🎯 Goal

The goal of today’s session was to understand how Security Operations Center (SOC) analysts transform raw logs into actionable evidence.

Rather than focusing on tools or commands alone, the emphasis was on learning the investigation mindset that allows analysts to interpret large volumes of system activity quickly and effectively.

The objective was to learn how to:

β€’ identify meaningful signals in logs
β€’ isolate relevant information
β€’ group events into patterns
β€’ convert raw data into investigative evidence


πŸ›  What I Did

Studied the Core SOC Investigation Loop

A key concept learned today was the investigation loop used by analysts when reading logs.

Instead of reading events sequentially, analysts typically follow a structured workflow:

inspect β†’ filter β†’ extract β†’ aggregate β†’ interpret

This means:

β€’ first understanding the data format
β€’ filtering only relevant events
β€’ extracting key fields
β€’ grouping events to reveal patterns
β€’ interpreting the result in context

This structured workflow prevents analysts from becoming overwhelmed by large datasets.


Practiced the Concept of β€œSignal vs Noise”

Most system logs contain enormous amounts of normal activity.

The challenge for analysts is identifying which events contain useful signals.

Examples of signals include:

β€’ repeated login failures
β€’ unusual process execution
β€’ suspicious parent-child processes
β€’ encoded PowerShell commands
β€’ repeated external network connections

Learning to ignore irrelevant information while focusing on these signals is a fundamental SOC skill.


Learned the Core Terminal Pipeline Pattern

A very common analysis workflow in Linux involves combining several small tools together.

The standard investigation pipeline looks like:

grep β†’ awk β†’ sort β†’ uniq β†’ sort

This pipeline allows analysts to:

β€’ filter specific events
β€’ extract important fields
β€’ count repeated values
β€’ identify the most common occurrences

Understanding this pipeline is extremely useful when working with text-based logs.


πŸ”— Key Cybersecurity Connections

SOC analysts rarely read logs line by line.

Instead they convert large datasets into statistical summaries that highlight anomalies.

For example, rather than manually reading thousands of authentication events, analysts may quickly calculate:

β€’ the most common attacking IP addresses
β€’ the most frequently targeted usernames
β€’ the number of failed logins per minute

These patterns often reveal attacks such as:

β€’ password spraying
β€’ brute force attempts
β€’ credential stuffing


πŸ” Investigation Questions

When analyzing logs in a SOC environment, investigators often begin with questions such as:

  • Is a single IP address generating repeated login attempts?
  • Are multiple accounts targeted within a short time window?
  • Is a suspicious process execution occurring on multiple hosts?
  • Are command-line arguments showing encoded or obfuscated commands?
  • Are there repeated network connections to unfamiliar external infrastructure?
  • Does the activity align with known attack patterns or techniques?

These questions guide analysts in transforming raw logs into meaningful investigative evidence.


🚨 Detection Opportunities

Several detection opportunities arise when analyzing aggregated log data:

  • detecting high volumes of authentication failures
  • identifying unusual parent-child process relationships
  • detecting encoded command execution such as Base64 PowerShell
  • monitoring repeated connections to rare or newly observed domains
  • identifying abnormal user behavior patterns across systems

Useful telemetry sources include:

  • authentication logs
  • endpoint process creation logs
  • network connection logs
  • DNS logs
  • EDR telemetry.

🧭 MITRE ATT&CK Techniques

SOC investigations frequently uncover activity associated with techniques such as:

  • T1110 β€” Brute Force
  • T1078 β€” Valid Accounts
  • T1059 β€” Command and Scripting Interpreter
  • T1105 β€” Ingress Tool Transfer

These techniques often become visible only after analysts aggregate and interpret log data.


⚠ Challenges

Understanding the Difference Between Data and Evidence

Initially it was difficult to separate raw events from meaningful evidence.

Logs contain huge amounts of data, but most of it is not relevant to an investigation.

Learning to ask the right investigative questions was essential to extracting useful information.


πŸ“š What I Learned

Several important insights emerged from today’s work.

SOC analysis is hypothesis-driven

Instead of searching randomly through logs, analysts begin with a question such as:

β€œIs a single IP attempting multiple logins?”

Once the hypothesis is defined, the investigation focuses on collecting evidence to confirm or disprove it.


Aggregation reveals hidden patterns

Single events rarely indicate malicious activity.

However, grouping events together can reveal clear patterns such as repeated failures or suspicious frequency.

This is why commands like sort and uniq are extremely useful for log analysis.


➑ Next Steps

The next stage of learning will focus on:

β€’ identifying suspicious process execution
β€’ recognizing malicious parent-child process chains
β€’ detecting encoded commands used by attackers

These skills are important for identifying malware execution in system logs.


🧠 Reflection

Today’s work shifted the focus from tools to thinking.

Understanding the investigative process behind SOC analysis makes logs far less intimidating.

Instead of appearing as random data, logs begin to reveal patterns and behavioral signals that can indicate malicious activity.


🧩 Lessons Learned

What worked

Studying the investigation workflow clarified how analysts approach large datasets.

What broke

Initially it was difficult to decide which information was relevant.

Why it broke

Without a clear investigative question, logs appear overwhelming.

Fix / takeaway

Always begin with a hypothesis and then collect only the evidence required to test it.


πŸ“ˆ Skill Progression Context

The skills developed today directly support core SOC responsibilities such as:

β€’ log triage
β€’ anomaly detection
β€’ authentication attack analysis

Learning how to extract evidence from logs is a foundational skill for SOC analysts and incident responders.