Incident Response and Investigation

Alert triaging and investigation process

Learning Outcome

4

Prioritize alerts by severity, impact, and threat confidence.

3

Differentiate True/False Positives and Negatives.

2

Describe the alert triaging and investigation workflow.

1

Explain the purpose of alert triaging in a SOC.

5

Use logs, IOCs, and MITRE ATT&CK for investigations.

A hospital emergency room receives many patients throughout the day. Some have serious conditions, while others have minor problems.

Patients = Security Alerts

Doctors quickly check each patient's symptoms, medical history, and condition to understand how serious the case is.

Reviewing an alert = Alert Analysis;

Checking seriousness = Severity Assessment

Patients with life-threatening conditions are treated first, while less serious cases wait.

Prioritizing alerts based on severity, risk, and business impact

Doctors investigate critical patients further and call specialists when necessary.

Alert Investigation and Escalation to senior security teams

The most critical patients receive immediate treatment, while false alarms or low-risk cases are handled appropriately.

True Positive alerts lead to response, while False Positives are safely closed after verification.

What is SIEM?

SIEM (Security Information and Event Management) tools collect, store, analyze, and monitor security data from systems, devices, and applications.

They provide centralized visibility to help security teams detect, investigate, and respond to threats.

Examples: Splunk, Wazuh, IBM QRadar, Microsoft Sentinel.

Role of SIEM in SOC

SOC teams use SIEM to:

Monitor security events

Detect threats

Investigate alerts

Analyze logs

Support incident response

SIEM also automates monitoring and analysis of large amounts of security data.

Why Organizations Use SIEM

Organizations generate large volumes of logs from servers, endpoints, firewalls, applications, and cloud services.

 

 

 

 

 

 

 

 

 

 

 

SIEM centralizes these logs, improves security visibility, speeds up threat detection, and supports compliance.

Popular SIEM Tools

Commercial SIEM

Commercial solutions provide advanced features, vendor support, and enterprise scalability.

Examples: Splunk, IBM QRadar, Microsoft Sentinel, LogRhythm.

Open-Source SIEM

Open-source solutions offer customizable security monitoring with lower licensing costs.

Examples: Splunk, IBM QRadar, Microsoft Sentinel, LogRhythm.

Other SIEM Platforms

Splunk

Log management, analytics, monitoring, and threat detection.

Smart Layouts

AI arranges content beautifully for better flow and impact

IBM QRadar

Log management, event correlation, and threat detection.

Microsoft Sentinel

Cloud-native SIEM and security analytics.

Wazuh

Log analysis, endpoint monitoring, vulnerability detection, and security monitoring.

What is Splunk?

Splunk is a data analytics and security monitoring platform that collects and analyzes machine-generated data.

 

It is widely used for SIEM, security monitoring, incident investigation, and threat detection.

Key Features

Log collection and indexing

Powerful search

Real-time monitoring

Alert generation

Splunk Architecture

Forwarders

Lightweight agents that collect logs and send them to Splunk.

Examples: Windows logs, Linux logs, application logs.

Indexers

Receive, process, and store data in searchable indexes.

Search Head

Provides the interface for searching data, creating dashboards, generating reports, and investigating incidents.

Splunk Dashboards

Display security information such as:

Alerts

Threat trends

Authentication activity

System events

Incident statistics

Search and Reporting

Splunk uses Splunk Processing Language (SPL) to search and analyze large datasets and supports automated reporting.

Splunk Use Cases:

Alerts

Threat trends

Authentication activity

System events

Incident statistics

What is Wazuh?

Wazuh is an open-source security platform for security monitoring, threat detection, endpoint protection, and log analysis.

 

It supports both on-premises and cloud environments.

Key Features

Log analysis

 

Endpoint monitoring

 

File integrity monitoring

 

Vulnerability detection

 

Security configuration assessment

Wazuh Architecture

Wazuh Agent

Installed on endpoints to collect security information and send it to the Wazuh Manager.

Wazuh Manager

Processes agent data, applies detection rules, and generates alerts.

Wazuh Indexer

Stores and indexes security data for searching and analysis.

Wazuh Dashboard

Provides a web interface for monitoring events, investigating alerts, and managing Wazuh.

Wazuh Monitoring

Includes:

Endpoint monitoring

Log monitoring

File integrity monitoring

Vulnerability monitoring

Security configuration monitoring

Wazuh Use Cases

Endpoint security

Vulnerability management

Threat detection

Compliance monitoring

File integrity monitoring

Splunk vs Wazuh

The choice depends on budget, requirements, and infrastructure.

Common SIEM Functions

Log Search

Allows analysts to search logs for suspicious activity and investigate incidents.

Alert Generation

Creates alerts when detection rules identify suspicious activity.

Dashboard Visualization

Log Collection

Collects logs from endpoints, servers, applications, network devices, and cloud services.

Threat Detection

Analyzes events and applies rules to identify malicious activity.

Displays security information through charts, graphs, and reports.

SIEM Workflow

Data Collection

Log Ingestion

Event Analysis

Alert Generation

Investigation

Data Collection

Gather security data from different sources.

Send logs to the SIEM for processing and storage.

Analyze events using rules and analytics.

Generate alerts for suspicious activity.

Analysts examine alerts and logs.

Provide information for incident response and remediation.

Benefits of SIEM

Centralized Visibility: Monitors security activities in one place.

 

Faster Detection: Identifies suspicious activity quickly.

 

Improved Investigation: Provides historical and detailed event data.

 

Compliance Support: Supports logging, retention, and reporting.

 

Monitoring Efficiency: Automates monitoring and analysis.

Challenges of SIEM

Large Data Volumes: 

Requires significant processing and storage.

Alert Fatigue: 

High alert volumes can overwhelm analysts.

Rule Tuning: 

Rules require continuous adjustment.

Resource Requirements: 

Needs skilled personnel and infrastructure.

Learning Curve: 

Analysts need time to learn SIEM tools and workflows.

Summary

5

SIEM tools improve SOC operations and incident response.

4

Both support logging, alerting, investigation, and threat detection.

3

Wazuh is an open-source platform with strong endpoint monitoring.

2

Splunk is a commercial SIEM with powerful search and analytics.

1

SIEM tools collect, analyze, and monitor security events.

Quiz

Which of the following is an open-source SIEM platform?

B. IBM QRadar

C. Microsoft Sentinel

D. Wazuh

A. Splunk

Quiz-Answer

D. Wazuh

Which of the following is an open-source SIEM platform?

A. Splunk

B. IBM QRadar

C. Microsoft Sentinel