🔄 Topic

Finishing the foundation course by connecting frameworks, controls, ethics, and common cybersecurity tools to practical analyst work.


🎯 Goal

Turn the broad Course 1 material into a clean operating model: risk, controls, evidence, ethics, and tools.


🛠 What I Did

Today I finished the main themes from Course 1 — Foundations of Cybersecurity.

The material covered security frameworks, controls, the CIA triad, secure design, cybersecurity ethics, and common tools used by analysts, including SIEM tools, packet analyzers, Linux, SQL, and Python.

These topics are broad, so I condensed them into one practical question:

How does an analyst move from security theory to evidence-based work?

🔗 Key Cybersecurity Connections

Frameworks and controls help explain why security decisions exist.

The CIA triad gives a simple impact model:

Confidentiality: was information exposed?
Integrity: was information changed or tampered with?
Availability: was a system or service disrupted?

Tools are how the analyst observes evidence:

SIEM: search and correlate logs
Packet analyzer: inspect network traffic
Linux: navigate systems and logs
SQL: query structured data
Python: automate repetitive work

Ethics matters because analysts may see sensitive data, user activity, internal systems, and incident details. Access is not permission to be careless.


🔍 Investigation Questions

  • Which part of the CIA triad is affected?
  • Which control should have reduced this risk?
  • What evidence source confirms the issue?
  • Is the analyst allowed to access the data being reviewed?
  • Does the investigation minimize unnecessary exposure of sensitive data?
  • Which tool is best for the evidence type: SIEM, packet capture, Linux logs, SQL data, or script output?

🚨 Detection Opportunities

Detection opportunities come from weak or missing controls:

  • sensitive file accessed by unusual user
  • service availability degraded after traffic spike
  • firewall rule changed unexpectedly
  • backup deletion before ransomware activity
  • security tool disabled or tampered with
  • new admin account created outside change window

Example:

event=security_control_changed
control=firewall_rule
actor=unknown_admin
time=outside_change_window
action=allow_inbound_rdp
risk=exposed_remote_access

🧭 MITRE ATT&CK Techniques

Possible mappings depend on the specific activity:

  • T1078 — Valid Accounts
  • T1098 — Account Manipulation
  • T1562 — Impair Defenses
  • T1490 — Inhibit System Recovery
  • T1046 — Network Service Discovery

🗺 Visual Investigation Diagram

Security concept
    ↓
Risk or control
    ↓
Evidence source
    ↓
Analyst tool
    ↓
Ethical review
    ↓
Clear finding

⚠ Challenges

The challenge is that frameworks can sound like management language. The fix is to connect them to real controls and logs.

If a control exists, there should be evidence of whether it worked. If the control failed, the analyst should be able to explain the risk clearly.


📚 What I Learned

I learned that Course 1 is broad, but it gives the vocabulary needed for later operational work. The important move is to translate every term into a real security question.


➡ Next Steps

  • Create a CIA-impact template for future incident reports
  • Build a tools-to-evidence map
  • Practice writing findings with risk, evidence, and control language
  • Keep ethical boundaries explicit when reviewing logs

🧠 Reflection

This foundation material was not technically difficult, but it helped tighten my language. That matters because poor wording creates poor investigations.


🧩 Lessons Learned

What worked

Condensing broad concepts into an analyst workflow.

What broke

Frameworks feel abstract when separated from evidence.

Why it broke

Theory only becomes useful when it explains controls, risk, or observations.

Fix / takeaway

Always connect framework language to a log source, control, asset, or response action.


📈 Skill Progression Context

This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.

Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.


😄 TL;DR

Security is not vibes. It is risk, controls, evidence, and responsibility.