Security Monitoring
Security monitoring collects and interprets signals from systems, identities, endpoints, networks, and cloud services so defenders can investigate suspicious activity and respond with evidence instead of guesswork.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Security monitoring is the continuous use of telemetry to discover, understand, and investigate activity that could affect an organization. It turns a distributed environment into evidence that analysts can search, compare, and act on. It is broader than a SIEM: endpoint, network, cloud, identity, application, and exposure tools can each produce useful signals. A SIEM commonly centralizes and correlates many of them.
Monitoring starts with a question, not a tool. A team may need to know whether privileged accounts are used outside an approved path, whether an endpoint started an unusual process, or whether a cloud identity accessed data from an unexpected location. The question determines the required telemetry, fields, retention, detection logic, and response path. A product that collects many records but cannot answer an important question leaves a coverage gap.
The evidence path
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/92/final
Supports
- Log-management infrastructure, collection, analysis, storage, protection, retention, and operational processes
- Evidence-path claims, limits, reference rationale, and the 2006 timeline milestone
- https://csrc.nist.gov/pubs/sp/800/92/r1/ipd
Supports
- Log generation, transmission, storage, access, disposal, planning, and logging-program improvement
- Time handling, source health, quiz answers, and reference rationale
- https://csrc.nist.gov/pubs/sp/800/61/r3/final
Supports
- Monitoring evidence inside cybersecurity risk management, incident detection, response, recovery, and automation safeguards
- Alert and incident distinction, triage, response limits, and quiz answers
- https://www.nist.gov/document/csf-20-implementations-pdf
Supports
- Continuous monitoring, correlation, threat intelligence, impact analysis, alert delivery, tickets, and incident criteria
- Detection, investigation, automation guardrails, quiz answers, and reference rationale
- https://attack.mitre.org/datasources/
Supports
- Data components and telemetry vocabulary for detection coverage planning
- Telemetry-selection claims, quiz grounding, and reference rationale
- https://www.rfc-editor.org/info/rfc3164/
Supports
- BSD syslog device, relay, and collector model and the 2001 timeline milestone
- https://www.rfc-editor.org/info/rfc5424/
Supports
- Syslog message structure, timestamps, structured data, transport, and security considerations
- Time and collection limits, quiz answers, reference rationale, and the 2009 timeline milestone
- https://www.sei.cmu.edu/about/divisions/cert/
Supports
- 1988 CERT Coordination Center timeline milestone
- https://www.ll.mit.edu/r-d/publications/1998-darpa-intrusion-detection-evaluation-dataset
Supports
- 1998 intrusion-detection evaluation timeline milestone
- https://github.com/SigmaHQ/sigma/commits/master/?after=f556d50a38791ab47353521c13d3d13a75f671c0+5599
Supports
- January 2017 initial repository history milestone
- https://sigmahq.io/docs/
Supports
- Structured portable log detections, rule resources, and conversion workflows
- Awesome-link rationale and reference-link rationale
- https://learn.microsoft.com/en-us/azure/sentinel/overview
Supports
- Collection, normalization, analytics, incidents, hunting, automation, playbooks, and product placement
- Quiz answer and landscape placement
- https://blogs.microsoft.com/blog/2019/02/28/announcing-new-cloud-based-technology-to-empower-cyber-defenders/
Supports
- February 2019 cloud-based SIEM timeline milestone
- https://www.elastic.co/security/siem
Supports
- Elastic SIEM, XDR, automation, data-platform, and product placement
- https://www.elastic.co/blog/introducing-elastic-siem/
Supports
- June 2019 Elastic SIEM timeline milestone
- https://aws.amazon.com/blogs/security/aws-co-announces-release-of-the-open-cybersecurity-schema-framework-ocsf-project/
Supports
- August 2022 OCSF telemetry-normalization timeline milestone
- https://github.com/sindresorhus/awesome
Supports
- Required discovery route to Awesome Cybersecurity Blue Team
- https://github.com/fabacab/awesome-cybersecurity-blueteam
Supports
- Security Monitoring category and discovery of Wazuh, Security Onion, Sigma, Zeek, and Suricata
- https://documentation.wazuh.com/current/getting-started/index.html
Supports
- Agent collection, file integrity monitoring, configuration assessment, vulnerability detection, log collection, and active response
- Awesome-link rationale and landscape placement
- https://docs.securityonion.net/en/2.4/
Supports
- Network and host visibility, alerts, hunting, cases, detections, packet capture, and analyst workflows
- Awesome-link rationale
- https://docs.zeek.org/en/current/
Supports
- Network-monitoring implementation, high-level logs, and log interpretation
- Awesome-link rationale
- https://docs.suricata.io/en/latest/
Supports
- Network alerts, protocol records, flows, anomalies, and statistics
- Awesome-link rationale
- https://www.splunk.com/en_us/products/enterprise-security.html
Supports
- Search, detection, investigation, response, and federated-analysis placement
- https://cloud.google.com/security/products/security-operations
Supports
- Security-operations product placement and telemetry retention model
- https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender
Supports
- Cross-product signals, incidents, investigation, threat hunting, and automated remediation placement
- https://www.paloaltonetworks.com/cortex/cortex-xdr
Supports
- Endpoint, network, cloud, identity, and email telemetry correlation and response placement
