🏠 Home / Hub

🎧 Cyber Security 08 — CySA+ & SOC Analyst

← Cyber Security Menu

CySA+ (CompTIA Cybersecurity Analyst) = Blue Team အတွက် cert တစ်ခု။ SOC Analyst Level 1/2 role နဲ့ threat detection, incident response, vulnerability management ကို focus လုပ်တယ်။

1. CySA+ Exam Overview

DomainWeightKey Topics
Security Operations33%Log analysis, SIEM, threat intel, monitoring
Vulnerability Management30%Scanning, patch priority, risk scoring (CVSS)
Incident Response & Management20%IR lifecycle, containment, forensics, reporting
Reporting & Communication17%Dashboards, KPIs, escalation, stakeholder comms
Exam: CS0-003 | 85 questions (MCQ + Performance-Based) | 165 min | Pass: 750/900

2. SOC Tiers Overview

TierRoleResponsibilities
Tier 1Alert AnalystMonitor SIEM alerts, triage, escalate, follow playbooks
Tier 2Incident ResponderDeep investigation, containment, log correlation
Tier 3Threat Hunter / ExpertProactive hunting, malware analysis, create detections
Tier 4SOC ManagerTeam leadership, metrics, process improvement

3. SOC Alert Triage — Step-by-Step

# Alert fires in SIEM (Splunk / QRadar / Microsoft Sentinel)

Step 1: ACKNOWLEDGE the alert
  - Mark in-progress in your ticketing system

Step 2: READ the alert
  - What rule triggered?
  - Which asset / user is affected?
  - Severity level? (Critical / High / Medium / Low)

Step 3: GATHER CONTEXT
  - Source IP → internal or external?
  - Lookup: VirusTotal, AbuseIPDB, Shodan
  - User account → service account? admin? new?
  - Time → business hours? First occurrence?

Step 4: CORRELATE events
  - Did same IP / user trigger OTHER alerts?
  - Look ±30 min around the event
  - Check firewall logs, DNS, EDR

Step 5: DETERMINE verdict
  - True Positive  → Escalate to Tier 2, document findings
  - False Positive → Document WHY, close, suggest rule tuning

Step 6: DOCUMENT everything
  - Ticket: what you found, what you checked, decision rationale

4. Key Log Sources & Questions

Log SourceWhat to Look For
Windows Security Event LogEvent ID 4625 (failed login), 4720 (account created), 4672 (admin privs)
Linux /var/log/auth.log"Failed password", "Invalid user", sudo commands
Firewall / Network logsPort scans, unusual outbound, denied traffic spikes
DNS logsQueries to newly-registered domains, DGA-like names, TXT abuse
Web proxy / HTTP logsUser-Agent anomalies, POST to weird endpoints, .exe downloads
Endpoint (EDR)PowerShell, base64 decode, process injection, lateral movement
Email gatewayPhishing indicators, attachment hashes, SPF/DKIM/DMARC fails
Cloud (AWS CloudTrail)IAM changes, S3 public bucket, API calls from new region

5. Windows Event IDs Cheat Sheet

# Authentication
4624 - Successful logon
4625 - Failed logon  ← many within short time = brute force
4634 - Logoff
4648 - Explicit credential use (runas)

# Account Management
4720 - User account created
4722 - User account enabled
4728 - User added to global security group
4732 - User added to local Administrators  ← suspicious!

# Privilege / Process
4672 - Admin privileges assigned to new logon
4688 - New process created  ← watch: powershell, wscript, mshta
4698 - Scheduled task created

# Audit
1102 - Audit log cleared  ← RED FLAG
4719 - Audit policy changed

# Splunk hunt for brute force:
index=wineventlog EventCode=4625
| stats count by src_ip, Account_Name
| where count > 10
| sort -count

6. Vulnerability Management Lifecycle

1. DISCOVER  → Scan assets (Nessus, Qualys, OpenVAS)
2. PRIORITIZE → Score with CVSS, add context
3. REMEDIATE → Patch, configure, or mitigate
4. VERIFY    → Re-scan to confirm fix
5. REPORT    → Track metrics, present to leadership

# CVSS v3.1 Severity Ranges
Critical  9.0-10.0 → patch within 24-72 hours
High      7.0-8.9  → patch within 1-2 weeks
Medium    4.0-6.9  → patch within 30 days
Low       0.1-3.9  → next maintenance window

# Prioritization factors BEYOND CVSS score:
# ✔ Internet-facing?
# ✔ Known exploit in the wild? (CISA KEV list)
# ✔ Sensitive data at risk?
# ✔ Exploitable without authentication?
# ✔ Business-critical service?

7. Incident Response Lifecycle

PhaseActions
1. PreparationIR plan, playbooks, tools, contacts, tabletop exercises
2. Detection & AnalysisAlert triage, IOC identification, scope the incident
3. ContainmentIsolate systems, block IOCs at firewall/DNS, reset creds
4. EradicationRemove malware, close vulnerabilities, clear persistence
5. RecoveryRestore from backup, verify clean state, monitor closely
6. Lessons LearnedPost-incident review, update playbooks, add detections
NIST SP 800-61 = official IR framework. CySA+ exam မှာ ဒါကို reference လုပ်တတ်တယ်။

8. Incident Report Template

INCIDENT REPORT
================
ID          : INC-2024-0312
Severity    : HIGH
Status      : RESOLVED
Date/Time   : 2024-03-12 14:32 UTC
Analyst     : [Your Name]

EXECUTIVE SUMMARY
-----------------
Malware infection on WORKSTATION-042 via phishing email.
Employee clicked link → PowerShell dropper → C2 beacon.
Contained within 47 min. No data exfiltration confirmed.

TIMELINE
---------
14:32 - SIEM alert: Unusual outbound → 185.220.x.x
14:38 - Confirmed C2 beacon (Cobalt Strike watermark)
14:45 - Host quarantined (EDR isolation)
14:52 - User credentials reset
15:19 - C2 IP + domain blocked at perimeter

ROOT CAUSE
----------
Phishing email bypassed email gateway filter.
User ran .lnk file → PowerShell dropper executed.
No application whitelisting in place.

IOCs
-----
IP:     185.220.x.x
Domain: evil-cdn.cloud
Hash:   d41d8cd98f00b204e9800998ecf8427e
File:   C:\Users\user\AppData\Local\Temp\update.ps1

REMEDIATION
-----------
1. Host re-imaged from clean baseline
2. User credentials reset + tokens revoked
3. IOCs blocked at firewall and DNS sinkhole
4. Detection rule added for PS Script Block patterns
5. Phishing awareness re-training scheduled

LESSONS LEARNED
---------------
- Enable PS Script Block Logging (Event ID 4104)
- Evaluate AppLocker / WDAC for app whitelisting
- Tune email gateway for .zip + .lnk combos

9. Threat Intelligence Reference

ConceptDescription
IOCIndicator of Compromise — IP, domain, file hash, URL
TTPTactics, Techniques, Procedures — HOW attackers behave
MITRE ATT&CKFramework cataloging adversary behaviors by tactic/technique
Diamond ModelMaps adversary → capability → infrastructure → victim
Kill ChainRecon → Weaponize → Deliver → Exploit → Install → C2 → Act
STIX/TAXIIStandards for sharing threat intel data
VirusTotalHash / IP / domain reputation lookup (free)
AbuseIPDBCommunity IP reputation database
CISA KEVKnown Exploited Vulnerabilities catalog — patch these first

📌 Study Checklist