 Laboratory Planning and Design | 206 |
| 3.2 Virtualization — The Foundation of the Modern Security | 214 |
| 3.3 VMware Virtual Networking | 222 |
| 3.4 Understanding the Wazuh Server | 231 |
| 3.5 The Wazuh Dashboard as an Operational Console | 240 |
| 3.6 Preparing the Ubuntu 26.04 Network Sensor | 248 |
| 3.7 Installing and Validating the Wazuh Agent on Ubuntu 26.04 | 257 |
| 3.8 Understanding Suricata — The Network Detection Engine | 266 |
| 3.9 Installing Suricata on Ubuntu 26.04 | 275 |
| 3.10 Emerging Threats Open — The Intelligence Behind Suricata | 283 |
| 3.11 Integrating Suricata with Wazuh | 291 |
| 3.12 End-to-End SOC Validation | 299 |
| 3.13 Chapter Summary | 309 |
| Chapter 4 — Navigating the Wazuh Dashboard and Conducting | 315 |
| 4.1 Mastering Discover — The Analyst’s Primary Investigation Tool | 324 |
| 4.2 Timeline Analysis — Reconstructing Security Events | 333 |
| 4.3 Event Correlation — Combining Evidence into Intelligence | 343 |
| 4.4 Hypothesis-Driven Investigations | 352 |
| 4.5 Professional Incident Documentation | 360 |
| 4.6 Evidence Collection and Preservation | 370 |
| 4.7 Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) | 378 |
| 4.8 Applying the MITRE ATT&CK® Framework to Investigations | 387 |
| 4.9 Measuring Detection Coverage with MITRE ATT&CK Navigator | 395 |
| Chapter 5 — Detection Engineering with Wazuh and Suricata | 408 |
| 5.1 Understanding the Wazuh Rule Engine | 415 |
| 5.2 Rule Hierarchy, Inheritance, and Evaluation Order | 424 |
| 5.3 Creating Your First Custom Wazuh Rule | 433 |
| 5.4 Rule Testing, Validation, and Debugging | 442 |
| 5.5 Reducing False Positives Through Detection Tuning | 454 |
| 5.6 Advanced Detection Tuning and Rule Optimization | 463 |
| 5.7 Developing Local Suricata Rules | 473 |
| 5.8 Multi-Source Correlation Rules | 483 |
| 5.9 Measuring Detection Effectiveness | 494 |
| 5.10 Detection Engineering Capstone Project | 503 |
| 5.11 Chapter Summary | 511 |
| Chapter 6 — Introduction to Threat Hunting | 516 |
| 6.1 Threat Hunting Fundamentals | 517 |
| 6.2 Developing Effective Threat Hunting Hypotheses | 525 |
| 6.3 Advanced Threat Hunting with Wazuh Discover | 535 |
| 6.4 Endpoint Threat Hunting with Sysmon | 545 |
| 6.5 Network Threat Hunting with Suricata and Packet Analysis | 555 |
| 6.6 Threat Hunting with the MITRE ATT&CK Framework | 566 |
| 6.7 Threat Hunting Playbooks and Repeatable Methodologies | 576 |
| 6.8 Adversary Emulation with Atomic Red Team and Caldera | 585 |
| 6.9 Threat Hunting and Adversary Emulation Capstone | 597 |
| 6.10 Chapter Summary | 607 |
| Chapter 7 — Introduction to Digital Forensics and Incident | 612 |
| 7.1 Introduction to Digital Forensics and Incident Response | 613 |
| 7.2 Evidence Collection and Preservation | 623 |
| 7.3 Windows Forensic Artifacts | 633 |
| 7.4 Memory Forensics and Live Response | 645 |
| 7.5 Network Forensics and Packet Analysis | 655 |
| 7.6 Timeline Analysis and Incident Reconstruction | 667 |
| 7.7 Incident Reporting and Executive Communication | 678 |
| 7.8 Digital Forensics and Incident Response Capstone | 690 |
| 7.9 Chapter Summary | 701 |
| Chapter 8 — Security Operations Automation | 705 |
| 8.1 Security Operations Automation | 706 |
| 8.2 Security Orchestration, Automation, and Response (SOAR) | 714 |
| 8.3 Artificial Intelligence in Security Operations Centers | 724 |
| 8.4 AI-Assisted Detection Engineering and Threat Hunting | 735 |
| 8.5 Enterprise Security Operations: Architecture, Evolution, and the | 746 |
| 8.6 Chapter Summary | 758 |
| Chapter 9 — Operating the Platform | 762 |
| 9.1 The Indexer, Retention, and Capacity | 763 |
| 9.2 Security Configuration Assessment | 765 |
| 9.3 Vulnerability Detection | 767 |
| 9.4 The Wazuh API | 767 |
| 9.5 Agent Groups and Centralized Configuration | 769 |
| 9.6 Onboarding a New Log Source | 769 |
| 9.7 Sensor Health and Capture Integrity | 771 |
| 9.8 Detection as Code | 772 |
| 9.9 The Operational Cadence | 773 |
| 9.10 Chapter Summary | 774 |
| Appendix A — Building the Complete Enterprise Cybersecurity | 1008 |
| Appendix B — Wazuh Administrator Command Reference | 1057 |
| Appendix C — SOC Operational Readiness Validation (ORV) Procedure and Checklist | 1074 |
| Appendix D — SOC Operational Readiness Validation (ORV) Troubleshooting and Recovery Guide | 1064 |
| Appendix E — Resetting the Lab for a New Investigation | 1079 |
| Glossary | 1089 |
| References | 1093 |