Kalos Cybersecurity LLC

Table of Contents

Chapter 1 — Introduction to Security Operations Centers 16
    1.1 What Is a Security Operations Center? 18
    1.2 Why Organizations Need a SOC 19
    1.3 The Evolution of Cyber Defense 20
    1.4 Events, Alerts, and Incidents 25
    1.5 Security Telemetry — The Lifeblood of the Security Operations 33
    1.6 Security Operations Center Organization and Analyst Roles 40
    1.7 A Day in the Life of a SOC Analyst 48
    1.8 Building Your First Security Operations Center Laboratory 55
    1.9 Chapter Summary 64
Chapter 2 — Understanding Security Information and Event 64
    2.1 What Is a SIEM? 76
    2.2 The SIEM Data Pipeline 82
    2.3 Event Normalization and Data Enrichment 90
    2.4 Correlation — Turning Data into Intelligence 97
    2.5 Detection Rules — How a SIEM Recognizes Suspicious Activity 107
    2.6 Searching, Investigating, and Thinking Like a SOC Analyst 115
    2.7 Wazuh — An Enterprise SIEM Platform 124
    2.8 Operating a SIEM — From Monitoring to Investigation 133
    2.9 The Wazuh Dashboard — Your Window into the Security 143
    2.10 Conducting a SIEM Investigation Using Wazuh 153
    2.11 Building an Investigation Mindset 161
    2.12 SIEM Maturity — From Log Collection to Threat Hunting 170
    2.13 Chapter Summary 188
Chapter 3 — Building the Wazuh Security Operations Center 198
    3.1 Laboratory Planning and Design 206
    3.2 Virtualization — The Foundation of the Modern Security 214
    3.3 VMware Virtual Networking 222
    3.4 Understanding the Wazuh Server 231
    3.5 The Wazuh Dashboard as an Operational Console 240
    3.6 Preparing the Ubuntu 26.04 Network Sensor 248
    3.7 Installing and Validating the Wazuh Agent on Ubuntu 26.04 257
    3.8 Understanding Suricata — The Network Detection Engine 266
    3.9 Installing Suricata on Ubuntu 26.04 275
    3.10 Emerging Threats Open — The Intelligence Behind Suricata 283
    3.11 Integrating Suricata with Wazuh 291
    3.12 End-to-End SOC Validation 299
    3.13 Chapter Summary 309
Chapter 4 — Navigating the Wazuh Dashboard and Conducting 315
    4.1 Mastering Discover — The Analyst’s Primary Investigation Tool 324
    4.2 Timeline Analysis — Reconstructing Security Events 333
    4.3 Event Correlation — Combining Evidence into Intelligence 343
    4.4 Hypothesis-Driven Investigations 352
    4.5 Professional Incident Documentation 360
    4.6 Evidence Collection and Preservation 370
    4.7 Indicators of Compromise (IOCs) and Indicators of Attack (IOAs) 378
    4.8 Applying the MITRE ATT&CK® Framework to Investigations 387
    4.9 Measuring Detection Coverage with MITRE ATT&CK Navigator 395
Chapter 5 — Detection Engineering with Wazuh and Suricata 408
    5.1 Understanding the Wazuh Rule Engine 415
    5.2 Rule Hierarchy, Inheritance, and Evaluation Order 424
    5.3 Creating Your First Custom Wazuh Rule 433
    5.4 Rule Testing, Validation, and Debugging 442
    5.5 Reducing False Positives Through Detection Tuning 454
    5.6 Advanced Detection Tuning and Rule Optimization 463
    5.7 Developing Local Suricata Rules 473
    5.8 Multi-Source Correlation Rules 483
    5.9 Measuring Detection Effectiveness 494
    5.10 Detection Engineering Capstone Project 503
    5.11 Chapter Summary 511
Chapter 6 — Introduction to Threat Hunting 516
    6.1 Threat Hunting Fundamentals 517
    6.2 Developing Effective Threat Hunting Hypotheses 525
    6.3 Advanced Threat Hunting with Wazuh Discover 535
    6.4 Endpoint Threat Hunting with Sysmon 545
    6.5 Network Threat Hunting with Suricata and Packet Analysis 555
    6.6 Threat Hunting with the MITRE ATT&CK Framework 566
    6.7 Threat Hunting Playbooks and Repeatable Methodologies 576
    6.8 Adversary Emulation with Atomic Red Team and Caldera 585
    6.9 Threat Hunting and Adversary Emulation Capstone 597
    6.10 Chapter Summary 607
Chapter 7 — Introduction to Digital Forensics and Incident 612
    7.1 Introduction to Digital Forensics and Incident Response 613
    7.2 Evidence Collection and Preservation 623
    7.3 Windows Forensic Artifacts 633
    7.4 Memory Forensics and Live Response 645
    7.5 Network Forensics and Packet Analysis 655
    7.6 Timeline Analysis and Incident Reconstruction 667
    7.7 Incident Reporting and Executive Communication 678
    7.8 Digital Forensics and Incident Response Capstone 690
    7.9 Chapter Summary 701
Chapter 8 — Security Operations Automation 705
    8.1 Security Operations Automation 706
    8.2 Security Orchestration, Automation, and Response (SOAR) 714
    8.3 Artificial Intelligence in Security Operations Centers 724
    8.4 AI-Assisted Detection Engineering and Threat Hunting 735
    8.5 Enterprise Security Operations: Architecture, Evolution, and the 746
    8.6 Chapter Summary 758
Chapter 9 — Operating the Platform 762
    9.1 The Indexer, Retention, and Capacity 763
    9.2 Security Configuration Assessment 765
    9.3 Vulnerability Detection 767
    9.4 The Wazuh API 767
    9.5 Agent Groups and Centralized Configuration 769
    9.6 Onboarding a New Log Source 769
    9.7 Sensor Health and Capture Integrity 771
    9.8 Detection as Code 772
    9.9 The Operational Cadence 773
    9.10 Chapter Summary 774
Appendix A — Building the Complete Enterprise Cybersecurity 1008
Appendix B — Wazuh Administrator Command Reference 1057
Appendix C — SOC Operational Readiness Validation (ORV) Procedure and Checklist 1074
Appendix D — SOC Operational Readiness Validation (ORV) Troubleshooting and Recovery Guide 1064
Appendix E — Resetting the Lab for a New Investigation 1079
Glossary 1089
References 1093