What is a SOC Analyst? Understanding SOC Tiers and SIEM Tools

 

HELLO FRIENDS

WELCOME TO MY CYPHER LOG

SECURITY OPERATION CENTRES [SOC] & SIEM BASICS

     Hello guys, today I'm going to share what I have learned today. When I started this cybersecurity learning journey I always heard about the common job role which is SOC analyst, I always wondered what it could be and what the analyst will do and today I got the answer. Yeah you guessed right that's the main topic we are going to see here and also the software they are using in the job, which is security operations center [SOC] and SIEM.
Ok let's see more about that role and that software, actually it's really interesting.

WHAT IS SOC

       SOC is nothing but a security operations centre to monitor, detect and analyze every incident in cybersecurity.
Actually it has a centralized facility and people are working as a team to detect any incidents. The centres were open 24/7 the whole year. Here people were working in person and also have a virtual team too.
It's like having a police station and hospitals which were open 24/7 yeah both were working the same but the hospital and police station for us and the SOC for the virtual world.
In The SOC centre, not everyone has the same work actually that's how every department works. It had mainly 3 tiers and if you are also still confused in what job will I get after graduation, I hope this information will help you in that case. To be honest today is the day I known about different job roles in SOC analyst.
Let's see about the three tires.

THE SOC ANALYST TIERS

 TIER 1 - [ Triage analyst ]

       They are the first responders because they are the one who monitor alerts, filter out the fake alarms and escalate the real threats.
Let's take real life example for this to be more clear.
  Every apartments have and any public places have CCTV cameras right and there are some guards are there to monitor everything day and night through it and if there is anything being suspicious they tend to take the next step.
That's how the first tier analyst works.

TIER 2 : [ Incident responder ]

   They are the detectives who would analyze the threat and figure out how deep the breach is.
Let's be clear with an example
   As the above example, the security guards will go and check there too but they will immediately contact the police to investigate the things and take actions, that's how the tier two analyst works.

TIER 3 : [ Threat hunters ] 

    The analysts who are in this tier are elite level hackers but they won't do illegal things they will work for us and hack the attackers network. They won't wait for the alerts to be alert they are already in the defence mode to keep yhe system secure. They always check for suspicious things.
They are like soldiers in the countries border, who are being alert every minute.
These are the three tiers and how it works.


Let's move into the next topic which is SIEM

SIEM - Security information and event management

   Actually SIEM is not something other than this SOC both are combined to keep the network secured. SOC is the crew and SIEM is the tool they are using.
   The SIEM were used to make the work easier for the crew. Let's take an application as an example how it works. We are all login into some applications daily and we are not the only one who is going to login in a day vast number of people will login at the same day, do you think it's easier to monitor everything manually, it would be a biggest headache for them.
That's why they are using it, this software does three things to make the work lite. Let's see about that 

AGGREGATION 

 It will monitor every log from every device and combine them into a single dashboard.

CORRELATION

    This is the one which shows alert to the analysts if there is an suspicious activity it won't just raise a flag based on a single thing they would connect every suspicious activity like, if the firewall shows the blocked port scan, antivirus shows a malware detection and failed continuous attempt login. Then they will raise the alert.

ALERTING

    It just sends the high prioritised alert, after the correlation detects it. It will send it to the analyst who is in the TIER 1.
And this is how the whole system works.


So that's it guys, I tried my best to explain the things as I have learned and I hope you guys understood it well, if you have any doubts feel free to ask and together we can figure it out..

THANK YOU

Comments

Popular posts from this blog

Day 2: Understanding the CIA Triad, AAA

Cryptography Basics: Encryption Types & Hashing Explained

Cyber Security Day 4: Understanding Layered Security & Defence in Depth