Threat Monitoring and Detection
You cannot prevent everything. Assume breach, watch the logs, and notice the attacker before payroll does. Good monitoring means detecting threats that slipped past preventive controls fast enough to limit the damage — and fast enough to spare you a 2 a.m. phone call.
The Five Monitoring Layers
Comprehensive threat monitoring requires visibility across network, endpoints, identity, applications, and communication channels. Gaps in any layer become blind spots that attackers exploit.
Components
- Flow data collection and analysis
- Network traffic baselines
- DPI for protocol identification
- Encrypted traffic analysis
- DNS monitoring for C2 traffic
What to Watch For
- Unusual outbound traffic volumes
- Connections to known malicious IPs
- Protocol anomalies (HTTP to port 443 behaving unexpectedly)
- Lateral movement patterns
- Data exfiltration signatures
Components
- Endpoint detection and response (EDR)
- Process monitoring and lineage
- File system activity monitoring
- Registry modification tracking
- Memory analysis
What to Watch For
- Processes spawning unusual child processes
- PowerShell executed with suspicious parameters
- Credential dumping tool execution
- Unauthorized software installation
- Unusual registry modifications
Components
- Authentication log aggregation
- Privileged account activity
- Account creation and modification
- Failed login patterns
- Identity-based anomaly detection
What to Watch For
- Impossible travel (logins from distant locations in short time)
- Authentication to multiple systems in short succession
- Service accounts behaving like users
- New privileged accounts without change tickets
- Authentication outside business hours
Components
- Application logs aggregation
- Error rate monitoring
- Access control validation
- API call pattern analysis
- Business logic abuse detection
What to Watch For
- Spikes in error rates
- Authorization failures from authenticated users
- Unusual API call volumes
- Data export activities
- Failed payment or transaction patterns
Components
- Email filtering and analysis
- Malicious link and attachment detection
- External email tagging
- Collaboration tool anomaly detection
- Impersonation attempt identification
What to Watch For
- Executive impersonation emails
- Links to credential harvesting pages
- Unusual forwarding rules
- External sender spoofing internal users
- Attachment analysis alerts
Threat Intelligence Sources
Effective monitoring benefits from context. Threat intelligence helps you prioritize alerts, understand attacker patterns, and focus monitoring on relevant threats to your industry and environment.
High fidelity, actionable indicators
Free, broad coverage
Relevant to your industry
Authoritative, nation-state intelligence
Early warning of breaches
Alert Triage Process
When an alert fires, a structured approach prevents both overreaction and underreaction. Not every alert is an incident, but every potential incident starts with a structured response.
Initial Correlation
Multiple signals are correlated to confirm an alert is not a false positive
Context Enrichment
Add context: who is the user, what is the asset, what else has happened recently
Impact Assessment
Determine the potential scope and severity of the threat
Containment Decision
Decide whether immediate containment is needed before full investigation
Investigation
Deep dive into logs, timeline, and related activity to understand what happened
Eradication and Recovery
Remove the threat, restore normal operations, verify clean state
Ready to improve your threat monitoring?
ABC of Cyber helps you design monitoring coverage, triage alerts, and build detection rules that catch the threats that matter.