π Day 74 β Turning Raw Logs into Patterns and Evidence
π Topic
Understanding how aggregation transforms logs into meaningful signals.
π― Goal
Learn how counting and grouping log entries reveals attack patterns.
π What I Did
Took raw authentication logs and applied:
- sorting
- counting
- ranking
Used:
sort | uniq -c | sort -nr
to identify:
- top attacking IPs
- frequency of attempts
The result was a small but important shift: instead of looking at individual events, I was building a ranked view of what deserved attention first.
π Key Cybersecurity Connections
SOC analysts do not read logs line-by-line.
They:
- aggregate
- group
- prioritize
π Investigation Questions
- What is the most frequent event?
- Which IP appears most often?
- What stands out from the baseline?
π¨ Detection Opportunities
- abnormal spikes in activity
- dominant IP addresses
- repeated patterns over time
π§ MITRE ATT&CK Techniques
- T1110 β Brute Force
β Challenges
Understanding that:
- raw logs = noise
- processed logs = signal
π What I Learned
- counting creates visibility
- patterns reveal attacker behavior
- prioritization is critical
- aggregation is how raw events become a triage queue
- the first job is to find what deserves attention fastest
- prioritization is part of the analysis, not something that happens after it
β‘ Next Steps
- visualize log data
- correlate across multiple sources
π§ Reflection
This is where analysis starts:
not reading logs, but summarizing them
π§© Lessons Learned
What worked
Transforming logs into counts.
What broke
Trying to interpret raw logs directly.
Why it broke
Too much data, no structure.
Fix / takeaway
Always aggregate first.
This is also where analyst judgment starts to show. The command gives counts, but the analyst decides what is normal, what is strange, and what needs escalation.
π Skill Progression Context
This builds analytical thinking required for SOC alert triage.
π TL;DR
Logs donβt speakβ¦
until you make them count.
