Skip to content

Instantly share code, notes, and snippets.

@ezzeldinadel
Last active November 19, 2020 10:28
Show Gist options
  • Save ezzeldinadel/8beaa2fb0cfeb9dd49c8873171679202 to your computer and use it in GitHub Desktop.
Save ezzeldinadel/8beaa2fb0cfeb9dd49c8873171679202 to your computer and use it in GitHub Desktop.
What should a SIEM see in a SOC?
If your SOC doesn't see
NIDS/NIPS (NDR/NTA)
HIDS/HIPS (EDR/EPP)
Netflow
PCAP
Sys Integrity Checkers
AV
User activity monitoring
DLP and IP
Firewalls (NFW/UTM)
Web filter
Mail gateway
Email server logs
Content detonation device
Router/Switches
DNS
DHCP
NAC
VPN and Remote Access
Local Windows event logs
Windows Domain Controller
SSO and IAM
Physical Security (fob and badge readers)
OS Logs
Any COTS or custom app (APPmon)
Web Server
DB
Vuln Scan (of apps, networks and hosts)
Cloud Access (CASB, trails, etc)
your SOC is still blind.
Invest in big data and scale with automation and remember to always-always assume breach!
Intel sources for ur SOC: https://gist.github.com/ezzeldinadel/676f99d0106cfa16ed4b119213b68c38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment