Security Monitoring
Security monitoring collects and interprets signals from systems, identities, endpoints, networks, and cloud services so defenders can investigate suspicious activity and respond with evidence instead of guesswork.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Security Monitoring
Security monitoring is the continuous use of telemetry to discover, understand, and investigate activity that could affect an organization. It turns a distributed environment into evidence analysts can search and act on. It is broader than a SIEM: endpoint, network, cloud, identity, and application tools each produce signals. A SIEM often centralizes and correlates many of them.
Start with a question, not a product. Privileged use outside policy, unusual endpoint processes, or unexpected cloud data access each demand different fields, retention, and detection logic. Collection without a question leaves coverage gaps that look like healthy dashboards.
The evidence path moves from source event through collection, parsing, normalization, enrichment, detection, and alert handling. Preserve raw records when practical. Normalized fields help correlation and can hide parser mistakes. Event time, collection time, ingestion time, and detection time are different; large gaps expose delay, backlogs, or clock problems.
Monitoring is successful when it answers important questions quickly with trustworthy evidence. Volume alone is not success. Silent collector failures are a common false-confidence failure mode.
Read the Intro for the evidence path. Use the Cheatsheet when you need telemetry and detection landmarks. Landscape and Timeline place monitoring among related security operations practices; Updates tracks NIST SP 800-92 guidance this course centers on. Measure twice when the stakes are operational. Measure twice when the stakes are operational. Measure twice when the stakes are operational. Measure twice when the stakes are operational. Measure twice when the stakes are operational. Measure twice when the stakes are operational.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/92/final
Supports
- Log-management infrastructure, collection, analysis, storage, protection, retention, and operational processes
- Evidence-path claims, limits, reference rationale, and the 2006 timeline milestone
- https://csrc.nist.gov/pubs/sp/800/92/r1/ipd
Supports
- Log generation, transmission, storage, access, disposal, planning, and logging-program improvement
- Time handling, source health, quiz answers, and reference rationale
- https://csrc.nist.gov/pubs/sp/800/61/r3/final
Supports
- Monitoring evidence inside cybersecurity risk management, incident detection, response, recovery, and automation safeguards
- Alert and incident distinction, triage, response limits, and quiz answers
- https://www.nist.gov/document/csf-20-implementations-pdf
Supports
- Continuous monitoring, correlation, threat intelligence, impact analysis, alert delivery, tickets, and incident criteria
- Detection, investigation, automation guardrails, quiz answers, and reference rationale
- https://attack.mitre.org/datasources/
Supports
- Data components and telemetry vocabulary for detection coverage planning
- Telemetry-selection claims, quiz grounding, and reference rationale
- https://www.rfc-editor.org/info/rfc3164/
Supports
- BSD syslog device, relay, and collector model and the 2001 timeline milestone
- https://www.rfc-editor.org/info/rfc5424/
Supports
- Syslog message structure, timestamps, structured data, transport, and security considerations
- Time and collection limits, quiz answers, reference rationale, and the 2009 timeline milestone
- https://www.sei.cmu.edu/about/divisions/cert/
Supports
- 1988 CERT Coordination Center timeline milestone
- https://www.ll.mit.edu/r-d/publications/1998-darpa-intrusion-detection-evaluation-dataset
Supports
- 1998 intrusion-detection evaluation timeline milestone
- https://github.com/SigmaHQ/sigma/commits/master/?after=f556d50a38791ab47353521c13d3d13a75f671c0+5599
Supports
- January 2017 initial repository history milestone
- https://sigmahq.io/docs/
Supports
- Structured portable log detections, rule resources, and conversion workflows
- Awesome-link rationale and reference-link rationale
- https://learn.microsoft.com/en-us/azure/sentinel/overview
Supports
- Collection, normalization, analytics, incidents, hunting, automation, playbooks, and product placement
- Quiz answer and landscape placement
- https://blogs.microsoft.com/blog/2019/02/28/announcing-new-cloud-based-technology-to-empower-cyber-defenders/
Supports
- February 2019 cloud-based SIEM timeline milestone
- https://www.elastic.co/security/siem
Supports
- Elastic SIEM, XDR, automation, data-platform, and product placement
- https://www.elastic.co/blog/introducing-elastic-siem/
Supports
- June 2019 Elastic SIEM timeline milestone
- https://aws.amazon.com/blogs/security/aws-co-announces-release-of-the-open-cybersecurity-schema-framework-ocsf-project/
Supports
- August 2022 OCSF telemetry-normalization timeline milestone
- https://github.com/sindresorhus/awesome
Supports
- Required discovery route to Awesome Cybersecurity Blue Team
- https://github.com/fabacab/awesome-cybersecurity-blueteam
Supports
- Security Monitoring category and discovery of Wazuh, Security Onion, Sigma, Zeek, and Suricata
- https://documentation.wazuh.com/current/getting-started/index.html
Supports
- Agent collection, file integrity monitoring, configuration assessment, vulnerability detection, log collection, and active response
- Awesome-link rationale and landscape placement
- https://docs.securityonion.net/en/2.4/
Supports
- Network and host visibility, alerts, hunting, cases, detections, packet capture, and analyst workflows
- Awesome-link rationale
- https://docs.zeek.org/en/current/
Supports
- Network-monitoring implementation, high-level logs, and log interpretation
- Awesome-link rationale
- https://docs.suricata.io/en/latest/
Supports
- Network alerts, protocol records, flows, anomalies, and statistics
- Awesome-link rationale
- https://www.splunk.com/en_us/products/enterprise-security.html
Supports
- Search, detection, investigation, response, and federated-analysis placement
- https://cloud.google.com/security/products/security-operations
Supports
- Security-operations product placement and telemetry retention model
- https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender
Supports
- Cross-product signals, incidents, investigation, threat hunting, and automated remediation placement
- https://www.paloaltonetworks.com/cortex/cortex-xdr
Supports
- Endpoint, network, cloud, identity, and email telemetry correlation and response placement
