📅 Day 110 — Enterprise Network Flow and Attack Surface Mapping
🔄 Topic
Mapping how data moves through an enterprise environment and where exploitation can happen.
🎯 Goal
Build an end-to-end mental model of enterprise traffic and identify the weak points defenders monitor.
🛠 What I Did
Today I expanded the network material from Course 3 into an enterprise attack-surface view.
The core question was:
When a user types into a laptop and gets a response, what does the data pass through?
A realistic path may include endpoint, local network, switch, router, firewall, DNS, proxy, identity provider, cloud service, application server, database, logging pipeline, and security tools.
Each layer can produce evidence. Each layer can also become a weak point.
🔗 Key Cybersecurity Connections
Attackers rarely need to attack everything. They need one useful weakness that leads to another.
Example chain:
phishing email
↓
credential theft
↓
VPN login
↓
internal discovery
↓
database access
↓
data theft
This chain crosses email security, identity, VPN, endpoint, network, database, and detection controls. A SOC analyst needs enough breadth to follow the path.
🔍 Investigation Questions
- Where does the user request begin?
- Which systems handle the request?
- Where is authentication checked?
- Where is DNS resolution performed?
- Which firewall or proxy sees the traffic?
- Which backend or database receives the request?
- Where are logs stored?
- Which layer shows the first suspicious event?
- Which team owns the affected control?
🚨 Detection Opportunities
Detection ideas:
- endpoint launches suspicious process
- DNS lookup to rare domain
- proxy allows suspicious download
- firewall sees unusual outbound port
- VPN login from unusual geography
- identity provider flags risky login
- database query volume spikes
- cloud API call from rare user
Example investigation chain:
user_click=true
process=powershell.exe
dns_query=rare-domain.example
outbound_https=true
proxy_category=uncategorized
triage=possible_initial_access
🧭 MITRE ATT&CK Techniques
Possible mappings:
- T1566 — Phishing
- T1078 — Valid Accounts
- T1046 — Network Service Discovery
- T1021 — Remote Services
- T1041 — Exfiltration Over C2 Channel
🗺 Visual Investigation Diagram
User
↓
Endpoint
↓
Identity / DNS
↓
Firewall / proxy
↓
Application
↓
Database / cloud
↓
Logs / SIEM
⚠ Challenges
The challenge is the scale of enterprise environments. There are many components, tools, and teams.
The practical solution is to group the attack surface into layers: user, endpoint, identity, network, application, cloud, data, and third party.
📚 What I Learned
I learned that architecture is not just infrastructure documentation. It is investigation guidance. If I know the path, I know where evidence may exist.
➡ Next Steps
- Create an enterprise data-flow diagram
- Label likely log sources on each layer
- Map common attacks to weak points
- Practice writing one attack chain end to end
🧠 Reflection
This connects network learning to real SOC work because incidents rarely stay in one layer. Good investigation requires following the chain.
🧩 Lessons Learned
What worked
Mapping data flow before thinking about attacks.
What broke
Looking at attack surface as one giant list.
Why it broke
Without layers, the environment becomes overwhelming.
Fix / takeaway
Group weak points by user, endpoint, identity, network, application, cloud, and data.
📈 Skill Progression Context
This supports my SOC analyst and detection engineering progression because it turns course material into investigation habits: identifying assets, reading evidence, asking better questions, and explaining security risk clearly.
Instead of treating the certificate as passive study, I am using each topic to build practical analyst thinking that can later become lab notes, detections, diagrams, or portfolio writeups.
😄 TL;DR
Attackers do not need every door. They need one forgotten window.
