Перейти к содержимому

Failed Logins, Then a Successful One: How to Investigate a SIEM Alert

Professor Simon

0:00 / 0:00

Failed Logins, Then a Successful One: How to Investigate a SIEM Alert

11 просмотров · 8 дн. назад
Professor Simon
55 подписчиков
11 просмотров · 8 дн. назад
👉 IT & cybersecurity career guidance: https://professorsimon.com/guidance ---------------------------------------------------- Learn how to investigate a SIEM alert when multiple failed logins are followed by a successful login. This practical SIEM and SOC analyst training walkthrough shows how an analyst can examine login activity, build a timeline, investigate possible password spraying, and determine whether the activity points to a security threat or a benign explanation. Using a hypothetical alert, Professor Simon walks through the investigation from start to finish, including alert triage, log analysis, source and destination review, MFA activity, and the evidence needed to reach a defensible conclusion. If you're building practical blue team or security operations skills, this walkthrough demonstrates the reasoning behind a real-world SIEM investigation rather than simply treating every alert as an incident. What you'll learn: • Why an alert is a question, not a verdict • What to check first: what the rule detects, which account is involved, and what it was signing into • How to build a timeline and read the pattern and reasons behind failed logins • How to check the source and destination, and how to recognize password spraying • What to look for after a successful login: new MFA devices, inbox forwarding rules, and unfamiliar systems • How to argue both the benign and suspicious stories, and how to write a conclusion someone else can check CHAPTERS 0:00 What to Do When Your SIEM Generates an Alert 1:04 What Does a SIEM Alert Actually Mean? 1:25 What Does the SIEM Alert Rule Actually Detect? 2:05 How to Check the Account Behind a SIEM Alert 2:42 How to Build a Timeline for a SIEM Alert 2:55 Automated vs. Human Failed Login Patterns 3:17 Why Did the Logins Fail? Wrong Password vs. Locked Account 3:41 Where Did the Failed Logins Come From? 4:27 How to Spot Password Spraying 4:56 What to Check After a Successful Login 5:55 Benign or Suspicious? Argue Both Sides of an Alert 7:03 How to Verify a Suspicious Login With the User 7:28 How to Write a Defensible Alert Conclusion 8:30 False Positive vs. Benign True Positive 8:56 What Should an Alert Write-Up Include? 9:15 How to Practice Alert Investigation in a Home Lab 📝 Companion Blog Post: https://professorsimon.com/blog/siem-... 🎧 Listen to the Podcast on Spotify: https://professorsimon.com/podcast 🧭 Figure out which path fits you with CareerVectors: https://careervectors.com 🔗 Resources, blog & more: https://professorsimon.com/links 💼 LinkedIn:   / leonardsimon   📸 IG / 🐦 X / 🎵 TikTok: @profsimononline If you found this helpful, subscribe for practical IT and cybersecurity career advice every week. #SIEM #SOC #Cybersecurity