Failed Logins, Then a Successful One: How to Investigate a SIEM Alert
Professor Simon
0:00 / 0:00
Failed Logins, Then a Successful One: How to Investigate a SIEM Alert
11 просмотров · 8 дн. назад
Professor Simon
55 подписчиков
11 просмотров · 8 дн. назад
👉 IT & cybersecurity career guidance: https://professorsimon.com/guidance
----------------------------------------------------
Learn how to investigate a SIEM alert when multiple failed logins are followed by a successful login. This practical SIEM and SOC analyst training walkthrough shows how an analyst can examine login activity, build a timeline, investigate possible password spraying, and determine whether the activity points to a security threat or a benign explanation.
Using a hypothetical alert, Professor Simon walks through the investigation from start to finish, including alert triage, log analysis, source and destination review, MFA activity, and the evidence needed to reach a defensible conclusion. If you're building practical blue team or security operations skills, this walkthrough demonstrates the reasoning behind a real-world SIEM investigation rather than simply treating every alert as an incident.
What you'll learn:
• Why an alert is a question, not a verdict
• What to check first: what the rule detects, which account is involved, and what it was signing into
• How to build a timeline and read the pattern and reasons behind failed logins
• How to check the source and destination, and how to recognize password spraying
• What to look for after a successful login: new MFA devices, inbox forwarding rules, and unfamiliar systems
• How to argue both the benign and suspicious stories, and how to write a conclusion someone else can check
CHAPTERS
0:00 What to Do When Your SIEM Generates an Alert
1:04 What Does a SIEM Alert Actually Mean?
1:25 What Does the SIEM Alert Rule Actually Detect?
2:05 How to Check the Account Behind a SIEM Alert
2:42 How to Build a Timeline for a SIEM Alert
2:55 Automated vs. Human Failed Login Patterns
3:17 Why Did the Logins Fail? Wrong Password vs. Locked Account
3:41 Where Did the Failed Logins Come From?
4:27 How to Spot Password Spraying
4:56 What to Check After a Successful Login
5:55 Benign or Suspicious? Argue Both Sides of an Alert
7:03 How to Verify a Suspicious Login With the User
7:28 How to Write a Defensible Alert Conclusion
8:30 False Positive vs. Benign True Positive
8:56 What Should an Alert Write-Up Include?
9:15 How to Practice Alert Investigation in a Home Lab
📝 Companion Blog Post: https://professorsimon.com/blog/siem-...
🎧 Listen to the Podcast on Spotify:
https://professorsimon.com/podcast
🧭 Figure out which path fits you with CareerVectors:
https://careervectors.com
🔗 Resources, blog & more:
https://professorsimon.com/links
💼 LinkedIn:
/ leonardsimon
📸 IG / 🐦 X / 🎵 TikTok: @profsimononline
If you found this helpful, subscribe for practical IT and cybersecurity career advice every week.
#SIEM #SOC #Cybersecurity