SOC and SIEM Use Cases

SOC and SIEM Use Cases

Authored by Don Murdoch
SOC Analyst 3 views 0 downloads 2018
Published 2018
Language eng
Publisher CreateSpace
'SOC SIEM USE CASES' by Don Murdoch is a practical operational guide dedicated to Security Operations Center (SOC) workflows, SIEM engineering, and defensive threat hunting. Focusing on the methodologies needed to detect, analyze, and remediate enterprise intrusions, this text provides actionable blueprints for cyber defense.

The book explores log ingestion, Splunk search processing language (SPL), alert correlation rule development, incident triage, memory and endpoint analysis, threat intelligence integration, and MITRE ATT&CK alignment. Real-world scenario drills and interview preparation questions prepare readers for operational SOC roles.

A must-read for SOC analysts, SIEM administrators, threat hunters, and IT security engineers working in modern enterprise defense centers.
Contents at a Glance
Chapter 1: Introduction to SIEM Architecture and Splunk Core
Chapter 2: Data Ingestion: Forwarders, Inputs, and Source Types
Chapter 3: Searching and Filtering Data with Search Processing Language (SPL)
Chapter 4: Creating Knowledge Objects: Field Extractions, Tags, and Event Types
Chapter 5: Designing SOC Dashboards, Visualizations, and Alerts
Chapter 6: Splunk for Incident Investigation: Correlating Multi-Source Logs
Chapter 7: Building Detection Rules Aligned with MITRE ATT&CK
Chapter 8: Splunk Enterprise Security (ES) and Threat Intelligence Frameworks
Index & Further Reading