Back to Frameworks
Threat Monitoring
Detection and Response

Threat Monitoring and Detection

You cannot prevent everything. Assume breach, watch the logs, and notice the attacker before payroll does. Good monitoring means detecting threats that slipped past preventive controls fast enough to limit the damage — and fast enough to spare you a 2 a.m. phone call.

The Five Monitoring Layers

Comprehensive threat monitoring requires visibility across network, endpoints, identity, applications, and communication channels. Gaps in any layer become blind spots that attackers exploit.

Network Monitoring
Visibility into traffic patterns, anomalies, and potential threats traversing your network.

Components

  • Flow data collection and analysis
  • Network traffic baselines
  • DPI for protocol identification
  • Encrypted traffic analysis
  • DNS monitoring for C2 traffic

What to Watch For

  • Unusual outbound traffic volumes
  • Connections to known malicious IPs
  • Protocol anomalies (HTTP to port 443 behaving unexpectedly)
  • Lateral movement patterns
  • Data exfiltration signatures
Endpoint Monitoring
Behavioral analysis on workstations, servers, and devices to detect malicious activity.

Components

  • Endpoint detection and response (EDR)
  • Process monitoring and lineage
  • File system activity monitoring
  • Registry modification tracking
  • Memory analysis

What to Watch For

  • Processes spawning unusual child processes
  • PowerShell executed with suspicious parameters
  • Credential dumping tool execution
  • Unauthorized software installation
  • Unusual registry modifications
Identity Monitoring
Tracking authentication patterns, privilege usage, and identity-based threats.

Components

  • Authentication log aggregation
  • Privileged account activity
  • Account creation and modification
  • Failed login patterns
  • Identity-based anomaly detection

What to Watch For

  • Impossible travel (logins from distant locations in short time)
  • Authentication to multiple systems in short succession
  • Service accounts behaving like users
  • New privileged accounts without change tickets
  • Authentication outside business hours
Application Monitoring
Observing application behavior, errors, and access patterns for anomalies.

Components

  • Application logs aggregation
  • Error rate monitoring
  • Access control validation
  • API call pattern analysis
  • Business logic abuse detection

What to Watch For

  • Spikes in error rates
  • Authorization failures from authenticated users
  • Unusual API call volumes
  • Data export activities
  • Failed payment or transaction patterns
Email and Collaboration Monitoring
Detecting phishing, business email compromise, and threats delivered through communication tools.

Components

  • Email filtering and analysis
  • Malicious link and attachment detection
  • External email tagging
  • Collaboration tool anomaly detection
  • Impersonation attempt identification

What to Watch For

  • Executive impersonation emails
  • Links to credential harvesting pages
  • Unusual forwarding rules
  • External sender spoofing internal users
  • Attachment analysis alerts

Threat Intelligence Sources

Effective monitoring benefits from context. Threat intelligence helps you prioritize alerts, understand attacker patterns, and focus monitoring on relevant threats to your industry and environment.

Commercial Threat Feeds
Curated intelligence from vendors like Recorded Future, Mandiant, or CrowdStrike

High fidelity, actionable indicators

OSINT Feeds
Open source threat intelligence from AbuseIPDB, URLhaus, AlienVault OTX

Free, broad coverage

Industry Sharing Groups
ISACs and ISMGs for sector-specific intelligence sharing

Relevant to your industry

Government Sources
CISA, FBI IC3, NSA Cybersecurity Advisories

Authoritative, nation-state intelligence

Dark Web Monitoring
Monitoring for leaked credentials, discussion of your organization

Early warning of breaches

Alert Triage Process

When an alert fires, a structured approach prevents both overreaction and underreaction. Not every alert is an incident, but every potential incident starts with a structured response.

1

Initial Correlation

Multiple signals are correlated to confirm an alert is not a false positive

2

Context Enrichment

Add context: who is the user, what is the asset, what else has happened recently

3

Impact Assessment

Determine the potential scope and severity of the threat

4

Containment Decision

Decide whether immediate containment is needed before full investigation

5

Investigation

Deep dive into logs, timeline, and related activity to understand what happened

6

Eradication and Recovery

Remove the threat, restore normal operations, verify clean state

Ready to improve your threat monitoring?

ABC of Cyber helps you design monitoring coverage, triage alerts, and build detection rules that catch the threats that matter.