Ravindra BagaleCourses & study guides

31. SOC, SIEM and Incident Response

Chala mitrano, aattaparyant aapan attacker cha drushtikon baghitla – scan, exploit, crack. Pan company madhe sarvat jast jobs defence baju la aahet: SOC (Security Operations Centre). SOC analyst che kaam mhanje logs baghne, alert samjun ghene, ani attack zala tar tyala thambavne. Ya chapter madhe logs kuthe astat, SIEM kay karto, Wazuh sarkha free tool kasa vaparaycha, ani incident zala tar step-by-step kay karaycha he shiku. Fresher sathi SOC analyst ha sarvat common entry job aahe, mhanun he chapter lakshapurvak vacha. Samjla ka? Chala!

What you will learn in this chapter

  • What a SOC is, its tiers (L1, L2, L3) and daily work
  • Where logs live on Linux, Apache/Nginx, Windows and AWS
  • What a SIEM does, with Splunk, the ELK stack and Wazuh compared
  • Setting up Wazuh in your lab and seeing real alerts from your own attacks
  • Alert triage: true positive, false positive, severity and escalation
  • The incident response lifecycle (NIST) with a worked example

Lab scope

Generate alerts only by attacking your own lab machines (Kali against Metasploitable/DVWA on the host-only network, Chapter 18). Never test detection by attacking real systems.

Concepts in this chapter

  1. 31.1What a SOC Is
  2. 31.2Where Logs Live
  3. 31.3What a SIEM Does
  4. 31.4Wazuh Lab: See Your Own Attacks
  5. 31.5Alert Triage
  6. 31.6The Incident Response Lifecycle
  7. 31.7Red vs Blue, Project and Real Incidents

The chapter recap is at the end of the last concept page.