The Security Operation Center Analyst Level 3 course is designed for experienced cybersecurity professionals who operate at the highest tier of SOC analysis. L3 analysts are subject matter experts who lead complex incident investigations, perform proactive threat hunting, conduct malware analysis and digital forensics, and drive strategic security improvements.
This outline covers the full spectrum of advanced SOC competencies: from advanced SIEM correlation and malware reverse-engineering to threat intelligence integration and incident command. Graduates are prepared to handle the most critical security incidents and mentor junior analysts.
Focus: Move beyond basic IOCs to understand adversary tactics, techniques, and procedures (TTPs).
πΉ Outcome: Analyst can proactively hunt for advanced threats using TTPs and intelligence feeds.
Focus: Master multi-source correlation, advanced querying, and SIEM optimization.
πΉ Outcome: Analyst can reduce false positives and prioritize the most critical alerts.
Focus: Analyze malicious software to understand its behavior and impact.
πΉ Outcome: Analyst can identify malware capabilities and produce actionable IOCs.
Focus: Conduct deep forensic investigations to determine root cause and impact.
πΉ Outcome: Analyst can reconstruct an attack from initial compromise to final impact.
Focus: Lead the response to major security incidents.
πΉ Outcome: Analyst can manage the full incident lifecycle and lead response efforts.
Focus: Find threats that evade existing security controls.
πΉ Outcome: Analyst can uncover advanced persistent threats (APTs) before they cause damage.
Focus: Extend SOC capabilities to cloud environments.
πΉ Outcome: Analyst can detect and respond to threats across hybrid and multiβcloud environments.
Focus: Automate repetitive tasks and orchestrate response workflows.
πΉ Outcome: Analyst can build automated response workflows to improve efficiency.
Focus: Understand attacker perspective to strengthen defenses.
πΉ Outcome: Analyst can assess and prioritize vulnerabilities to guide remediation.
Focus: Drive SOC maturity and mentor junior analysts.
πΉ Outcome: Analyst can lead a team, improve processes, and communicate with executives.
| Framework | Application in L3 role |
|---|---|
| MITRE ATT&CK | Mapping adversary TTPs, threat hunting, detection engineering |
| NIST SP 800-61 | Incident response lifecycle and methodology |
| Cyber Kill Chain | Tracking attacks through phases; identifying early indicators |
| MITRE D3FEND | Countermeasure mapping and defense techniques |
| NICE Cybersecurity Framework | Role alignment: Cyber Defense Analyst (PR-CDA-001) |
Certification paths: This course aligns with ECβCouncil Certified SOC Analyst (CSA) v2, which now includes L3-level skills such as threat hunting, malware analysis, and digital forensics. It also maps to industry certifications like GCIA, GCIH, and CySA+.
Welcome to the world of Security Operations β where we protect people, data, and systems from digital bad guys.
Hello! This is the first module of our Security Operation Center (SOC) Analyst Level 3 course. You might be wondering: βWhat is a SOC Analyst?β Well, think of a SOC like a digital police station β a team of experts who watch over computer networks, looking for signs of trouble. The Level 3 analyst is like the detective chief β the most experienced person who solves the toughest cases.
In this module, we will use very simple words β like we are teaching a bright 10βyearβold. We will tell stories, draw pictures with letters and symbols, and give lots of examples from home, school, and Nigeria. By the end, you will understand what a SOC does, why it is important, and how Level 3 analysts protect us from cyber attacks.
After this module, you will be able to:
In a big city in Nigeria, there was a bank. One day, the bank manager noticed that money was disappearing from customer accounts β but no one had stolen physical cash. It was a digital robbery!
The bank called the Security Operations Center β a team of cybersecurity experts. The L1 analyst saw the alert first: βSuspicious login from a strange IP address.β She passed it to the L2 analyst, who dug deeper. But the attack was very clever β it used advanced tricks.
Then the Level 3 analyst, Mr. Ade, took over. He analysed the logs, traced the hacker's path, and found hidden malware that was stealing money in tiny amounts. He stopped the attack, recovered the money, and wrote a report to prevent it from happening again.
That is what a Level 3 SOC Analyst does β they are the super-detectives of the digital world!
Definition: A Security Operation Center (SOC) is a team that monitors and protects an organisation's computer systems from cyber attacks.
Why important? Every day, hackers try to break into computers, steal data, or cause harm. The SOC is the guardian that stops them.
Simple explanation: Think of a SOC as a control room β like the one in an airport, where people watch screens to make sure planes are safe. But instead of planes, they watch computer networks.
Real-life example: Banks, hospitals, and government agencies have SOCs to protect their data.
School example: Imagine your school has a security team that watches the gates and cameras β that is a physical SOC.
Home example: You might have a smart doorbell that alerts you when someone is at the door β that is a tiny home SOC.
Nigerian example: Nigerian banks like GTBank and Access Bank have SOCs to protect customers' money from hackers.
π’ SECURITY OPERATION CENTER (SOC)
-----------------------------------
+-----------------------+
| Monitoring screens |
| Alerts |
| Analysts at desks |
| Big displays |
+-----------------------+
|
V
PROTECTS NETWORKS
Mini summary: A SOC is a team that watches over computer systems to stop cyber attacks.
Definition: SOC analysts work in three levels, like a school system: L1 (primary), L2 (secondary), and L3 (university).
Why important? Each level has different skills and handles different types of problems.
Simple: Level 1 is like a gate guard β they watch for obvious problems. Level 2 is like a police officer β they investigate. Level 3 is like a detective chief β they solve the hardest cases.
Real: L1 analyst triages alerts; L2 analyst investigates; L3 analyst does advanced analysis and forensics.
School: In a school, L1 might be the prefect who watches the gate; L2 is the class teacher; L3 is the principal.
Home: L1 is the alarm system; L2 is you checking who is at the door; L3 is your parents handling a complex situation.
Nigeria: Many Nigerian companies have SOC teams with three levels to handle different threats.
π₯ SOC ANALYST LEVELS ---------------------- L1: Junior β Triage alerts L2: Mid-level β Investigate L3: Senior β Advanced analysis, forensics, hunting
Mini summary: SOC analysts work in three levels β L1, L2, and L3 β with increasing expertise.
Definition: A Level 3 analyst is the expert who handles the most complex threats and guides the team.
Why important? They are the last line of defence β when all else fails, L3 steps in.
Simple: Like a surgeon who performs the most difficult operations.
Real: L3 analysts do malware analysis, digital forensics, and threat hunting.
School: The head teacher who solves the biggest problems.
Home: Your parent who deals with a serious emergency.
Nigeria: L3 analysts in Nigerian banks investigate sophisticated fraud attempts.
π¦Έ L3 ANALYST RESPONSIBILITIES ------------------------------- β’ Malware analysis β’ Digital forensics β’ Threat hunting β’ Incident response leadership β’ Mentoring L1/L2 β’ Creating playbooks
Mini summary: The L3 analyst is the top expert who handles the toughest security cases.
Definition: A cyber threat is anything that can harm a computer system or steal information.
Why important? To protect against threats, we must first understand them.
Simple: A cyber threat is like a storm that can damage your house β you need to know about it to prepare.
Real: Hackers, viruses, and phishing emails are cyber threats.
School: Someone trying to break into the school's computer system.
Home: A scammer calling your home phone.
Nigeria: Cyber threats in Nigeria include phishing, banking fraud, and ransomware.
β οΈ CYBER THREATS ---------------- β’ Malware β bad software β’ Phishing β fake emails β’ Ransomware β locks files β’ DDoS β overloads websites β’ Insider threats β trusted people who do bad things
Mini summary: A cyber threat is anything that can harm computers or steal data.
Definition: Malware is short for malicious software β programs designed to harm or hack computers.
Why important? Malware is one of the most common cyber threats.
Simple: Like a virus that makes you sick β but for computers.
Real: A computer gets infected after downloading a fake file.
School: A school computer starts acting strangely after a student inserts a USB drive with malware.
Home: Your phone gets a virus from a fake game app.
Nigeria: Some Nigerian computers have been infected with malware that steals banking details.
π¦ TYPES OF MALWARE ------------------- β’ Virus β spreads to other files β’ Worm β spreads across networks β’ Trojan β disguises as good software β’ Ransomware β locks files and demands money β’ Spyware β steals your information
Mini summary: Malware is bad software that harms computers and steals information.
Definition: Phishing is when a hacker sends a fake email or message to trick you into giving them your personal information.
Why important? Phishing is one of the easiest ways for hackers to steal passwords and money.
Simple: Like someone pretending to be your friend to get your secret code.
Real: An email that looks like it's from your bank, asking for your password.
School: A fake email to students asking for their school login.
Home: A text message that says you won a prize, but asks for your bank details.
Nigeria: Many Nigerians have received phishing emails pretending to be from GTBank or other companies.
π£ PHISHING EXAMPLE ------------------- Fake email: "Your account is locked. Click here to reset." Real link: www.bank.com/reset Fake link: www.bankβsecure.com/reset
Mini summary: Phishing is a trick where hackers send fake messages to steal your information.
Definition: Ransomware is a type of malware that locks your files and demands money (a ransom) to unlock them.
Why important? Ransomware can cause huge damage to businesses and individuals.
Simple: Like someone locking your room and asking for money to open it.
Real: A hospital's computers are locked until they pay a ransom.
School: The school's files are encrypted and the hacker demands money.
Home: Your family photos are locked and you can't access them.
Nigeria: Some Nigerian companies have been attacked by ransomware, forcing them to pay to get their data back.
π RANSOMWARE ATTACK -------------------- 1. Malware gets into system 2. Encrypts files (locks them) 3. Displays a message: "Pay $500" 4. If paid, they may unlock files 5. Often they don't unlock!
Mini summary: Ransomware locks your files and demands money to unlock them.
Definition: Incident response is the process of detecting, containing, and recovering from a cyber attack.
Why important? A good plan saves time, money, and reputation.
Simple: Like a fire drill β you practise so you know what to do if there is a real fire.
Real: When a company detects a hack, they follow an incident response plan.
School: The school has a plan for what to do if there is a security breach.
Home: Your family has a plan for emergencies like a power outage.
Nigeria: Nigerian banks have incident response teams to handle cyber attacks.
π¨ INCIDENT RESPONSE STEPS -------------------------- 1. Preparation β get ready 2. Detection β find the attack 3. Containment β stop it spreading 4. Eradication β remove the cause 5. Recovery β restore systems 6. Lessons learned β improve
Mini summary: Incident response is a stepβbyβstep plan to handle a cyber attack.
Definition: Threat hunting is actively searching for threats that have not yet been detected by automated tools.
Why important? Some attacks are so clever that they bypass normal security β hunting finds them.
Simple: Like a detective searching for clues before a crime is even reported.
Real: An analyst looks for unusual activity in logs to find hidden attackers.
School: The school security team checks the cameras regularly for suspicious activity.
Home: You check your room to make sure nothing is missing.
Nigeria: Nigerian cybersecurity experts hunt for threats in government networks.
π THREAT HUNTING ----------------- 1. Create a hypothesis: "Is there any sign of attacker X?" 2. Collect data: logs, network traffic 3. Analyse: look for patterns 4. Investigate: find evidence 5. Respond: if found, contain it
Mini summary: Threat hunting is proactively searching for hidden cyber threats.
Definition: Digital forensics is the process of collecting and analysing evidence from computers to understand what happened during an attack.
Why important? It helps find the root cause and gather evidence for legal action.
Simple: Like a detective collecting fingerprints at a crime scene β but for computers.
Real: After a hack, forensics analysts examine the computer's hard drive to see what the attacker did.
School: If someone cheats on a test using a phone, the teacher might investigate the phone's data.
Home: You check your phone's location history to see where you went.
Nigeria: Nigerian police have digital forensics labs to investigate cyber crimes.
π¬ DIGITAL FORENSICS -------------------- β’ Collect data (hard drive, logs) β’ Preserve evidence (make copies) β’ Analyse (find traces) β’ Document findings β’ Present in court if needed
Mini summary: Digital forensics is the investigation of computer evidence to solve cyber crimes.
Definition: Tools are the software and hardware that SOC analysts use to do their job.
Why important? Without tools, it is like trying to fix a car without a wrench.
Simple: Like a doctor using a stethoscope to check your heartbeat.
Real: Analysts use SIEM (Security Information and Event Management) tools to collect logs.
School: The school uses cameras and door locks as security tools.
Home: You use a password manager to keep your passwords safe.
Nigeria: Nigerian SOCs use tools like Splunk, QRadar, and openβsource tools like Wireshark.
π οΈ SOC TOOLS ------------- β’ SIEM (Splunk, QRadar) β collects and analyses logs β’ EDR (CrowdStrike, SentinelOne) β detects threats on endpoints β’ Network tools (Wireshark) β captures network traffic β’ Threat intelligence (MISP) β shares threat data β’ Sandboxes β run suspicious files safely
Mini summary: SOC analysts use special software tools to detect, investigate, and respond to threats.
Definition: The Cyber Kill Chain is a model that breaks down a cyber attack into seven stages β like a timeline.
Why important? Understanding the stages helps us stop attacks at each step.
Simple: Like a burglar planning a robbery β they have steps from planning to escape.
Real: An attack starts with reconnaissance (scouting), then weaponization, and ends with exfiltration (stealing data).
School: A student planning to cheat: they check the teacher's routine, prepare notes, and then cheat.
Home: A thief casing a house: they watch, find a way in, steal, and escape.
Nigeria: Nigerian cybersecurity professionals use the Cyber Kill Chain to stop bank fraud.
π CYBER KILL CHAIN ------------------- 1. Reconnaissance β gather info 2. Weaponization β create exploit 3. Delivery β send the attack 4. Exploitation β trigger the exploit 5. Installation β install malware 6. Command & Control β control the system 7. Actions on Objective β steal, encrypt, etc.
Mini summary: The Cyber Kill Chain breaks down an attack into seven stages so we can stop it early.
Definition: MITRE ATT&CK is a knowledge base of known adversary tactics and techniques used in cyber attacks.
Why important? It helps analysts understand and describe what attackers do.
Simple: Like a map of all the ways a burglar can enter a house β so you can block each way.
Real: Analysts use ATT&CK to map an attack to specific techniques (e.g., phishing, command line usage).
School: A map of all possible ways to cheat β and how to prevent them.
Home: A list of all the ways someone could break into your house β and how to secure each one.
Nigeria: Nigerian SOC teams use MITRE ATT&CK to improve their detection capabilities.
πΊοΈ MITRE ATT&CK --------------- β’ Tactics β the "why" (e.g., Credential Access) β’ Techniques β the "how" (e.g., Brute Force) β’ Procedures β specific implementation Used to understand and defend against attacks.
Mini summary: MITRE ATT&CK is a library of attacker methods that helps SOC analysts defend better.
Definition: Threat intelligence is information about potential or current attacks β who is doing them, how, and why.
Why important? Knowing about threats helps you prepare and respond faster.
Simple: Like getting a weather forecast β you know when to carry an umbrella.
Real: A company receives intelligence about a new ransomware variant and updates its defences.
School: The school hears about a new virus going around and tells students to wash their hands.
Home: Your parents hear about a scam and warn you not to answer unknown calls.
Nigeria: Nigerian cybersecurity firms share threat intelligence to protect the banking sector.
π‘ THREAT INTELLIGENCE ---------------------- β’ Strategic β big picture β’ Tactical β specific indicators β’ Operational β attacker campaigns β’ Technical β IOCs (IPs, hashes)
Mini summary: Threat intelligence is information about cyber threats that helps you defend.
Definition: SOC maturity is how advanced and effective a SOC is β from beginner to worldβclass.
Why important? A mature SOC can handle more complex threats.
Simple: Like a student moving from Primary 1 to University β each level is more advanced.
Real: A SOC starts with basic alerts, then adds threat hunting, then automation.
School: A school starts with simple security, then adds cameras, then a security team.
Home: You start with a simple lock, then add an alarm, then a smart camera.
Nigeria: Nigerian SOCs are maturing as they adopt more advanced tools and techniques.
π SOC MATURITY LEVELS ---------------------- Level 1: Reactive β just respond to alerts Level 2: Proactive β hunt for threats Level 3: Optimized β automation and intelligence Level 4: Advanced β predictive and adaptive
Mini summary: SOC maturity describes how advanced and effective a SOC is.
PREPARATION
|
V
DETECTION
|
V
CONTAINMENT
|
V
ERADICATION
|
V
RECOVERY
|
V
LESSONS LEARNED
+-------------------+-------------------+-------------------+ | L1 (Junior) | L2 (Mid) | L3 (Senior) | +-------------------+-------------------+-------------------+ | Triage alerts | Investigate | Advanced analysis | | Monitor dashboards| Escalate to L3 | Forensics | | First line | Threat hunting | Threat hunting | | | | Mentoring | +-------------------+-------------------+-------------------+
Reconnaissance
|
V
Weaponization
|
V
Delivery
|
V
Exploitation
|
V
Installation
|
V
Command & Control
|
V
Actions on Objective
| Level | Experience | Main Tasks | Decision Making |
|---|---|---|---|
| L1 | 0β2 years | Triage, monitor | Basic |
| L2 | 2β5 years | Investigate, escalate | Intermediate |
| L3 | 5+ years | Advanced analysis, forensics, hunting | Strategic |
In this module, we learned about the Security Operation Center (SOC) β the digital guardians who protect computer systems from cyber attacks. We explored the three levels of SOC analysts, with Level 3 being the top experts who handle the most complex cases.
We learned about common cyber threats like malware, phishing, and ransomware. We also covered the incident response lifecycle β a stepβbyβstep plan for handling attacks. We discovered threat hunting, digital forensics, and the tools that SOC analysts use.
We saw many examples from Nigeria and everyday life. Remember: the SOC is like a digital police station, and L3 analysts are the detectives who solve the toughest cases.
1. What does SOC stand for?
Security Operation Center β a team that protects networks.
2. What does a Level 3 analyst do?
They handle the most complex threats, do forensics, and mentor others.
3. What is malware?
Bad software that harms computers.
4. What is phishing?
Fake emails or messages that trick you into giving information.
5. What is ransomware?
Malware that locks your files and demands money.
6. What is incident response?
A plan to handle cyber attacks.
7. What is threat hunting?
Actively searching for hidden threats.
8. What is digital forensics?
Investigating computer evidence to understand attacks.
9. What is the Cyber Kill Chain?
A model that shows the stages of a cyber attack.
10. Are there SOCs in Nigeria?
Yes, many Nigerian companies have SOCs to protect their data.
Match the term with its definition:
| Term | Definition |
|---|---|
| 1. SOC | A. Bad software |
| 2. Malware | B. Security Operation Center |
| 3. Phishing | C. Locks files and demands money |
| 4. Ransomware | D. Fake message to steal information |
| 5. Forensics | E. Investigating digital evidence |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario 1: A Nigerian bank receives an alert about a large money transfer that seems suspicious. The L1 analyst escalates to L2, who finds it is a sophisticated attack. What would an L3 analyst do next?
Scenario 2: A hospital's computers are locked with a ransomware message demanding payment. The SOC team is called. What are the steps they should follow?
Scenario 3: You are a Level 3 analyst and you notice unusual traffic on the network. You suspect a hacker is inside. How would you conduct a threat hunt?
In groups of 4, roleβplay a SOC team: one person is L1, one L2, one L3, and one is the manager. You receive an alert about a phishing attack. Each person explains what they would do. Present your response to the class.
Draw a diagram of the incident response lifecycle. Label each step and write one sentence about what happens in that step. Use your own words.
Create an incident response plan for a small business. Your plan should include: who is responsible, steps to detect and contain an attack, and how to recover. Present it as a oneβpage document.
Research a realβworld cyber attack (e.g., a ransomware attack on a Nigerian company). Write a oneβpage report on: what happened, how the SOC likely responded, and what could have been done to prevent it.
Imagine you are the L3 analyst for a Nigerian telecom company. A sophisticated hacker group has been stealing customer data. Design a threat hunting plan to find them. Include: what data you would look at, what tools you would use, and how you would contain the attack.
In Module Two, we will dive deeper into network security and monitoring β how to watch the digital roads and spot intruders. We will learn about IP addresses, ports, firewalls, and how to read network logs. For homework, think about what a network looks like β maybe draw a map of your home WiβFi.
Homework: Write down three things you know about computer networks. Bring your ideas to class.
π Congratulations! You have completed Module One. You are now on your way to becoming a SOC analyst!
Understanding the digital roads β how to watch, protect, and investigate the networks that connect us all.
Welcome to Module Two! In the first module, we learned what a Security Operation Center (SOC) is and how Level 3 analysts are the top experts. Now, we are going to look at the digital roads β the networks that connect computers, phones, and devices. Think of a network like a road system that cars (data) travel on. If we want to protect against cyber attacks, we must understand these roads β where they go, how they work, and how we can watch for trouble.
This module will teach you about IP addresses (like house numbers), ports (like doors), firewalls (like gates), and how to monitor network traffic to find intruders. We will use simple words, fun stories, and lots of examples from Nigeria and everyday life. By the end, you will understand how a Level 3 analyst watches the digital roads to catch hackers.
After this module, you will be able to:
In a big city in Nigeria, there was a busy highway. Cars (data) travelled back and forth between homes, banks, and offices. But there were also bandits (hackers) trying to steal from the cars.
The government set up a Highway Patrol β a team that watched the road, checked for suspicious vehicles, and stopped bandits. They had cameras (monitoring tools) and checkpoints (firewalls).
One day, they noticed a car that was not supposed to be on the road β it was a fake delivery van. The patrol stopped it and found stolen data inside. The chief patrol officer (that's our L3 analyst) investigated and found the bandits' hideout.
That is what network security is about β watching the digital roads, finding intruders, and stopping them!
Definition: A computer network is a group of computers and devices connected together so they can share information.
Why important? Networks allow us to send emails, browse the web, and transfer money β but they also need protection.
Simple explanation: Like a postal system β letters (data) travel from one house to another using roads (the network).
Real-life example: The internet is the biggest network in the world.
School example: The school's computers are connected so students can share files.
Home example: Your WiβFi connects your phone, laptop, and smart TV.
Nigerian example: A bank's network connects its branches across Nigeria.
π NETWORK BASICS
------------------
Device 1 (computer)
|
| (cable or Wi-Fi)
|
Device 2 (printer)
|
|
Device 3 (phone)
Mini summary: A computer network connects devices so they can share data.
Definition: An IP address is a unique number that identifies a device on a network β like a house number for your computer.
Why important? IP addresses help data find the right destination.
Simple explanation: When you send a letter, you write the address. IP addresses do the same for data.
Real-life example: Your phone has an IP address when you connect to WiβFi.
School example: Each school computer has a different IP address.
Home example: Your laptop and your phone have different IP addresses on your home network.
Nigerian example: A bank's server in Lagos has a public IP address that customers connect to.
π§ IP ADDRESS EXAMPLE --------------------- 192.168.1.1 β Your home router 192.168.1.2 β Your laptop 192.168.1.3 β Your phone
Mini summary: An IP address is a unique number that identifies a device on a network.
Definition: A port is a number that identifies a specific service or application on a device β like a door to a room.
Why important? Ports help data go to the right app (like email, web, or games).
Simple explanation: If a house (IP address) has many rooms (ports), each room has a different number.
Real-life example: Port 80 is for web traffic; Port 443 is for secure web (HTTPS).
School example: The school's web server uses port 443 for its website.
Home example: Your game console uses a specific port to connect to online games.
Nigerian example: A bank's online portal uses port 443 for secure customer logins.
πͺ COMMON PORTS --------------- Port 80 β HTTP (web) Port 443 β HTTPS (secure web) Port 25 β SMTP (email) Port 53 β DNS (domain names) Port 22 β SSH (secure remote access)
Mini summary: Ports are like doors that data uses to reach the right application.
Definition: A firewall is a security system that monitors and controls incoming and outgoing network traffic β like a gatekeeper.
Why important? It blocks bad traffic and allows good traffic.
Simple explanation: Like a security guard at a gate β they check who is coming in and out.
Real-life example: Your home router has a firewall to block hackers.
School example: The school has a firewall to block inappropriate websites.
Home example: Your computer's builtβin firewall blocks suspicious programs.
Nigerian example: Nigerian banks use firewalls to protect their networks from external attacks.
π‘οΈ FIREWALL
------------
+-----------------------+
| INCOMING TRAFFIC |
| (from internet) |
+-----------------------+
|
V
+-----------------------+
| FIREWALL (checks) |
| Allow or Block |
+-----------------------+
|
V
+-----------------------+
| YOUR COMPUTER |
+-----------------------+
Mini summary: A firewall is a gatekeeper that allows good traffic and blocks bad traffic.
Definition: IDS (Intrusion Detection System) watches for suspicious activity and alerts you. IPS (Intrusion Prevention System) also blocks it.
Why important? They help detect and stop attacks in real time.
Simple explanation: IDS is like a security camera; IPS is like a camera that also locks the door.
Real-life example: A bank uses IDS to detect hackers and IPS to block them.
School example: The school has a camera (IDS) that alerts the principal if someone enters after hours.
Home example: A smart alarm that detects motion (IDS) and sounds a siren (IPS).
Nigerian example: Nigerian telecom companies use IDS/IPS to protect their networks.
π‘ IDS vs IPS ------------- IDS: Watches and alerts IPS: Watches, alerts, and blocks Both are essential for network security.
Mini summary: IDS detects threats; IPS detects and blocks them.
Definition: TCP (Transmission Control Protocol) is a reliable delivery method. UDP (User Datagram Protocol) is faster but less reliable.
Why important? Different applications need different delivery methods.
Simple explanation: TCP is like sending a package with tracking and confirmation. UDP is like tossing a ball β faster, but you might miss it.
Real-life example: Web browsing uses TCP; video streaming uses UDP.
School example: Sending a test file via TCP; watching a live video uses UDP.
Home example: Email uses TCP; online games often use UDP.
Nigerian example: Nigerian banks use TCP for transactions and UDP for video surveillance.
π¦ TCP vs UDP ------------- +-------------------+-------------------+ | TCP | UDP | +-------------------+-------------------+ | Reliable | Faster | | Has tracking | No tracking | | Used for web, | Used for streaming| | email, files | gaming, VoIP | +-------------------+-------------------+
Mini summary: TCP is reliable; UDP is fast but less reliable.
Definition: Network logs are records of all activity on a network β like a diary that writes down everything that happens.
Why important? Logs help analysts investigate what happened during an incident.
Simple explanation: Like a school attendance register β it records who came, when, and for how long.
Real-life example: A server logs every IP address that connects to it.
School example: The school's computer lab logs which students use which computer.
Home example: Your router has a log of all websites visited.
Nigeria: Banks keep detailed logs of all transactions to detect fraud.
π NETWORK LOG EXAMPLE ---------------------- Time: 10:32:15 Source IP: 192.168.1.5 Destination IP: 8.8.8.8 Port: 443 Action: Allowed Bytes: 1,024
Mini summary: Network logs record all activity β they are essential for investigations.
Definition: Packet analysis is the process of inspecting individual packets of data as they travel across a network.
Why important? It helps us see exactly what is being sent β including hidden malicious content.
Simple explanation: Like opening a letter to read it before it reaches the recipient.
Real-life example: An L3 analyst uses Wireshark to capture and examine packets.
School example: The school IT team checks packets to see if students are accessing blocked sites.
Home example: You check your smart home camera's packets to ensure it's not sending data to a hacker.
Nigeria: Nigerian cybersecurity firms use packet analysis to investigate cyber crimes.
π¨ PACKET STRUCTURE ------------------- +----------------------------------+ | Source IP: 192.168.1.2 | | Destination IP: 8.8.8.8 | | Source Port: 54321 | | Destination Port: 443 | | Data: "GET /index.html" | +----------------------------------+
Mini summary: Packet analysis is reading the individual pieces of data to find hidden threats.
Definition: DDoS (Distributed Denial of Service) is an attack that floods a network with so much traffic that it crashes.
Why important? It can shut down websites and services.
Simple explanation: Like sending thousands of cars to a single road β it gets jammed and no one can move.
Real-life example: A website is bombarded with millions of requests and goes offline.
School example: Many students trying to log in at once β the system slows down.
Home example: Many devices streaming video at the same time β your network slows down.
Nigeria: Nigerian banks have faced DDoS attacks that temporarily took down their apps.
π DDoS ATTACK --------------- Attacker controls many computers (botnet) | V All send traffic to one website | V Website gets overwhelmed and crashes
Mini summary: DDoS attacks cause network jams by flooding it with traffic.
Definition: A manβinβtheβmiddle (MITM) attack is when a hacker secretly intercepts and possibly alters communication between two parties.
Why important? It can steal sensitive information like passwords and credit card numbers.
Simple explanation: Like someone listening to your phone call and writing down what you say.
Real-life example: A hacker intercepts your WiβFi connection to capture your bank login.
School example: Someone intercepts messages between teachers on the school's network.
Home example: A neighbour uses a fake WiβFi to capture your online activity.
Nigeria: Some hackers use MITM attacks in public WiβFi hotspots to steal data.
π€ MITM ATTACK
---------------
Victim A β (communicating) β Victim B
β
|
Hacker (intercepts)
Mini summary: Manβinβtheβmiddle attacks intercept and steal data during communication.
Definition: DNS (Domain Name System) translates humanβreadable domain names (like google.com) into IP addresses.
Why important? Without DNS, we would have to remember numbers instead of names.
Simple explanation: Like a phonebook β you look up a name (google.com) to find the number (IP address).
Real-life example: When you type "bank.com", DNS finds the bank's IP address.
School example: The school's website is reached by its name, not its IP.
Home example: You type "youtube.com" and DNS finds the IP.
Nigeria: Nigerian ISPs provide DNS services to their customers.
π DNS LOOKUP
-------------
Type "www.nigerianbank.com"
|
V
DNS Server finds IP: 196.1.2.3
|
V
Your browser connects to that IP
Mini summary: DNS translates names to numbers so we can easily find websites.
Definition: VPN (Virtual Private Network) creates a secure, encrypted tunnel for data to travel β like a secret passage.
Why important? It protects data from eavesdroppers, especially on public networks.
Simple explanation: Like an armoured van carrying money β it protects the contents.
Real-life example: A remote employee uses VPN to connect securely to the company network.
School example: The school's principal uses VPN to access school files from home.
Home example: You use VPN to protect your browsing at a cafe.
Nigeria: Many Nigerian companies use VPN for secure remote work.
π VPN ------ Your device β VPN (encrypted) β Internet Other users cannot see your data.
Mini summary: VPN creates a secure tunnel to protect data from hackers.
Definition: SIEM (Security Information and Event Management) collects and analyses logs from across the network β like a central command center.
Why important? It gives analysts a single view of all security events.
Simple explanation: Like a control room that shows all cameras at once.
Real-life example: Splunk or QRadar collects logs from firewalls, servers, and endpoints.
School example: The school's IT team has a dashboard that shows all computer activity.
Home example: A smart home hub that shows all devices and their status.
Nigeria: Nigerian banks use SIEM tools to monitor their entire infrastructure.
π§ SIEM ------- Firewall logs | Server logs β SIEM (central analysis) β Alerts | Endpoint logs
Mini summary: SIEM is a central system that collects and analyses logs from many sources.
Definition: Threat hunting is proactively searching for hidden threats that bypass automated tools.
Why important? Some attackers are very stealthy β they need a human to find them.
Simple explanation: Like a detective going through old files to find clues that were missed.
Real-life example: An L3 analyst finds unusual DNS queries that reveal a hidden malware.
School example: The IT team checks network logs for signs of a student hacker.
Home example: You check your router's connected devices for unknown intruders.
Nigeria: Nigerian SOC teams hunt for threats in government networks.
π THREAT HUNTING PROCESS ------------------------- 1. Form a hypothesis 2. Collect data 3. Analyse 4. Investigate findings 5. Respond
Mini summary: Threat hunting is the proactive search for hidden threats.
Definition: Incident response in networks is the process of handling a security event β from detection to recovery.
Why important? A swift response minimises damage.
Simple explanation: Like a fire drill β you practise so you know what to do.
Real-life example: If a DDoS attack is detected, the team reroutes traffic and blocks the source.
School example: If a school computer is infected, it is isolated and cleaned.
Home example: If your home WiβFi is hacked, you change the password and check devices.
Nigeria: Nigerian companies have incident response plans for network attacks.
π¨ NETWORK INCIDENT RESPONSE ---------------------------- 1. Detect 2. Contain (block) 3. Investigate 4. Eradicate 5. Recover 6. Learn
Mini summary: Incident response is the stepβbyβstep process of handling a network security event.
INTERNET
|
V
[FIREWALL] β gatekeeper
|
V
[SWITCH] β connects devices
|
+---+---+
| | |
PC1 PC2 Server
ATTACKER (Botnet)
|
+---+---+
| | |
PC1 PC2 PC3 (hundreds of devices)
| | |
+---+---+
|
V
TARGET WEBSITE
(overwhelmed)
SENDER
|
V
[PACKET] β [ROUTER] β [RECEIVER]
(data) (directs)
| Feature | TCP | UDP |
|---|---|---|
| Reliability | High | Low |
| Speed | Slower | Faster |
| Tracking | Yes | No |
| Used for | Web, email, files | Streaming, gaming, VoIP |
In this module, we explored the digital roads β computer networks β and how we protect them. We learned about IP addresses (digital house numbers) and ports (digital doors). We discovered how firewalls act as gatekeepers and IDS/IPS as alarm systems.
We compared TCP (reliable delivery) and UDP (fast delivery). We learned to read logs and analyse packets to find hidden threats. We explored common attacks like DDoS (traffic jams) and MITM (eavesdropping).
We also covered DNS (the phonebook), VPN (secure tunnels), and SIEM (central monitoring). Finally, we discussed threat hunting and incident response β the core activities of a Level 3 analyst. Nigeria has many opportunities in network security, and you are now ready to explore them.
1. What is a computer network?
Devices connected together to share data.
2. What is an IP address?
A unique number that identifies a device on a network.
3. What is a port?
A number that identifies a specific service on a device.
4. What does a firewall do?
It blocks bad traffic and allows good traffic.
5. What is the difference between IDS and IPS?
IDS detects; IPS detects and blocks.
6. What is TCP?
A reliable delivery method for data.
7. What is UDP?
A fast but less reliable delivery method.
8. What is a DDoS attack?
An attack that overwhelms a network with traffic.
9. What is a MITM attack?
An attack where a hacker intercepts communication.
10. Why is packet analysis important?
It reveals hidden threats in data.
Match the term with its definition:
| Term | Definition |
|---|---|
| 1. IP address | A. Digital house number |
| 2. Port | B. Digital door |
| 3. Firewall | C. Gatekeeper |
| 4. IDS | D. Alarm system |
| 5. VPN | E. Secure tunnel |
Answers: 1-A, 2-B, 3-C, 4-D, 5-E
Scenario 1: A Nigerian bank notices unusual traffic on its network. The SIEM shows many connections to an unknown IP address on port 445. As an L3 analyst, what steps would you take?
Scenario 2: A hospital's network is experiencing slow performance. You suspect a DDoS attack. How would you confirm it and what would you do?
Scenario 3: You find a packet that shows data being sent to an unauthorised server. How would you investigate this as an L3 analyst?
In groups of 4, design a network security plan for a small company in Nigeria. Include: firewall rules, IDS/IPS placement, logging strategy, and an incident response procedure. Present to the class.
Draw a diagram of a home network. Label the devices, the router, and the firewall. Add IP addresses (use 192.168.1.x). Write a short description of how data travels.
Design a network monitoring dashboard. Draw a simple dashboard (on paper) that shows: number of active connections, alerts, blocked traffic, and top source IPs. Include at least 3 visual elements.
Research a realβworld network security incident in Nigeria (e.g., bank fraud, DDoS attack, or data breach). Write a oneβpage report on: what happened, how it was detected, and how it could have been prevented.
Imagine you are the L3 analyst for a Nigerian telecom company. A hacker group is using DNS tunneling to exfiltrate data. Design a threat hunting plan to detect and stop them. Include: data to analyse, tools to use, and steps to contain.
In Module Three, we will dive into Endpoint Security and Malware Analysis β how to protect individual computers and devices, and how to analyse malicious software. We will learn about antivirus, EDR, and how to reverseβengineer malware. For homework, think about what you would do if your own computer got infected.
Homework: Write down three ways you protect your personal devices from malware. Bring your ideas to class.
π Congratulations! You have completed Module Two. You now understand the digital roads and how to guard them!
Hello, young defender! You have already learned what a Security Operation Centre (SOC) is and why it is important. You also learned about the tools we use to keep systems safe. Now, it is time to learn about the enemies we are protecting against β cyber threats! In this module, we will explore different types of attacks, how they work, and how we can stop them. Get ready to become a threat detective!
In Module One, you learned what a Security Operation Centre is and why we need it. In Module Two, you learned about the tools and technologies we use to protect systems. Now, in Module Three, we will focus on the threats themselves. A threat is anything that can harm a computer system or steal information. Threat actors are the people or groups who create these threats. In this module, we will learn about different types of attacks, like viruses, phishing, and hacking. We will also learn how to detect and respond to them. By the end of this module, you will understand the dangers that SOC Analysts face every day and how to stay safe.
Remember: Knowing your enemy is the first step to defeating them.
After this module, you will be able to:
Tunde is 10 years old and lives in Port Harcourt. One day, he received an email on his tablet. The email said: "Congratulations! You have won a brand new phone! Click this link to claim it." Tunde was very excited. He was about to click the link when his older sister, Ada, stopped him.
Ada said, "Tunde, wait! This looks suspicious. Look at the email address β it's from a strange sender, not a real company." Tunde looked closely. The email address was "win@prize-fake.com" instead of a real company's address. Ada explained, "This is a phishing attack. They want you to click the link so they can steal your information."
Tunde was shocked. He had almost fallen for it. Ada said, "This is why we need Security Operation Centres. They protect us from these threats." Tunde learned a valuable lesson: always be careful with emails and messages from unknown people. He decided he would learn more about cyber threats to protect himself and his friends.
Question for you: Have you ever received a suspicious email or message? What did you do?
Definition: A cyber threat is any danger that can harm a computer system, network, or data. It can be a virus, a hacker, or even a careless mistake.
Why it is important: Understanding cyber threats helps us protect ourselves and our information from being stolen or damaged.
Simple explanation: Just like we lock our doors to keep out burglars, we use security to keep out cyber threats.
Real-life example: A virus that deletes all your files is a cyber threat.
School example: A student accidentally downloading a malicious file on a school computer.
Home example: A family member clicking on a fake pop-up ad.
Nigerian example: Scammers who send fake text messages pretending to be a bank.
Cyber Threat Sources: - Hackers - Viruses - Malware - Phishing emails - Ransomware
Mini summary: A cyber threat is anything that can harm your computer or data.
Definition: A virus is a program that can copy itself and spread to other computers. Malware is any bad software designed to harm your computer.
Why it is important: Viruses and malware can steal your information, slow down your computer, or even delete your files.
Simple explanation: A virus is like a sickness for computers β it spreads and makes them sick.
Real-life example: A virus that infects your computer and steals your passwords.
School example: A student's USB drive infects the school's network with a virus.
Home example: A family member downloads a game that has malware hidden inside.
Nigerian example: Scammers sending a file that is actually a virus to steal bank details.
Malware Types: - Virus: spreads and harms - Worm: spreads without help - Trojan: pretends to be safe - Spyware: spies on you - Ransomware: locks your files
Mini summary: Viruses and malware are harmful programs that can damage your computer.
Definition: Phishing is when someone pretends to be a trusted person or company to trick you into giving them your information.
Why it is important: Phishing is one of the most common cyber threats. It can lead to identity theft and financial loss.
Simple explanation: Imagine someone pretending to be your friend to get your secrets. That's phishing.
Real-life example: An email that looks like it's from your bank asking for your password.
School example: A fake email from the principal asking for student details.
Home example: A message that says "You've won a prize" and asks for your address.
Nigerian example: "You don win N1,000,000! Click this link to collect."
Phishing Signs: - Urgent language - Requests for personal info - Suspicious links - Strange email addresses - Spelling or grammar errors
Mini summary: Phishing is a trick to steal your personal information.
Definition: Ransomware is a type of malware that locks your files and demands payment (ransom) to unlock them.
Why it is important: Ransomware can cause huge damage to individuals, businesses, and even hospitals.
Simple explanation: Imagine if someone locked your room and wouldn't give you the key until you paid them.
Real-life example: A hospital's computers were locked, and they had to pay to get patient records back.
School example: A ransomware attack on a school's computer system.
Home example: A family member's computer gets locked by ransomware.
Nigerian example: A Nigerian company's data is encrypted and they are asked to pay in Bitcoin.
Ransomware Process: 1. Infiltrate system 2. Encrypt files 3. Display ransom note 4. Victim pays (or not) 5. Files are unlocked (hopefully)
Mini summary: Ransomware locks your files and demands money to unlock them.
Definition: A DoS attack floods a server with traffic, making it unavailable to users. DDoS is a distributed attack from multiple sources.
Why it is important: These attacks can shut down websites, banks, and even government services.
Simple explanation: Imagine if millions of people tried to enter a shop at the same time β no one could get in. That's a DoS attack.
Real-life example: A website crashes because of a DDoS attack.
School example: A school's online portal goes down because of a DDoS attack.
Home example: Your favourite game server is down because of a DDoS attack.
Nigerian example: A Nigerian bank's website is attacked and customers can't access it.
DoS Attack Steps: 1. Attacker sends massive traffic 2. Server becomes overloaded 3. Legitimate users can't access 4. Service is disrupted
Mini summary: DoS attacks overload systems to make them unavailable.
Definition: An insider threat is when a person inside an organisation causes harm β either accidentally or on purpose.
Why it is important: Insiders have access to sensitive information and can cause significant damage.
Simple explanation: Like a trusted friend who steals from you.
Real-life example: An employee who shares company secrets with a competitor.
School example: A teacher who accidentally leaves student records unsecured.
Home example: A family member who shares your passwords with others.
Nigerian example: A staff member who sells customer data to scammers.
Insider Threat Types: - Malicious: intentional harm - Negligent: carelessness - Compromised: their account was hacked
Mini summary: Insider threats come from people inside the organisation.
Definition: Social engineering is when hackers manipulate people into giving them information or access.
Why it is important: Many security breaches happen because people are tricked, not because of technical failures.
Simple explanation: Like pretending to be someone's friend to get their secrets.
Real-life example: A hacker calls and pretends to be IT support to get your password.
School example: Someone pretends to be a parent to get a student's records.
Home example: A scammer calls and says they're from Microsoft to fix your computer.
Nigerian example: "Hello, I'm calling from your bank. Please confirm your account number."
Social Engineering Tricks: - Pretending to be trusted - Creating urgency - Asking for help - Offering fake rewards
Mini summary: Social engineering tricks people into giving away information.
Definition: A zero-day vulnerability is a weakness in software that no one knows about yet, not even the people who made it.
Why it is important: Hackers can use zero-day vulnerabilities to attack before anyone can fix them.
Simple explanation: Like a hidden trap door in your house that only a burglar knows about.
Real-life example: A hacker finds a weakness in a popular app and uses it to steal data.
School example: A flaw in the school's software that a student discovers.
Home example: A smart speaker has a flaw that lets hackers listen in.
Nigerian example: A vulnerability in a Nigerian bank's mobile app.
Zero-Day Timeline: 1. Flaw is discovered by hacker 2. Hacker exploits it 3. Vendor learns about it 4. Vendor creates a fix 5. Users apply the fix
Mini summary: Zero-day flaws are unknown weaknesses that hackers can exploit.
Definition: Threat intelligence is information about potential threats β who is attacking, how they attack, and what they want.
Why it is important: Knowing your enemy helps you prepare and defend better.
Simple explanation: Like a spy who gathers information about the enemy's plans.
Real-life example: A company tracks hacking groups and learns their methods.
School example: A school learns about common scams targeting students.
Home example: A family learns about new types of phishing attacks.
Nigerian example: Tracking scammers who target Nigerian businesses.
Threat Intelligence Sources: - Internal logs - Public reports - Security vendors - Government agencies - Threat-sharing communities
Mini summary: Threat intelligence helps us understand and defend against enemies.
Definition: Incident response is the process of dealing with a security breach β finding it, stopping it, and recovering from it.
Why it is important: A quick and effective response can limit the damage from an attack.
Simple explanation: Like a fire brigade rushing to put out a fire.
Real-life example: A company detects a hack, isolates the affected system, and restores data from backups.
School example: A school's IT team responds to a malware infection.
Home example: A family removes a virus from their computer.
Nigerian example: A bank responds to a data breach and notifies customers.
Incident Response Steps: 1. Detect 2. Isolate 3. Investigate 4. Contain 5. Eradicate 6. Recover 7. Review and improve
Mini summary: Incident response is the process of handling a security problem.
Definition: Prevention means taking steps to stop threats from happening in the first place.
Why it is important: It's easier to prevent an attack than to fix the damage after.
Simple explanation: Like locking your door to prevent a break-in, rather than fixing it after.
Real-life example: Installing antivirus software and updating it regularly.
School example: Educating students about phishing and safe internet use.
Home example: Using strong passwords and not sharing them.
Nigerian example: Companies training employees on cybersecurity.
Prevention Measures: - Use strong passwords - Update software - Install antivirus - Educate users - Back up data
Mini summary: Prevention is key to staying safe from cyber threats.
Definition: AI can help detect threats by analysing patterns and identifying suspicious activity automatically.
Why it is important: AI can find threats faster than humans and handle huge amounts of data.
Simple explanation: Like a guard dog that alerts you when something is wrong.
Real-life example: A security system that uses AI to detect unusual network traffic.
School example: An AI system that monitors school computers for malware.
Home example: A smart security camera that detects intruders.
Nigerian example: A Nigerian bank using AI to detect fraudulent transactions.
AI in Threat Detection: - Monitors traffic - Detects anomalies - Alerts analysts - Learns from past attacks
Mini summary: AI helps detect threats quickly and accurately.
Definition: Real-world scenarios are examples of actual attacks that have happened.
Why it is important: Studying real attacks helps us learn and prepare for future ones.
Simple explanation: Like learning from stories of past battles.
Real-life example: The WannaCry ransomware attack that affected many countries.
School example: A local school that was hit by a phishing scam.
Home example: A family member who fell for a fake tech support call.
Nigerian example: A Nigerian company that lost data due to insider threat.
Notable Attacks: - WannaCry ransomware (2017) - Yahoo data breach (2013) - Nigerian email scams (ongoing)
Mini summary: Studying real-world attacks helps us prepare.
Definition: Staying safe online means using good habits to protect yourself and your information.
Why it is important: Everyone β including you β can be targeted by cyber threats.
Simple explanation: Like wearing a seatbelt to protect yourself in a car.
Real-life example: Using strong passwords and not clicking on suspicious links.
School example: Logging out of school computers after use.
Home example: Not sharing passwords with friends.
Nigerian example: Being cautious of "you've won a prize" messages.
Online Safety Tips: - Use strong passwords - Don't click on suspicious links - Don't share personal info - Keep software updated - Think before you click
Mini summary: Good online habits protect you from cyber threats.
Definition: A threat detective is someone who can identify and understand cyber threats. You have become one!
Why it is important: Your knowledge helps you protect yourself and others.
Simple explanation: You have learned the skills to spot dangers and stay safe.
Real-life example: You can now recognise a phishing email and avoid it.
School example: You can help your friends stay safe online.
Home example: You can help your family be more secure.
Nigerian example: You can help your community avoid scams.
You β Learned about threats β Can now protect others! π‘οΈ
Mini summary: You are now a threat detective, ready to protect yourself and others.
Step 1: Check sender β suspicious email Step 2: Check subject β "URGENT ACTION REQUIRED" Step 3: Hover link β fake website Step 4: Check grammar β many errors Step 5: Don't click β ignore or spam Step 6: Contact company directly β use real number Step 7: Report to trusted adult
Potential Threat
|
V
Identify the Threat
|
V
Assess the Risk
|
V
Respond (Isolate/Eradicate)
|
V
Recover
|
V
Review and Improve
| Threat Type | What It Does | Example |
|---|---|---|
| Virus | Spreads and harms | Delete files |
| Phishing | Tricks for info | Fake bank email |
| Ransomware | Locks files, demands payment | WannaCry |
| DoS/DDoS | Overloads systems | Website crash |
| Insider Threat | Harm from within | Employee steals data |
| Prevention | How It Helps |
|---|---|
| Strong Passwords | Makes it hard for hackers to guess |
| Software Updates | Fixes security flaws |
| Antivirus | Detects and removes malware |
| Education | Helps people spot threats |
| Backups | Restores data if lost |
1986 First virus (Brain)
|
2000 ILOVEYOU virus spreads
|
2013 Yahoo data breach
|
2017 WannaCry ransomware
|
Today AI helps detect threats
Congratulations! You have completed Module Three of your Security Operation Centre Analyst training. You have learned about the many types of cyber threats β viruses, malware, phishing, ransomware, DoS attacks, insider threats, and more. You also learned about social engineering, zero-day vulnerabilities, and the importance of threat intelligence. You now understand how to spot threats and how to respond to them. You are well on your way to becoming a skilled SOC Analyst!
Match the threat to its description:
| Threat | Description |
|---|---|
| Virus | Spreads and harms computers |
| Phishing | Trick for personal information |
| Ransomware | Locks files and demands payment |
| DoS Attack | Overloads a system |
| Insider Threat | Harm from within |
Scenario 1: You receive an email from "your bank" asking you to update your password by clicking a link. What do you do?
Scenario 2: Your school's computer system is running very slowly, and students can't log in. You suspect a DoS attack. What steps would you take?
Scenario 3: A colleague tells you they received a call from "IT support" asking for their password. They gave it. What should the organisation do?
Threat Investigation: In groups of 4, you will be given a scenario of a potential cyber attack. Work together to identify the threat, assess the risk, and develop an incident response plan. Present your findings to the class.
Online Safety Checklist: Create a checklist of actions to stay safe online. Include things like using strong passwords, not clicking on suspicious links, and keeping software updated. Share your checklist with the class.
Task: Create a poster that educates people about a specific cyber threat. Include a description, an example, and prevention tips. Use pictures and simple language. Present your poster to the class.
Assignment: Look for a suspicious email or message you have received (or ask an adult for one). Analyse it β identify the signs that make it suspicious. Write a report on your findings and how you would respond.
Challenge: Write a short story about a cyber attack. Include the attack, how it was detected, and how it was resolved. Use at least 5 different threat types and 5 prevention measures in your story.
Fill-in-the-Blank Answers: 1. threat, 2. Phishing, 3. Ransomware, 4. DoS, 5. insider, 6. Social, 7. zero-day, 8. Threat, 9. Incident, 10. better, 11. Phishing, 12. sender, 13. strong, 14. software, 15. threat.
True or False: 1T, 2F, 3T, 4F, 5F, 6F, 7F, 8T, 9F, 10T.
Multiple Choice Answers: 1B, 2B, 3B, 4B, 5B, 6B, 7B, 8A, 9A, 10B, 11B, 12A, 13A, 14A, 15C.
In Module Four, you will learn about threat detection and how SOC Analysts use tools and techniques to identify threats in real-time. We will dive into tools like SIEM, intrusion detection systems, and threat hunting. You will also learn about the role of AI in detecting and responding to threats.
Before next class: Think about how you would detect a threat in a computer system. What signs would you look for? We'll explore this together in the next module.
π‘οΈ You have completed Module Three β keep up the great work! π‘οΈ
Hello, data detective! In the last module, you learned about cyber threats. In this module, we will learn about a powerful tool that helps Security Operation Centre (SOC) Analysts investigate threats: MySQL. MySQL is a way to store, search, and manage information in a database. Think of it as a giant digital filing cabinet. Let's learn how to use it!
In Module One, you learned about the SOC. In Module Two, you learned about security tools. In Module Three, you learned about cyber threats. Now, in Module Four, we will focus on MySQL. But what is MySQL? It is a program that helps us organise and search for information quickly. Imagine a library with millions of books. MySQL is like the librarian who can find any book in seconds.
SOC Analysts use MySQL to search logs, find suspicious activities, and track attackers. In this module, we will learn how to write simple commands to store and retrieve data. We will use very simple language, so don't worry if you have never coded before. You will be a MySQL expert by the end!
Remember: Every great detective needs a way to organise clues. MySQL is your clue organizer!
After this module, you will be able to:
Ada is 10 years old and lives in Lagos. Her school has a computer lab with 50 computers. One day, the lab manager noticed something strange β someone had been accessing the lab computers late at night. He needed to find out who it was. He had logs (records) of every time someone logged in, but there were thousands of entries. He was overwhelmed.
Ada's older sister, Amina, is a SOC Analyst. She came to help. She opened a program called MySQL. She typed a simple command to search for logins after 10 PM. In just a few seconds, the results appeared β there was only one person who had logged in late at night! The lab manager was amazed. He asked Amina how she did it. She said, "I used MySQL to search through the data quickly."
Ada was so impressed. She asked Amina to teach her MySQL. Amina said, "It's like talking to the computer in a language it understands. Let me show you!"
Question for you: Have you ever had to find something in a big pile of information? How did you do it?
Definition: A database is a place where we store information in an organised way. It is like a digital filing cabinet.
Why it is important: Databases help us store and find information quickly. Without a database, it would be very hard to find anything.
Simple explanation: Imagine a shelf with books. If the books are organised by subject, it's easy to find one. That's a database.
Real-life example: Your school's student records are stored in a database.
School example: The library catalogue is a database of all books.
Home example: A recipe box with cards is a tiny database.
Nigerian example: A bank stores all customer account information in a database.
Database = Organised Information Example: - Student names - Classes - Grades
Mini summary: A database is an organised collection of information.
Definition: MySQL is a type of database software. It helps us create, read, update, and delete data.
Why it is important: MySQL is used by many companies and organisations to manage their data. Knowing MySQL is a valuable skill.
Simple explanation: MySQL is like a language we use to talk to the database.
Real-life example: Many websites use MySQL to store user information.
School example: A school might use MySQL to store student grades.
Home example: A family might use a simple database to keep track of their books.
Nigerian example: Nigerian companies use MySQL to store customer data.
MySQL = Language to talk to the database - Create data - Read data - Update data - Delete data
Mini summary: MySQL is a language that helps us manage data in a database.
Definition: A table is like a grid of rows and columns. Each row is a record, and each column is a field.
Why it is important: Tables help us organise data into a structure that is easy to search.
Simple explanation: Imagine a spreadsheet with rows and columns β that's a table.
Real-life example: A table of students with columns for name, age, and grade.
School example: A class register is a table.
Home example: A list of phone numbers is a table.
Nigerian example: A customer table with name, account number, and balance.
Table Example: +----------+-----+-------+ | Name | Age | Grade | +----------+-----+-------+ | Tunde | 10 | A | | Ada | 9 | B | | Chidi | 11 | A+ | +----------+-----+-------+
Mini summary: A table organises data into rows and columns.
Definition: Creating a table means defining the columns and what type of data each column will hold.
Why it is important: Before we can add data, we need a table to put it in.
Simple explanation: It's like drawing the grid on a piece of paper before writing in it.
Real-life example: A school creates a table to store student information.
School example: A teacher creates a table with columns for students' names and test scores.
Home example: A family creates a table to keep track of chores.
Nigerian example: A shopkeeper creates a table for customers and their orders.
SQL to create a table:
CREATE TABLE students (
name VARCHAR(50),
age INT,
grade VARCHAR(2)
);
Mini summary: Creating a table is like drawing a grid to fill in later.
Definition: Inserting data means adding rows of information into a table.
Why it is important: A table is empty until we add data to it.
Simple explanation: It's like writing in a notebook.
Real-life example: Adding a new student's information to the school database.
School example: Entering the latest test scores into the table.
Home example: Adding a new chore to the chore list.
Nigerian example: Adding a new customer to the shop's database.
SQL to insert data:
INSERT INTO students (name, age, grade)
VALUES ('Tunde', 10, 'A');
Mini summary: Inserting data means adding new rows to a table.
Definition: Reading data means retrieving information from a table. We do this with the SELECT command.
Why it is important: Reading data is how we find the information we need.
Simple explanation: It's like asking the database a question.
Real-life example: A SOC Analyst uses SELECT to find all logins after 10 PM.
School example: A teacher wants to see all students who got an A.
Home example: A parent wants to see a list of all chores.
Nigerian example: A bank manager wants to see all customers with high balances.
SQL to read data: SELECT * FROM students; SELECT name, grade FROM students WHERE age = 10;
Mini summary: SELECT helps us read and retrieve data from a table.
Definition: Updating data means changing existing information in a table.
Why it is important: Sometimes information changes, and we need to keep the database up to date.
Simple explanation: It's like crossing out a word and writing a new one.
Real-life example: A student's grade is updated from a B to an A.
School example: A student changes their phone number.
Home example: A chore is marked as completed.
Nigerian example: A customer's address is updated.
SQL to update data: UPDATE students SET grade = 'A' WHERE name = 'Ada';
Mini summary: Updating data changes existing information in a table.
Definition: Deleting data means removing rows from a table.
Why it is important: Sometimes we need to remove old or incorrect information.
Simple explanation: It's like tearing out a page from a notebook.
Real-life example: Removing a student who has left the school.
School example: Deleting a test score that was entered incorrectly.
Home example: Removing a chore that is no longer relevant.
Nigerian example: Removing a customer who closed their account.
SQL to delete data: DELETE FROM students WHERE name = 'Chidi';
Mini summary: Deleting data removes rows from a table.
Definition: The WHERE clause helps us search for specific rows that match a condition.
Why it is important: It helps us find exactly what we are looking for.
Simple explanation: It's like using a filter to find only the things you want.
Real-life example: Find all students who are 10 years old.
School example: Find all students who got an A.
Home example: Find all chores that are not completed.
Nigerian example: Find all customers with a balance over β¦100,000.
SQL with WHERE: SELECT * FROM students WHERE age = 10; SELECT name FROM students WHERE grade = 'A';
Mini summary: WHERE helps us search for specific data.
Definition: ORDER BY sorts the results in ascending or descending order.
Why it is important: It helps us see data in a meaningful order.
Simple explanation: It's like putting numbers in order from smallest to largest.
Real-life example: Sorting students by age.
School example: Sorting test scores from highest to lowest.
Home example: Sorting chores by priority.
Nigerian example: Sorting customers by account balance.
SQL with ORDER BY: SELECT * FROM students ORDER BY age DESC;
Mini summary: ORDER BY helps us sort data.
Definition: SOC Analysts use MySQL to search logs and find suspicious activities.
Why it is important: MySQL helps investigators find clues quickly.
Simple explanation: It's like using a magnifying glass to find tiny clues.
Real-life example: Searching login logs for failed attempts.
School example: Searching for who accessed a system late at night.
Home example: Searching for who logged into a smart device.
Nigerian example: Searching for suspicious transactions in a bank's database.
Security Query Example: SELECT * FROM login_logs WHERE login_time > '22:00:00' AND success = false;
Mini summary: MySQL helps SOC Analysts find security clues.
Definition: You can combine SELECT, WHERE, and ORDER BY to create powerful searches.
Why it is important: Combining commands gives us more control.
Simple explanation: It's like using a toolkit with many tools together.
Real-life example: Find failed logins after 10 PM and sort by time.
School example: Find students with B grades and sort by name.
Home example: Find high-priority chores and sort by deadline.
Nigerian example: Find customers with low balances and sort by last transaction.
Combined Query: SELECT * FROM login_logs WHERE success = false ORDER BY login_time DESC;
Mini summary: Combining commands makes searches more powerful.
Definition: The more you practise MySQL, the better you become.
Why it is important: Practice helps you remember commands and use them quickly.
Simple explanation: Like riding a bike β you get better with practice.
Real-life example: A SOC Analyst practises queries every day.
School example: Students practise writing SQL commands in class.
Home example: A parent practises with a simple database.
Nigerian example: A bank employee practises with customer data.
Practice Schedule: - Write a CREATE TABLE command - INSERT 5 rows - SELECT specific data - UPDATE a row - DELETE a row
Mini summary: Practice is key to becoming a MySQL expert.
Definition: A summary of the most important MySQL commands.
Why it is important: Knowing the basics is enough to start using MySQL.
Simple explanation: These are the building blocks of MySQL.
Real-life example: Every SOC Analyst uses these commands.
School example: Students learn these commands first.
Home example: These commands can be used for simple projects.
Nigerian example: These commands are used in many Nigerian companies.
Key Commands: - CREATE TABLE - INSERT INTO - SELECT - UPDATE - DELETE - WHERE - ORDER BY
Mini summary: These are the essential MySQL commands.
Definition: You have learned the basics of MySQL and can use it to manage data.
Why it is important: This skill is valuable for any SOC Analyst.
Simple explanation: You can now organise, search, and manage data like a pro.
Real-life example: You can help a company search through logs.
School example: You can help your teacher organize grades.
Home example: You can help your family track chores or movies.
Nigerian example: You can help a small business track customers.
You β Learned MySQL β Can manage data! π
Mini summary: You are now a MySQL user β congratulations!
Step 1: Plan columns (name, age, grade)
Step 2: CREATE TABLE students (name VARCHAR(50), age INT, grade VARCHAR(2));
Step 3: Table created.
Step 4: INSERT INTO students (name, age, grade) VALUES ('Tunde', 10, 'A');
Step 5: SELECT * FROM students;
Step 6: UPDATE students SET grade = 'B' WHERE name = 'Tunde';
Step 7: DELETE FROM students WHERE name = 'Tunde';
Plan Table
|
V
Create Table
|
V
Insert Data
|
V
Query Data (SELECT)
|
V
Analyse Results
|
V
Update/Delete as Needed
| Command | What It Does | Example |
|---|---|---|
| CREATE TABLE | Creates a new table | CREATE TABLE students (name VARCHAR(50)); |
| INSERT INTO | Adds data | INSERT INTO students VALUES ('Tunde'); |
| SELECT | Reads data | SELECT * FROM students; |
| UPDATE | Changes data | UPDATE students SET name = 'Tunde' WHERE id = 1; |
| DELETE | Removes data | DELETE FROM students WHERE id = 1; |
| Data Type | What It Stores | Example |
|---|---|---|
| INT | Whole numbers | 10, 25, 100 |
| VARCHAR | Text (short) | 'Tunde', 'Lagos' |
| DATE | Dates | '2025-01-01' |
| DECIMAL | Numbers with decimals | 10.50 |
Lesson 1: What is a database?
|
Lesson 2: What is MySQL?
|
Lesson 3: Tables
|
Lesson 4: CREATE TABLE
|
Lesson 5: INSERT
|
Lesson 6: SELECT
|
Lesson 7: UPDATE
|
Lesson 8: DELETE
|
Lesson 9: WHERE
|
Lesson 10: ORDER BY
|
Lesson 11: Security Investigations
|
Lesson 12: Combining Commands
|
YOU ARE A MYSQL USER! π
Congratulations! You have completed Module Four of your Security Operation Centre Analyst training. You have learned about MySQL β a powerful language for managing data. You learned how to create tables, insert data, read data, update data, and delete data. You also learned how to use WHERE to filter and ORDER BY to sort. You now have the skills to search for clues in data β a vital skill for any SOC Analyst!
Match the command to its action:
| Command | Action |
|---|---|
| CREATE TABLE | Creates a new table |
| INSERT | Adds data |
| SELECT | Reads data |
| UPDATE | Changes data |
| DELETE | Removes data |
Scenario 1: You work at a school and need to store student data. Create a table called 'students' with columns for name, age, and grade. Insert three students and then select all students who are 10 years old.
Scenario 2: A company has a table of employees. One employee has left the company. Write a command to delete their record.
Scenario 3: A bank has a table of customer accounts. One customer's address has changed. Write a command to update their address.
MySQL Challenge: In groups of 4, design a simple database for a school. Create a table for students, a table for teachers, and a table for classes. Insert sample data and write queries to find specific information. Present your database to the class.
My SQL Practice: Create a table with your favourite movies (title, genre, rating). Insert 5 movies. Write a query to find all movies with a rating of 5. Write a query to sort movies by rating. Write a query to update a movie's rating. Write a query to delete a movie.
Task: Create a database to store security logs. The table should have columns: log_id, timestamp, user, action, success. Insert 10 sample logs. Write queries to find all failed logins, all actions after a certain time, and all actions by a specific user.
Assignment: Write a report on how MySQL is used in a Nigerian company or organisation. Include examples of how they use it, what data they store, and how they protect it.
Challenge: Write a MySQL query that finds all suspicious login attempts. Use a table called 'login_logs' with columns: id, username, login_time, success. Find all failed logins after 10 PM, and sort them by time.
Fill-in-the-Blank Answers: 1. database, 2. MySQL, 3. table, 4. CREATE TABLE, 5. INSERT, 6. SELECT, 7. UPDATE, 8. DELETE, 9. WHERE, 10. ORDER BY, 11. SOC, 12. changes, 13. WHERE, 14. Practice, 15. Nigerian.
True or False: 1T, 2F, 3T, 4F, 5F, 6T, 7T, 8T, 9T, 10F.
Multiple Choice Answers: 1B, 2B, 3A, 4B, 5A, 6B, 7A, 8B, 9A, 10B, 11A, 12A, 13B, 14B, 15A.
In Module Five, we will dive deeper into threat detection and analysis. You will learn how to use MySQL and other tools to identify and investigate security incidents. We will also learn about advanced SQL techniques and how to use them in real-world scenarios.
Before next class: Review the commands you learned in this module. Think about how you could use them to find suspicious activities in a log database.
ποΈ You have completed Module Four β keep up the great work! ποΈ
Hello, data detective! In Module Four, you learned the basics of MySQL β how to create tables, add data, read data, update data, and delete data. Now, in Module Five, we will go further. We will learn advanced techniques to search, filter, and connect data. These skills will help you find hidden clues and investigate security incidents like a pro!
In Module Four, you learned the basic commands of MySQL. You learned how to create tables, add data, read data, update data, and delete data. But in real security investigations, we need more powerful tools. We need to search for patterns, find relationships, and analyse large amounts of data quickly.
In this module, we will learn advanced MySQL skills. We will learn how to use JOIN to combine tables, GROUP BY to group data, and subqueries to ask complex questions. We will also learn how to use MySQL to find suspicious patterns and investigate security incidents. By the end of this module, you will be a MySQL expert!
Remember: Great detectives connect the dots. MySQL helps you connect the dots!
After this module, you will be able to:
Chidi is 10 years old and lives in Abuja. His school has a new computer lab. One day, the lab manager noticed that someone had been logging in late at night and trying to guess passwords. He had two tables of data: one with login logs and one with student information. But he couldn't figure out who the suspicious person was.
Chidi's older brother, Emeka, is a SOC Analyst. He came to help. He used a special MySQL command called JOIN to combine the two tables. He searched for all failed logins after 10 PM and connected them to student names. In just a few seconds, he found that only one student had failed logins late at night β a student who had been caught before.
Chidi was amazed. He asked Emeka to teach him advanced MySQL. Emeka said, "It's like putting together pieces of a puzzle. Let me show you how to use JOIN and GROUP BY!"
Question for you: Have you ever had to connect pieces of information to solve a puzzle?
Definition: In Module Four, we learned basic MySQL commands: CREATE TABLE, INSERT, SELECT, UPDATE, DELETE, WHERE, and ORDER BY.
Why it is important: These are the foundation for advanced commands.
Simple explanation: Before we learn to run, we need to learn to walk.
Real-life example: You use basic commands to create a table of students.
School example: You create a table of test scores.
Home example: You create a table of chores.
Nigerian example: You create a table of customers.
Basic Commands: - CREATE TABLE - INSERT INTO - SELECT - UPDATE - DELETE - WHERE - ORDER BY
Mini summary: Basic commands are the building blocks of MySQL.
Definition: A JOIN combines data from two or more tables based on a common column.
Why it is important: JOIN helps us connect information that is stored in different tables.
Simple explanation: It's like matching puzzle pieces β you find the pieces that fit together.
Real-life example: Combining a table of students with a table of their grades.
School example: Combining a table of teachers with a table of classes.
Home example: Combining a table of family members with a table of chores.
Nigerian example: Combining a table of customers with a table of orders.
JOIN Example: Students table: name, age, class_id Classes table: class_id, class_name JOIN them to get: name, age, class_name
Mini summary: JOIN helps us combine data from different tables.
Definition: INNER JOIN returns only the rows that match in both tables.
Why it is important: It helps us find data that exists in both tables.
Simple explanation: It's like finding friends who have the same favourite colour.
Real-life example: Finding students who have grades recorded.
School example: Finding teachers who are assigned to a class.
Home example: Finding family members who have chores assigned.
Nigerian example: Finding customers who have placed orders.
INNER JOIN Syntax: SELECT students.name, grades.grade FROM students INNER JOIN grades ON students.id = grades.student_id;
Mini summary: INNER JOIN matches data that exists in both tables.
Definition: LEFT JOIN returns all rows from the left table, and matching rows from the right table. If there is no match, it shows NULL.
Why it is important: It helps us find data that is missing from one table.
Simple explanation: It's like a guest list β you have all guests, and some might not have RSVP'd.
Real-life example: Finding students who have no grades recorded.
School example: Finding teachers who are not assigned to a class.
Home example: Finding family members who have no chores.
Nigerian example: Finding customers who have never placed an order.
LEFT JOIN Syntax: SELECT students.name, grades.grade FROM students LEFT JOIN grades ON students.id = grades.student_id;
Mini summary: LEFT JOIN includes all rows from the left table, even if there's no match.
Definition: GROUP BY groups rows that have the same value in a column. It is often used with aggregate functions like COUNT, SUM, AVG.
Why it is important: It helps us find patterns and summaries.
Simple explanation: It's like counting how many of each colour you have in a box of crayons.
Real-life example: Counting how many students are in each class.
School example: Finding the average test score for each subject.
Home example: Counting how many chores each person has.
Nigerian example: Counting how many orders each customer has placed.
GROUP BY Syntax: SELECT class_id, COUNT(*) AS student_count FROM students GROUP BY class_id;
Mini summary: GROUP BY groups data and helps us find patterns.
Definition: HAVING is like WHERE, but it filters groups created by GROUP BY.
Why it is important: It helps us filter groups based on a condition.
Simple explanation: It's like saying "only show me groups that have more than 5 students."
Real-life example: Finding classes that have more than 20 students.
School example: Finding subjects with an average score above 80.
Home example: Finding family members with more than 5 chores.
Nigerian example: Finding customers with more than 10 orders.
HAVING Syntax: SELECT class_id, COUNT(*) AS student_count FROM students GROUP BY class_id HAVING student_count > 10;
Mini summary: HAVING filters groups based on a condition.
Definition: A subquery is a query inside another query. It helps us ask complex questions.
Why it is important: It allows us to answer questions that need multiple steps.
Simple explanation: It's like asking a friend a question, and then asking them another question based on the answer.
Real-life example: Finding students who scored higher than the average.
School example: Finding subjects where the average score is above the overall average.
Home example: Finding chores that take longer than the average.
Nigerian example: Finding customers who have spent more than the average.
Subquery Syntax: SELECT name FROM students WHERE grade > (SELECT AVG(grade) FROM students);
Mini summary: Subqueries help us ask multiple-step questions.
Definition: LIKE is used to search for a pattern in a column. Wildcards like % (any characters) and _ (one character) help us search.
Why it is important: It helps us find data that matches a pattern, not just an exact value.
Simple explanation: It's like finding all words that start with "A".
Real-life example: Finding all students whose names start with "A".
School example: Finding all emails that end with ".edu".
Home example: Finding all movies that start with "The".
Nigerian example: Finding all customers with "Lagos" in their address.
LIKE Syntax: SELECT * FROM students WHERE name LIKE 'A%'; SELECT * FROM students WHERE email LIKE '%@gmail.com';
Mini summary: LIKE helps us search for patterns in data.
Definition: LIMIT restricts the number of rows returned by a query.
Why it is important: It helps us manage large datasets and see only the most important results.
Simple explanation: It's like only looking at the first page of a search result.
Real-life example: Showing only the top 10 students.
School example: Showing the top 5 test scores.
Home example: Showing the next 3 movies to watch.
Nigerian example: Showing the top 10 customers by spending.
LIMIT Syntax: SELECT * FROM students ORDER BY grade DESC LIMIT 5;
Mini summary: LIMIT controls how many rows we see.
Definition: We can combine JOIN, GROUP BY, and HAVING for powerful analysis.
Why it is important: It helps us answer complex security questions.
Simple explanation: It's like using all your detective tools at once.
Real-life example: Finding classes with more than 5 students who scored above 80.
School example: Finding subjects where the average score is above 75.
Home example: Finding family members with more than 3 chores and an average duration of 30 minutes.
Nigerian example: Finding customers who have placed more than 5 orders with a total spending above β¦10,000.
Combined Query: SELECT classes.name, COUNT(students.id) AS student_count, AVG(grades.grade) AS avg_grade FROM classes JOIN students ON classes.id = students.class_id JOIN grades ON students.id = grades.student_id GROUP BY classes.name HAVING student_count > 5 AND avg_grade > 70;
Mini summary: Combining tools gives us powerful analysis.
Definition: SOC Analysts use MySQL to analyse login logs and find suspicious activities.
Why it is important: It helps us detect and respond to security incidents.
Simple explanation: It's like searching for footprints to find the culprit.
Real-life example: Finding all failed login attempts after 10 PM.
School example: Finding who accessed a file after hours.
Home example: Finding who logged into a smart device.
Nigerian example: Finding suspicious transactions in a bank.
Security Query: SELECT username, login_time, success FROM login_logs WHERE success = false AND login_time > '22:00:00' ORDER BY login_time DESC;
Mini summary: MySQL helps us investigate security incidents.
Definition: Sometimes we need to combine data from multiple tables to find suspicious patterns.
Why it is important: It helps us connect clues from different sources.
Simple explanation: It's like putting together puzzle pieces from different boxes.
Real-life example: Combining login logs with user information to find who made failed attempts.
School example: Combining access logs with student information.
Home example: Combining device logs with family member information.
Nigerian example: Combining transaction logs with customer information.
Security Query with JOIN: SELECT users.name, logs.login_time, logs.success FROM login_logs logs JOIN users ON logs.user_id = users.id WHERE logs.success = false ORDER BY logs.login_time DESC;
Mini summary: Combining tables helps us find hidden connections.
Definition: We can use advanced MySQL to find unusual patterns, like logins at odd times or from strange locations.
Why it is important: Unusual patterns often indicate a security threat.
Simple explanation: It's like noticing that someone is wearing a disguise.
Real-life example: Finding logins from a country where the company doesn't operate.
School example: Finding access to files that a student shouldn't see.
Home example: Finding a device that is online when no one is home.
Nigerian example: Finding transactions from unusual locations.
Unusual Pattern Query: SELECT user_id, login_time, ip_address FROM login_logs WHERE login_time BETWEEN '00:00:00' AND '05:00:00' AND ip_address NOT LIKE '192.168.%';
Mini summary: Advanced MySQL helps us find unusual patterns.
Definition: The more you practise advanced MySQL, the better you become at security investigations.
Why it is important: Practice helps you think like a detective and find clues faster.
Simple explanation: Like practising a sport β you get better with time.
Real-life example: A SOC Analyst practises queries every day.
School example: Students practise writing complex queries.
Home example: A parent practises with a home database.
Nigerian example: A bank analyst practises with customer data.
Practice Exercises: - Write a query with JOIN and GROUP BY - Write a query with a subquery - Write a query with LIKE and wildcards - Write a query with HAVING
Mini summary: Practice makes you a faster, better detective.
Definition: You have learned advanced MySQL skills. You can now investigate security incidents like a pro.
Why it is important: These skills are essential for any SOC Analyst.
Simple explanation: You are now a master of data β you can find hidden clues.
Real-life example: You can help a company investigate a security breach.
School example: You can help your school analyse access logs.
Home example: You can help your family monitor their devices.
Nigerian example: You can help a bank detect fraud.
You β Learned Advanced MySQL β Can Investigate Threats! π΅οΈββοΈ
Mini summary: You are now an advanced MySQL user β ready to investigate!
Step 1: Find failed logins and user names Step 2: Tables: login_logs, users Step 3: Common column: user_id Step 4: SELECT users.name, logs.login_time Step 5: JOIN users ON logs.user_id = users.id Step 6: WHERE logs.success = false Step 7: ORDER BY logs.login_time DESC Step 8: Run the query!
Identify Question
|
V
Identify Tables
|
V
Choose JOIN Type
|
V
Write SELECT Statement
|
V
Add GROUP BY (if needed)
|
V
Add HAVING (if needed)
|
V
Add ORDER BY
|
V
Run Query
|
V
Analyse Results
| JOIN Type | What It Returns | Use Case |
|---|---|---|
| INNER JOIN | Only matching rows | Find students with grades |
| LEFT JOIN | All rows from left table | Find students without grades |
| RIGHT JOIN | All rows from right table | Rarely used |
| FULL JOIN | All rows from both tables | Not supported in MySQL |
| Function | What It Does | Example |
|---|---|---|
| COUNT | Counts rows | COUNT(*) |
| SUM | Adds values | SUM(amount) |
| AVG | Calculates average | AVG(grade) |
| MIN | Finds minimum | MIN(grade) |
| MAX | Finds maximum | MAX(grade) |
Lesson 1: Review basic commands
|
Lesson 2: Introduction to JOIN
|
Lesson 3: INNER JOIN
|
Lesson 4: LEFT JOIN
|
Lesson 5: GROUP BY
|
Lesson 6: HAVING
|
Lesson 7: Subqueries
|
Lesson 8: LIKE and Wildcards
|
Lesson 9: LIMIT
|
Lesson 10: Combining commands
|
Lesson 11: Security with MySQL (Logs)
|
Lesson 12: Security with MySQL (Multiple tables)
|
Lesson 13: Finding unusual patterns
|
Lesson 14: Practice
|
YOU ARE AN ADVANCED MYSQL USER! π
Congratulations! You have completed Module Five of your Security Operation Centre Analyst training. You have learned advanced MySQL skills β JOIN, GROUP BY, HAVING, subqueries, LIKE, wildcards, and LIMIT. You have learned how to combine data from multiple tables, group data to find patterns, and ask complex questions. You have also learned how to use these skills in security investigations. You are now a true MySQL expert!
Match the command to its description:
| Command | Description |
|---|---|
| JOIN | Combines tables |
| GROUP BY | Groups rows |
| HAVING | Filters groups |
| LIKE | Searches for a pattern |
| LIMIT | Restricts rows |
Scenario 1: You are a SOC Analyst. You have two tables: login_logs (user_id, login_time, success) and users (id, name). Write a query to find all failed logins after 10 PM and the user names.
Scenario 2: You have a table of transactions (customer_id, amount, date). Write a query to find the total spending for each customer, and only show customers who have spent more than β¦10,000.
Scenario 3: You have a table of emails (id, sender, subject). Write a query to find all emails that contain the word "phishing" in the subject.
Security Investigation Challenge: In groups of 4, you are given a sample database with login logs, user information, and transaction data. Your task is to write queries to find suspicious activities β failed logins, unusual transaction amounts, and logins from unusual locations. Present your findings to the class.
My Advanced SQL Practice: Create a database with at least two tables (e.g., students and grades). Write queries that use JOIN, GROUP BY, HAVING, subqueries, and LIKE. Write a report on what you found.
Task: Create a security log database with tables for login logs, user information, and IP addresses. Write at least 5 advanced queries to find suspicious activities, such as failed logins, logins from unusual countries, and users with multiple failed attempts. Present your queries and findings.
Assignment: Write a report on a real-world security incident that could have been detected using MySQL. Explain how MySQL queries could have been used to identify the suspicious activity.
Challenge: Write a complex MySQL query that finds all users who have had more than 3 failed login attempts in the last 24 hours, and then joined by a user who logged in successfully from a different IP address within 5 minutes. Use JOIN, GROUP BY, HAVING, and subqueries.
Fill-in-the-Blank Answers: 1. JOIN, 2. INNER, 3. LEFT, 4. GROUP BY, 5. HAVING, 6. subquery, 7. LIKE, 8. LIMIT, 9. aggregate, 10. Security, 11. %, 12. _, 13. WHERE, 14. Practice, 15. advanced.
True or False: 1T, 2F, 3F, 4T, 5F, 6T, 7F, 8T, 9T, 10F.
Multiple Choice Answers: 1A, 2B, 3A, 4B, 5B, 6A, 7B, 8A, 9A, 10B, 11B, 12A, 13B, 14C, 15B.
In Module Six, we will learn about threat detection tools and how SOC Analysts use them to monitor networks and detect attacks. We will look at tools like SIEM, intrusion detection systems, and endpoint detection. We will also learn how to use MySQL to analyse security data.
Before next class: Think about how you would monitor a network for suspicious activities. What would you look for? We will explore this together in the next module.
ποΈ You have completed Module Five β keep up the great work! ποΈ
Hello, security detective! You have learned the basics of MySQL, advanced queries, and how to combine tables. Now, in Module Six, we will use MySQL to hunt for threats! Threat hunting means actively searching for hidden dangers in your data. We will learn how to use MySQL to find suspicious patterns, detect attacks, and protect our systems.
In Module Four, you learned the basics of MySQL β how to create tables, add data, read data, update data, and delete data. In Module Five, you learned advanced skills like JOIN, GROUP BY, HAVING, subqueries, LIKE, and LIMIT. Now, in Module Six, we will put all of these skills together to hunt for threats.
Threat hunting is like being a detective. Instead of waiting for an alarm to go off, you actively search for clues that something is wrong. MySQL is a powerful tool for threat hunting because it can search through millions of records quickly. By the end of this module, you will be able to use MySQL to find suspicious activities, investigate incidents, and keep systems safe.
Remember: The best hunters are always looking for clues. Let's start hunting!
After this module, you will be able to:
Ade is 10 years old and lives in Ibadan. His father works at a bank. One morning, Ade's father told him that someone had been trying to log into the bank's system late at night. The security team was worried, but they couldn't find the culprit.
Ade had just learned MySQL in his SOC Analyst course. He asked his father, "Can I see the login logs?" His father gave him a copy of the logs. Ade opened MySQL and started writing queries. He searched for failed logins after 10 PM. He found dozens of failed attempts β all from the same IP address!
He then used a JOIN to combine the login logs with the user table. He found that the IP address belonged to a former employee who had left the company. The security team blocked the IP address and improved their security. Ade's father was so proud of him.
Ade said, "MySQL is like a superpower! It helped me find the bad guy."
Question for you: What would you do if you found suspicious activity in a system?
Definition: Threat hunting is actively searching for hidden threats in a system. It's not waiting for an alarm β it's looking for clues.
Why it is important: Many attacks go unnoticed for months. Threat hunting helps us find them early.
Simple explanation: It's like being a detective who looks for clues before a crime happens.
Real-life example: A security team searches for unusual logins every day.
School example: A teacher checks who is accessing the school's computer system late at night.
Home example: A parent checks who is using their smart devices at odd hours.
Nigerian example: A bank searches for suspicious transactions.
Threat Hunting = Active Search - Look for patterns - Find anomalies - Investigate suspicious activities
Mini summary: Threat hunting is actively searching for hidden dangers.
Definition: A security database is a collection of security-related data, like login logs, access logs, and system events.
Why it is important: We need a place to store and organise security data so we can search it.
Simple explanation: It's like having a detective's notebook to write down all the clues.
Real-life example: A company creates a table to store all login attempts.
School example: A school creates a table to track who uses the computer lab.
Home example: A family creates a table to track who logs into their smart devices.
Nigerian example: A bank creates a table to track all transactions.
Security Database Tables: - login_logs (id, user_id, login_time, success, ip_address) - users (id, name, email, role) - system_events (id, event_type, description, time)
Mini summary: A security database helps us store and organise security data.
Definition: Failed login attempts are times when someone tries to log in but gets the password wrong. This can be a sign of an attack.
Why it is important: Many failed attempts might mean someone is trying to break into the system.
Simple explanation: It's like someone trying to open a locked door with the wrong key again and again.
Real-life example: A hacker tries 100 different passwords to get into a system.
School example: A student tries to guess a teacher's password.
Home example: Someone tries to guess your smart device password.
Nigerian example: A fraudster tries to guess a customer's bank password.
Query for failed logins: SELECT * FROM login_logs WHERE success = false;
Mini summary: Failed login attempts can indicate an attack.
Definition: Logins that happen after normal working hours can be suspicious.
Why it is important: Most employees don't log in at 2 AM. If someone does, it might be an attacker.
Simple explanation: It's like hearing someone in your house at midnight β it's not normal.
Real-life example: An employee logs in at 3 AM from a different country.
School example: A student logs into the school system at 1 AM.
Home example: A family member logs into a streaming service at 4 AM.
Nigerian example: A bank employee logs in at 2 AM from an unusual location.
Query for after-hours failed logins: SELECT * FROM login_logs WHERE success = false AND TIME(login_time) > '22:00:00';
Mini summary: After-hours logins can be a sign of an attack.
Definition: An IP address is a unique number that identifies a device on the internet. Suspicious IP addresses are those from unknown or suspicious locations.
Why it is important: Attackers often use IP addresses from other countries to hide their identity.
Simple explanation: It's like a stranger coming to your house β you don't know who they are.
Real-life example: An IP address from a country where the company doesn't operate.
School example: An IP address from a different city accessing the school system.
Home example: An unknown device connecting to your Wi-Fi.
Nigerian example: A transaction from an IP address outside Nigeria.
Query for suspicious IPs: SELECT * FROM login_logs WHERE ip_address NOT LIKE '192.168.%' AND ip_address NOT LIKE '10.%';
Mini summary: Suspicious IP addresses can indicate an attack.
Definition: Unusual behaviour means a user is doing something they don't normally do, like logging in at odd times or from different locations.
Why it is important: Unusual behaviour can mean an account has been hacked.
Simple explanation: It's like your friend suddenly acting differently β something might be wrong.
Real-life example: An employee who always logs in from Lagos suddenly logs in from London.
School example: A student who always logs in during school hours suddenly logs in at midnight.
Home example: A family member who never uses the TV suddenly starts streaming at 3 AM.
Nigerian example: A bank customer who always uses a specific branch suddenly uses a branch in another state.
Query for unusual behaviour: SELECT user_id, COUNT(*) AS login_count FROM login_logs WHERE login_time BETWEEN '00:00:00' AND '05:00:00' GROUP BY user_id HAVING login_count > 3;
Mini summary: Unusual behaviour can mean an account is compromised.
Definition: A brute force attack is when an attacker tries many passwords in a short time to guess the right one.
Why it is important: Brute force attacks are very common. They can break into systems if the passwords are weak.
Simple explanation: It's like trying every key in a keyring until you find the right one.
Real-life example: An attacker tries 10,000 passwords in one hour.
School example: A student tries 100 different passwords to get into the school system.
Home example: Someone tries to guess your Wi-Fi password.
Nigerian example: A fraudster tries to guess a bank customer's PIN.
Query for brute force: SELECT user_id, COUNT(*) AS attempts FROM login_logs WHERE success = false AND login_time BETWEEN NOW() - INTERVAL 1 HOUR AND NOW() GROUP BY user_id HAVING attempts > 50;
Mini summary: Brute force attacks try many passwords quickly.
Definition: If many failed logins come from the same IP address, it could be an attacker.
Why it is important: Attackers often try many accounts from the same IP address.
Simple explanation: It's like someone trying all the doors in a building to find one that is unlocked.
Real-life example: An attacker uses one computer to try to hack into many accounts.
School example: A student from one computer tries to access many student accounts.
Home example: A device on your network tries to access many services.
Nigerian example: An attacker uses one IP to try to hack into a bank's customer accounts.
Query for same IP failed logins: SELECT ip_address, COUNT(*) AS attempts FROM login_logs WHERE success = false GROUP BY ip_address HAVING attempts > 5;
Mini summary: Multiple failed logins from the same IP can indicate an attack.
Definition: Unusual locations are places where a user doesn't normally log in from.
Why it is important: If a user logs in from a different country, their account might be hacked.
Simple explanation: It's like your friend suddenly calling you from a different country.
Real-life example: A user logs in from Nigeria and then 10 minutes later from the UK.
School example: A student logs in from home and then from a different city.
Home example: A family member logs into their email from two different places.
Nigerian example: A bank customer logs in from Lagos and then from Kano in 5 minutes.
Query for unusual locations: SELECT user_id, ip_address, login_time FROM login_logs WHERE ip_address NOT LIKE '192.168.%' ORDER BY user_id, login_time;
Mini summary: Logins from unusual locations can indicate account compromise.
Definition: Combining clues means using multiple queries to find a pattern.
Why it is important: A single clue might not mean anything, but several clues together can reveal an attack.
Simple explanation: It's like putting together a jigsaw puzzle β each piece is a clue.
Real-life example: Failed logins + unusual IP + after-hours = likely attack.
School example: Failed logins + late at night + different city = suspicious.
Home example: Multiple failed logins + unknown device = security threat.
Nigerian example: Failed logins + unusual location + after-hours = fraud attempt.
Combined Query: SELECT users.name, logs.ip_address, logs.login_time FROM login_logs logs JOIN users ON logs.user_id = users.id WHERE logs.success = false AND TIME(logs.login_time) > '22:00:00' AND logs.ip_address NOT LIKE '192.168.%' ORDER BY logs.login_time DESC;
Mini summary: Combining clues helps us detect hidden attacks.
Definition: Subqueries can help us find users who have multiple suspicious activities.
Why it is important: Some attackers are very active. Subqueries help us find them.
Simple explanation: It's like asking a question, then asking another question based on the answer.
Real-life example: Find users who have had more than 3 failed logins and a login from an unusual IP.
School example: Find students who have failed logins and late-night access.
Home example: Find family members who have failed logins and unusual activity.
Nigerian example: Find customers who have failed logins and unusual transactions.
Subquery Example:
SELECT name FROM users
WHERE id IN (
SELECT user_id FROM login_logs
WHERE success = false
GROUP BY user_id
HAVING COUNT(*) > 5
);
Mini summary: Subqueries help us find users with multiple suspicious activities.
Definition: LIKE can help us find suspicious patterns in text, like email addresses or IP addresses.
Why it is important: Attackers often use patterns, like fake email addresses.
Simple explanation: It's like searching for a word in a book.
Real-life example: Finding all emails from a suspicious domain.
School example: Finding all students with fake email addresses.
Home example: Finding all devices with suspicious MAC addresses.
Nigerian example: Finding all transactions with suspicious reference numbers.
LIKE Query: SELECT * FROM users WHERE email LIKE '%hacker%'; SELECT * FROM login_logs WHERE ip_address LIKE '10.0.%';
Mini summary: LIKE helps us find patterns in text data.
Definition: Date and time functions help us analyse data over time.
Why it is important: Attacks often happen at specific times.
Simple explanation: It's like checking the clock to see when something happened.
Real-life example: Finding all logins in the last 24 hours.
School example: Finding all access to the school system in the last week.
Home example: Finding all smart device usage in the last hour.
Nigerian example: Finding all transactions in the last month.
Date/Time Queries: SELECT * FROM login_logs WHERE login_time > NOW() - INTERVAL 1 DAY; SELECT * FROM login_logs WHERE DATE(login_time) = CURDATE();
Mini summary: Date/time functions help us analyse data over time.
Definition: Practice means using your skills on real-world data.
Why it is important: Practice helps you think like a detective.
Simple explanation: Like a fire drill β you practise so you're ready for the real thing.
Real-life example: A security team practices threat hunting every month.
School example: Students practice hunting for threats in a lab environment.
Home example: A parent practices monitoring their devices.
Nigerian example: A bank practices threat hunting on test data.
Practice Scenario: You have a login_logs table. Write queries to find: 1. All failed logins in the last 24 hours. 2. All logins after 11 PM. 3. All logins from unusual IP addresses. 4. Users with more than 10 failed logins.
Mini summary: Practice makes you a better threat hunter.
Definition: A threat hunter is someone who actively searches for hidden threats. You have become one!
Why it is important: Your skills can help protect systems and stop attacks.
Simple explanation: You are now a digital detective.
Real-life example: You can help a company find suspicious activities.
School example: You can help your school protect its network.
Home example: You can help your family protect their devices.
Nigerian example: You can help a bank detect fraud.
You β Learned threat hunting β Can protect systems! π
Mini summary: You are now a threat hunter β congratulations!
Step 1: Set up database Step 2: Collect data Step 3: Define normal behaviour Step 4: Write queries for anomalies Step 5: Analyse results Step 6: Take action Step 7: Review and improve
Define Normal
|
V
Collect Data
|
V
Write Queries
|
V
Analyse Results
|
V
Identify Anomalies
|
V
Investigate
|
V
Take Action
|
V
Review and Improve
| Normal Activity | Suspicious Activity |
|---|---|
| Logins during working hours | Logins after midnight |
| Logins from known IPs | Logins from unknown IPs |
| Few failed logins | Many failed logins |
| Logins from one location | Logins from multiple locations |
| Query Purpose | Example Query |
|---|---|
| Failed logins | SELECT * FROM login_logs WHERE success = false; |
| After-hours logins | SELECT * FROM login_logs WHERE TIME(login_time) > '22:00:00'; |
| Unusual IPs | SELECT * FROM login_logs WHERE ip_address NOT LIKE '192.168.%'; |
| Brute force | SELECT user_id, COUNT(*) FROM login_logs WHERE success = false GROUP BY user_id HAVING COUNT(*) > 10; |
| Combined clues | SELECT users.name, logs.ip_address FROM login_logs logs JOIN users ON logs.user_id = users.id WHERE logs.success = false AND TIME(logs.login_time) > '22:00:00'; |
Lesson 1: What is threat hunting?
|
Lesson 2: Setting up a security database
|
Lesson 3: Finding failed logins
|
Lesson 4: After-hours logins
|
Lesson 5: Suspicious IP addresses
|
Lesson 6: Unusual user behaviour
|
Lesson 7: Brute force attacks
|
Lesson 8: Multiple failed logins from same IP
|
Lesson 9: Logins from unusual locations
|
Lesson 10: Combining clues
|
Lesson 11: Subqueries
|
Lesson 12: LIKE for threat hunting
|
Lesson 13: Date/time functions
|
Lesson 14: Practice
|
YOU ARE A THREAT HUNTER! π
Congratulations! You have completed Module Six of your Security Operation Centre Analyst training. You have learned how to use MySQL for threat hunting. You can now find failed logins, after-hours activity, suspicious IP addresses, and brute force attacks. You have learned to combine clues and use advanced queries to find hidden threats. You are now a true threat hunter!
Match the term to its description:
| Term | Description |
|---|---|
| Threat Hunting | Actively searching for threats |
| Brute Force | Trying many passwords |
| IP Address | Device identifier |
| Failed Login | Unsuccessful login attempt |
| After-Hours | Time outside normal hours |
Scenario 1: You are a SOC Analyst. You notice that there are many failed logins from a specific IP address. Write a query to find all failed logins from that IP in the last 24 hours.
Scenario 2: You have a table of login logs. You want to find all users who have more than 5 failed logins after 10 PM. Write the query.
Scenario 3: You notice that a user has logged in from two different cities in 5 minutes. Write a query to find all users with logins from different locations within a short time.
Threat Hunting Challenge: In groups of 4, you are given a sample database with login logs. Your task is to write queries to find at least 5 suspicious activities. Present your findings to the class and explain why they are suspicious.
My Threat Hunt: Create a database with sample login logs. Write queries to find failed logins, after-hours logins, and suspicious IP addresses. Write a report on your findings.
Task: Build a simple dashboard that shows the results of your threat hunting queries. Include tables for failed logins, after-hours logins, suspicious IPs, and brute force attempts. Present your dashboard to the class.
Assignment: Find a real-world dataset of security logs (or use sample data). Write at least 5 threat hunting queries and document your findings. Explain what each query does and what it found.
Challenge: Write a complex query that finds all users who have had more than 10 failed logins in the last 24 hours, and then joined by a login from an unusual IP address. Use JOIN, GROUP BY, HAVING, and subqueries.
Fill-in-the-Blank Answers: 1. Threat hunting, 2. brute force, 3. IP, 4. After, 5. Unusual, 6. false, 7. subquery, 8. Combining, 9. MySQL, 10. Practice, 11. night, 12. brute force, 13. locations, 14. Date/time, 15. threat.
True or False: 1F, 2T, 3F, 4F, 5T, 6T, 7T, 8F, 9T, 10T.
Multiple Choice Answers: 1B, 2B, 3B, 4A, 5B, 6B, 7A, 8A, 9A, 10B, 11A, 12A, 13A, 14A, 15A.
In Module Seven, we will learn about incident response β what to do when a security incident happens. You will learn how to contain an attack, investigate it, and recover from it. We will also look at how MySQL can help in incident response.
Before next class: Think about what you would do if you discovered a security breach. We will explore this together in the next module.
π‘οΈ You have completed Module Six β keep up the great work! π‘οΈ
Hello, security hero! You have learned how to use MySQL to hunt for threats. Now, in Module Seven, we will learn what to do when a threat becomes a real incident. Incident response is the process of handling a security breach β finding it, stopping it, and recovering from it. MySQL will be your tool to investigate and document everything. Let's become incident response experts!
In Module Six, you learned how to hunt for threats using MySQL. You found suspicious activities like failed logins, after-hours access, and unusual IP addresses. But what happens when you actually find a real attack? That's when incident response begins.
Incident response is like being a firefighter. When a fire (attack) breaks out, you need to act fast. You need to contain the fire, put it out, and then figure out what happened so it doesn't happen again. MySQL helps you do all of this by letting you search through logs, find evidence, and track the attacker's steps.
By the end of this module, you will know how to use MySQL to investigate security incidents, contain attacks, and help your team recover. You will be a true incident responder!
Remember: Stay calm, act fast, and use your tools.
After this module, you will be able to:
Zainab is 10 years old and lives in Kaduna. Her mother works at a hospital. One day, the hospital's computer system stopped working. Patient records were locked. The security team said it was a ransomware attack β someone had locked the files and wanted money to unlock them.
Zainab's mother was worried. She called in the incident response team. Zainab watched as they used MySQL to investigate. They searched the logs to find when the attack started. They found the entry point β a single employee had clicked on a bad link in an email. They isolated the infected computer and restored the files from backups.
Zainab was amazed at how quickly they responded. She asked the team leader, "How did you know what to do?" He said, "We follow a plan. We call it incident response. We detect, contain, eradicate, and recover." Zainab decided she wanted to learn incident response so she could help people too.
Question for you: What would you do if your school's computers were attacked?
Definition: Incident response is the process of handling a security breach β finding it, stopping it, and recovering from it.
Why it is important: A quick and effective response can limit damage, save money, and protect people.
Simple explanation: It's like a fire drill β you have a plan to follow when there's a fire.
Real-life example: A company discovers a hack and follows a plan to stop it.
School example: A school's system is breached and the IT team follows an incident response plan.
Home example: A family member's account is hacked and they change passwords and report it.
Nigerian example: A bank is attacked and the security team responds to protect customer money.
Incident Response Steps: 1. Detect 2. Contain 3. Eradicate 4. Recover 5. Review
Mini summary: Incident response is a plan to handle security breaches.
Definition: An incident response plan is a document that tells you what to do during a security breach. It's like a step-by-step guide.
Why it is important: Having a plan means you don't panic β you know what to do.
Simple explanation: It's like a recipe for handling emergencies.
Real-life example: A company has a plan that includes who to call, what to do, and how to recover.
School example: A school has a plan for cyber attacks.
Home example: A family has a plan for if a device is hacked.
Nigerian example: A bank has a detailed incident response plan.
Incident Response Plan Contents: - Roles and responsibilities - Communication plan - Steps to contain and recover - List of tools - Review process
Mini summary: An incident response plan is a guide for handling breaches.
Definition: Detection is the first step. You need to know that something is wrong. MySQL helps you detect by searching for suspicious patterns.
Why it is important: The earlier you detect an incident, the less damage it can cause.
Simple explanation: It's like noticing that your door is open when you left it closed.
Real-life example: A query finds multiple failed logins from an unknown IP.
School example: A query finds a student accessing files they shouldn't.
Home example: A query finds an unknown device on your Wi-Fi.
Nigerian example: A query finds unusual transactions in a bank.
Detection Query: SELECT * FROM login_logs WHERE success = false AND login_time > NOW() - INTERVAL 1 HOUR AND ip_address NOT LIKE '192.168.%';
Mini summary: MySQL helps detect incidents by finding suspicious patterns.
Definition: Investigation means finding out what happened, when it happened, and who did it. MySQL helps you gather evidence.
Why it is important: Understanding the attack helps you stop it and prevent future attacks.
Simple explanation: It's like being a detective and collecting clues.
Real-life example: A query finds all logins from a suspicious IP address.
School example: A query finds all files accessed by a particular user.
Home example: A query finds all devices that connected to your Wi-Fi at night.
Nigerian example: A query finds all transactions from a specific location.
Investigation Query: SELECT * FROM login_logs WHERE ip_address = '203.0.113.45' ORDER BY login_time;
Mini summary: MySQL helps investigate by gathering evidence.
Definition: Containment means stopping the attack from spreading. You isolate the affected systems.
Why it is important: Containment limits the damage and stops the attacker from moving further.
Simple explanation: It's like closing a door to stop a fire from spreading.
Real-life example: A company disconnects an infected server from the network.
School example: A school disconnects a compromised computer from the school network.
Home example: A family disconnects an infected device from Wi-Fi.
Nigerian example: A bank disables an account that is being attacked.
Containment Actions: - Isolate infected systems - Block suspicious IPs - Disable compromised accounts - Change passwords
Mini summary: Containment stops the attack from spreading.
Definition: MySQL can help you identify which systems to contain. You can find all connections from a suspicious IP or all actions by a compromised user.
Why it is important: Knowing exactly what to contain helps you act quickly.
Simple explanation: It's like knowing exactly which room the fire is in so you can close the right doors.
Real-life example: A query finds all systems that a compromised user accessed.
School example: A query finds all files a suspicious user opened.
Home example: A query finds all devices that a suspicious IP connected to.
Nigerian example: A query finds all accounts that a compromised user accessed.
Containment Query: SELECT DISTINCT system_name FROM access_logs WHERE user_id = 12345;
Mini summary: MySQL helps identify what to contain.
Definition: Eradication means removing the cause of the attack β like deleting malware or closing vulnerabilities.
Why it is important: If you don't remove the cause, the attack will happen again.
Simple explanation: It's like removing a fire's fuel so it can't start again.
Real-life example: A company removes a virus from all infected computers.
School example: A school removes a virus from a computer lab.
Home example: A family removes malware from a device.
Nigerian example: A bank removes a Trojan from its system.
Eradication Steps: - Delete malware - Patch vulnerabilities - Close backdoors - Reset passwords
Mini summary: Eradication removes the cause of the attack.
Definition: Recovery means restoring systems to normal operation. You bring back data from backups and get things running again.
Why it is important: Recovery gets your business back to work.
Simple explanation: It's like rebuilding a house after a fire.
Real-life example: A company restores data from backups.
School example: A school restores student records from a backup.
Home example: A family restores files from a backup.
Nigerian example: A bank restores customer data from backups.
Recovery Steps: - Restore from backups - Test systems - Monitor for recurrence - Communicate with stakeholders
Mini summary: Recovery restores systems to normal.
Definition: MySQL can help you check if recovery was successful. You can query logs to ensure that no further suspicious activity is happening.
Why it is important: You need to make sure the attack is really over.
Simple explanation: It's like checking that the fire is completely out.
Real-life example: A query checks for any new failed logins after recovery.
School example: A query checks for any unusual access after recovery.
Home example: A query checks for any unknown devices after recovery.
Nigerian example: A query checks for any suspicious transactions after recovery.
Recovery Query: SELECT * FROM login_logs WHERE login_time > '2025-01-01 00:00:00' AND success = false AND ip_address NOT LIKE '192.168.%';
Mini summary: MySQL helps verify that recovery was successful.
Definition: Documentation means writing down everything that happened β the timeline, the actions taken, and the lessons learned.
Why it is important: Documentation helps you learn from the incident and improve your security.
Simple explanation: It's like taking notes so you don't forget what you learned.
Real-life example: A security team writes a report on the incident.
School example: A school writes a report on a cyber attack.
Home example: A family writes down what happened and how they fixed it.
Nigerian example: A bank writes a detailed incident report.
Documentation Contents: - Timeline of events - Actions taken - Evidence collected - Lessons learned - Recommendations for improvement
Mini summary: Documentation helps you learn and improve.
Definition: After an incident, you review what happened and make changes to prevent it from happening again.
Why it is important: Continuous improvement makes your systems stronger.
Simple explanation: It's like practising fire drills after a real fire to be better prepared next time.
Real-life example: A company implements new security measures after an attack.
School example: A school updates its security policies.
Home example: A family uses stronger passwords.
Nigerian example: A bank improves its fraud detection systems.
Review Steps: - Analyse the incident - Identify gaps - Implement improvements - Train staff
Mini summary: Reviewing and improving makes your security stronger.
Definition: Let's look at a real example of how an incident was handled.
Why it is important: Learning from real cases helps us prepare.
Simple explanation: It's like learning from history to not repeat mistakes.
Real-life example: The WannaCry ransomware attack in 2017.
School example: A local school that was hit by a phishing attack.
Home example: A family that dealt with a ransomware attack.
Nigerian example: A Nigerian company that responded to a data breach.
Real-World Incident Process: 1. Detection: Alerts of suspicious activity 2. Investigation: Found the entry point 3. Containment: Isolated infected systems 4. Eradication: Removed malware 5. Recovery: Restored data from backups 6. Review: Implemented new security measures
Mini summary: Real-world examples show how incident response works.
Definition: Forensics is the process of collecting and analysing evidence for legal purposes. MySQL can help you preserve and analyse logs.
Why it is important: Evidence can be used to catch attackers and in court.
Simple explanation: It's like collecting fingerprints at a crime scene.
Real-life example: A company preserves logs to help law enforcement.
School example: A school preserves logs to find who hacked the system.
Home example: A family preserves logs to show what happened.
Nigerian example: A bank preserves transaction logs for evidence.
Forensics Steps: - Preserve evidence - Analyse logs - Document findings - Hand over to authorities
Mini summary: Forensics helps collect evidence for legal purposes.
Definition: Practice means running through an incident response exercise with a team.
Why it is important: Practice helps you be ready for a real incident.
Simple explanation: It's like a fire drill β you practice so you're ready for a real fire.
Real-life example: A company runs a simulated attack to test their response.
School example: A school practices responding to a cyber attack.
Home example: A family practices what to do if a device is hacked.
Nigerian example: A bank runs a simulation of a cyber attack.
Practice Scenario: - Simulate an attack - Follow the incident response plan - Use MySQL to investigate - Contain and recover - Review the exercise
Mini summary: Practice ensures you're ready for a real incident.
Definition: An incident responder is someone who can handle security breaches effectively. You have become one!
Why it is important: Your skills can help protect organisations from cyber attacks.
Simple explanation: You are now a digital firefighter.
Real-life example: You can help a company respond to a breach.
School example: You can help your school respond to an attack.
Home example: You can help your family respond to a cyber incident.
Nigerian example: You can help a bank respond to a fraud attempt.
You β Learned incident response β Can protect systems! π¨
Mini summary: You are now an incident responder β congratulations!
Step 1: Detection β SELECT * FROM logs WHERE suspicious = true; Step 2: Investigation β SELECT * FROM logs WHERE ip = 'bad_ip'; Step 3: Containment β SELECT DISTINCT system FROM access WHERE user = 'bad_user'; Step 4: Eradication β Remove malware, patch vulnerabilities. Step 5: Recovery β Restore from backups, monitor for suspicious activity. Step 6: Documentation β Write a report. Step 7: Review β Analyse and improve.
Detect Incident
|
V
Investigate
|
V
Contain
|
V
Eradicate
|
V
Recover
|
V
Document
|
V
Review and Improve
| Step | What It Does | MySQL Example |
|---|---|---|
| Detection | Find suspicious activity | SELECT * FROM logs WHERE suspicious = true; |
| Investigation | Gather evidence | SELECT * FROM logs WHERE ip = 'bad_ip'; |
| Containment | Stop the spread | SELECT DISTINCT system FROM access WHERE user = 'bad_user'; |
| Eradication | Remove the cause | N/A (manual action) |
| Recovery | Restore normal operations | SELECT * FROM logs WHERE login_time > NOW() - INTERVAL 1 DAY; |
| Documentation | Write down everything | N/A (manual action) |
| Review | Analyse and improve | N/A (manual action) |
| Role | Responsibility |
|---|---|
| Incident Commander | Leads the response |
| Investigator | Gathers evidence |
| Containment Lead | Isolates systems |
| Recovery Lead | Restores systems |
| Documentation Lead | Writes the report |
0 min Detect suspicious activity
|
10 min Investigate and identify the threat
|
30 min Contain the attack
|
60 min Eradicate the cause
|
90 min Begin recovery
|
120 min Verify recovery and monitor
|
180 min Document and review
Congratulations! You have completed Module Seven of your Security Operation Centre Analyst training. You have learned how to handle security incidents using MySQL. You now know the steps of incident response β detection, investigation, containment, eradication, recovery, documentation, and review. You have learned how to use MySQL to investigate attacks, contain them, and recover from them. You are now a skilled incident responder!
Match the term to its description:
| Term | Description |
|---|---|
| Detection | Finding something wrong |
| Containment | Stopping the spread |
| Eradication | Removing the cause |
| Recovery | Restoring systems |
| Documentation | Writing down what happened |
Scenario 1: You are a SOC Analyst. You detect multiple failed logins from an unknown IP address. What steps do you take?
Scenario 2: A ransomware attack has occurred at a hospital. You need to respond quickly. Write a plan using the incident response steps.
Scenario 3: After an incident, you need to document what happened. Write a summary of the incident, the actions taken, and recommendations for improvement.
Incident Response Simulation: In groups of 4, you will simulate an incident response. One group member plays the attacker, one plays the incident commander, one plays the investigator, and one plays the recovery lead. Work through an incident scenario and present your findings.
My Incident Response Plan: Create an incident response plan for a small business. Include detection, containment, eradication, recovery, and review steps. Also include what MySQL queries you would use at each step.
Task: Build a simple dashboard that shows the status of incident response. Include sections for detection, containment, eradication, recovery, and documentation. Use MySQL to power the dashboard.
Assignment: Write a detailed incident response report for a simulated attack. Include a timeline of events, the actions taken, and recommendations for improvement. Use MySQL queries to support your findings.
Challenge: Write a complex incident response plan that includes detection, containment, eradication, recovery, and review. Use MySQL queries for each step. Include a documentation template and a review checklist.
Fill-in-the-Blank Answers: 1. Incident, 2. detection, 3. Containment, 4. Eradication, 5. Recovery, 6. Documentation, 7. Forensics, 8. Practice, 9. Review, 10. MySQL, 11. incident, 12. Containment, 13. Eradication, 14. Recovery, 15. Review.
True or False: 1T, 2F, 3T, 4F, 5F, 6F, 7T, 8T, 9F, 10T.
Multiple Choice Answers: 1B, 2B, 3B, 4C, 5C, 6B, 7A, 8B, 9B, 10B, 11B, 12A, 13B, 14A, 15B.
In Module Eight, we will learn about Security Information and Event Management (SIEM) systems. You will learn how SIEM tools collect and analyse security data from across an organisation. You will also learn how MySQL can be used to power SIEM systems.
Before next class: Think about how you would collect and analyse security data from many different sources. We will explore this together in the next module.
π¨ You have completed Module Seven β keep up the great work! π¨
Hello, security detective! You have learned so much about security monitoring, incident response, and using tools like MySQL. Now, in Module Eight, we will learn about threat hunting and advanced detection. Threat hunting means actively looking for hidden threats that automated tools might miss. Let's become super sleuths!
In Module Seven, you learned how to respond to incidents. You followed a plan to detect, contain, eradicate, and recover from attacks. But what if an attack happens slowly and quietly, and no alarm goes off? That's where threat hunting comes in.
Threat hunting is like being a detective who looks for clues even when no one has reported a crime. You use data, patterns, and your own curiosity to find threats that are hiding. This is different from waiting for alerts β you actively search.
In this module, we will learn what threat hunting is, how to do it, and how to use advanced techniques to find even the sneakiest attackers. We will also learn about detection tools and how to stay ahead of the bad guys.
Remember: Great detectives don't wait for clues β they go looking for them.
After this module, you will be able to:
Dara is 10 years old and lives in Enugu. She loves solving puzzles. One day, her school's computers were acting strangely. Some files were missing, but no alarm went off. The IT team was confused.
Dara's older brother, Chidi, is a SOC Analyst. He told her, "Sometimes attacks are quiet. You can't just wait for alerts β you have to go looking."
Chidi started threat hunting. He looked at the logs (records) of all the computers. He noticed that one computer was sending small amounts of data to a strange internet address every night. The amount was so small that no alarm would have gone off. But Chidi knew it was suspicious.
He investigated and found that a student had installed a hidden program that was stealing files. Chidi stopped the program and fixed the problem. Dara was amazed. She said, "So threat hunting is like being a detective who finds clues before a crime is solved!"
Chidi smiled. "Exactly!"
Question for you: What would you look for if you were hunting for a threat?
Definition: Threat hunting is actively searching for hidden threats in a system. It is not waiting for alerts β it is looking for signs of danger.
Why it is important: Many attacks are designed to be quiet and avoid detection. Threat hunting finds them before they cause damage.
Simple explanation: It's like looking for clues even when you don't know a crime has been committed.
Real-life example: A security team searches for unusual data transfers that could be stealing information.
School example: A teacher notices a student acting suspiciously and investigates.
Home example: A parent checks their smart devices to see if any unknown devices are connected.
Nigerian example: A bank looks for unusual transaction patterns that could indicate fraud.
Threat Hunting = Active Search - Not waiting for alerts - Looking for hidden clues - Investigating suspicious patterns
Mini summary: Threat hunting is actively searching for hidden dangers.
Definition: Automated detection uses machines to find threats. Threat hunting uses humans to find threats that machines might miss.
Why it is important: Machines are fast, but humans are creative. Together, they are a powerful team.
Simple explanation: It's like having a robot that finds obvious things, but you also have a detective who finds hidden things.
Real-life example: An antivirus program detects known viruses, but a threat hunter finds a new, unknown virus.
School example: A security camera records everything, but a person watches the footage to find suspicious behaviour.
Home example: A smoke alarm detects fire, but a person checks the house for hidden fire risks.
Nigerian example: A bank's fraud detection system flags obvious fraud, but analysts hunt for subtle fraud patterns.
Automated Detection: - Fast - Detects known threats - Generates alerts Threat Hunting: - Human-led - Finds unknown threats - Uses creativity
Mini summary: Threat hunting finds what automated detection might miss.
Definition: The threat hunting process is a step-by-step guide to finding hidden threats. It helps you stay organised.
Why it is important: Following a process ensures you don't miss anything.
Simple explanation: It's like a recipe for finding threats.
Real-life example: A team follows a process to investigate a suspicious network connection.
School example: A teacher follows a process to investigate a student's strange behaviour.
Home example: A parent follows a process to check if a device is compromised.
Nigerian example: A bank follows a process to investigate unusual transactions.
Threat Hunting Process: 1. Hypothesis β create a theory 2. Investigation β gather data 3. Analysis β look for patterns 4. Response β take action 5. Review β learn from it
Mini summary: The threat hunting process helps you find threats methodically.
Definition: A hypothesis is an educated guess about what might be happening. It is a starting point for your hunt.
Why it is important: A good hypothesis focuses your search and saves time.
Simple explanation: It's like guessing what might be wrong with a puzzle before you start solving it.
Real-life example: "I think someone is trying to guess passwords because there are many failed logins."
School example: "I think a student is accessing files they shouldn't."
Home example: "I think someone is using my Wi-Fi without permission."
Nigerian example: "I think there is fraud happening in our bank because of a pattern I noticed."
Hypothesis Examples: - "Brute force attack is happening." - "Insider threat is stealing data." - "Malware is communicating with a command centre."
Mini summary: A hypothesis is a starting guess for your investigation.
Definition: Investigation means gathering data to test your hypothesis. You look at logs, network traffic, and system events.
Why it is important: You need evidence to prove or disprove your theory.
Simple explanation: It's like collecting clues to solve a mystery.
Real-life example: A security analyst collects logs from all servers to find a pattern.
School example: A teacher checks computer logs to see who accessed a file.
Home example: A parent checks their Wi-Fi router logs to see who is connected.
Nigerian example: A bank analyst collects transaction logs to find fraud.
Investigation Tools: - Logs - Network traffic analysis - System event monitoring - Threat intelligence feeds
Mini summary: Investigation is gathering evidence.
Definition: Analysis means examining the data you collected to find patterns or anomalies (things that are unusual).
Why it is important: Analysis turns raw data into useful information.
Simple explanation: It's like looking at a puzzle and finding how the pieces fit together.
Real-life example: An analyst finds that many failed logins come from the same IP address.
School example: A teacher notices that a student logs in at unusual times.
Home example: A parent notices a device connected to Wi-Fi that they don't recognise.
Nigerian example: An analyst finds that many transactions are coming from the same location.
Analysis Techniques: - Look for patterns - Identify anomalies - Compare to baselines - Correlate events
Mini summary: Analysis finds patterns and anomalies in data.
Definition: Response is the action you take based on your findings. This could be blocking an IP address, disabling a user account, or patching a vulnerability.
Why it is important: You need to act quickly to stop the threat.
Simple explanation: It's like catching the thief and locking them up.
Real-life example: A security team blocks a suspicious IP address.
School example: A teacher disables a student's account.
Home example: A parent changes the Wi-Fi password.
Nigerian example: A bank blocks a customer's account to stop fraud.
Response Actions: - Block IP addresses - Disable accounts - Remove malware - Patch vulnerabilities
Mini summary: Response is taking action to stop the threat.
Definition: Review means analysing what you did and how you can improve for next time.
Why it is important: Learning from each hunt makes you a better hunter.
Simple explanation: It's like practising a sport and getting better each time.
Real-life example: A team reviews their hunt and improves their process.
School example: A teacher reflects on how to better monitor students.
Home example: A parent updates their security settings.
Nigerian example: A bank improves its fraud detection system.
Review Questions: - What went well? - What could be improved? - Did we miss anything? - What did we learn?
Mini summary: Review helps you improve your hunting skills.
Definition: Advanced detection tools are software that help analysts find threats. They include SIEM, EDR (Endpoint Detection and Response), and network monitoring tools.
Why it is important: Tools help you analyse large amounts of data quickly.
Simple explanation: It's like having a magnifying glass, a microscope, and a flashlight all in one.
Real-life example: A SIEM tool collects and analyses logs from all systems.
School example: A school uses software to monitor computer usage.
Home example: A family uses a home security app.
Nigerian example: A bank uses fraud detection software.
Advanced Tools: - SIEM (Security Information and Event Management) - EDR (Endpoint Detection and Response) - Network Traffic Analysis - Threat Intelligence Platforms
Mini summary: Advanced tools help analysts find threats.
Definition: Data is the foundation of threat hunting. You need good data to find good clues.
Why it is important: Without data, you are guessing. With data, you are investigating.
Simple explanation: It's like trying to find a treasure without a map β you need data to guide you.
Real-life example: An analyst uses logs to trace an attacker's steps.
School example: A teacher uses attendance records to track a student.
Home example: A parent uses Wi-Fi logs to see who is online.
Nigerian example: A bank uses transaction records to track fraud.
Data Sources for Hunting: - Login logs - Network traffic - System events - File access logs - Application logs
Mini summary: Data is the key to successful threat hunting.
Definition: To find threats, you need to think like a hacker. You need to anticipate their moves.
Why it is important: If you know how hackers think, you can find them faster.
Simple explanation: It's like playing chess β you need to think about what your opponent might do.
Real-life example: An analyst imagines how a hacker might try to break into the system.
School example: A teacher thinks about how a student might try to cheat.
Home example: A parent thinks about how a stranger might try to access their Wi-Fi.
Nigerian example: A bank analyst thinks about how fraudsters might try to steal money.
Hacker Thinking: - What would I target? - How would I get in? - How would I hide? - How would I avoid detection?
Mini summary: Thinking like a hacker helps you find them.
Definition: A threat hunting plan is a document that outlines your hunting strategy, schedule, and goals.
Why it is important: A plan keeps you focused and organised.
Simple explanation: It's like a map for your hunt.
Real-life example: A company creates a plan to hunt for threats every month.
School example: A school creates a plan to monitor computer usage.
Home example: A family creates a plan to check their devices weekly.
Nigerian example: A bank creates a plan to hunt for fraud daily.
Hunting Plan Components: - Goals (what to look for) - Schedule (when to hunt) - Tools (what to use) - Team (who is involved) - Review process
Mini summary: A hunting plan keeps you organised and focused.
Definition: Real-world threat hunting is how companies actually hunt for threats.
Why it is important: Seeing real examples helps you understand how it works.
Simple explanation: It's like watching a detective solve a real case.
Real-life example: A company hunts for ransomware before it spreads.
School example: A school hunts for students using unauthorised software.
Home example: A family hunts for unknown devices on their network.
Nigerian example: A bank hunts for fraudsters trying to steal money.
Real-World Hunt: - Identify a suspicious pattern - Investigate using logs - Find the source - Contain the threat - Eradicate and recover - Review and improve
Mini summary: Real-world threat hunting helps protect organisations.
Definition: Practice means doing mock hunts to improve your skills.
Why it is important: Practice makes you faster and better at finding threats.
Simple explanation: It's like a sports team practising before a game.
Real-life example: A security team runs a mock attack to practice hunting.
School example: Students practice finding threats in a lab environment.
Home example: A family practises checking their devices.
Nigerian example: A bank runs drills to practice fraud detection.
Practice Steps: - Set up a mock environment - Create a scenario - Hunt for the threat - Document your findings - Review and improve
Mini summary: Practice makes you a better threat hunter.
Definition: You have learned the skills and process of threat hunting. You can now hunt for threats like a pro.
Why it is important: Your skills can protect organisations and people.
Simple explanation: You are now a digital detective!
Real-life example: You can help a company find hidden threats.
School example: You can help your school find cyber threats.
Home example: You can help your family protect their devices.
Nigerian example: You can help a bank find fraud.
You β Learned threat hunting β Can protect the world! π΅οΈββοΈ
Mini summary: You are now a threat hunter β congratulations!
Step 1: Hypothesis β many failed logins Step 2: Gather data β collect login logs Step 3: Analyse β find pattern Step 4: Anomaly β 50 failed logins from one IP Step 5: Investigate β trace IP, check other logs Step 6: Respond β block IP, change passwords Step 7: Review β learn and improve
Hypothesis
|
V
Investigation
|
V
Analysis
|
V
Response
|
V
Review
| Automated Detection | Threat Hunting |
|---|---|
| Machine-driven | Human-driven |
| Finds known threats | Finds unknown threats |
| Generates alerts | Generates investigations |
| Reactive | Proactive |
| Tool | What It Does |
|---|---|
| SIEM | Collects and analyses logs |
| EDR | Monitors endpoints |
| Network Analyser | Monitors network traffic |
| Threat Intelligence | Provides information on threats |
2000s Basic log analysis
|
2010s Automated detection systems
|
2015s Threat hunting emerges
|
Today Threat hunting is essential
Congratulations! You have completed Module Eight of your Security Operation Centre Analyst training. You have learned about threat hunting and advanced detection. You now know what threat hunting is, why it is important, and how to do it. You have learned the process: hypothesis, investigation, analysis, response, and review. You also learned about tools and how to think like a hacker. You are now a skilled threat hunter!
Match the term to its description:
| Term | Description |
|---|---|
| Hypothesis | Educated guess |
| Investigation | Gathering data |
| Analysis | Examining data |
| Response | Taking action |
| Review | Improving skills |
Scenario 1: You notice that many failed logins are happening from a single IP address. Create a hypothesis and a plan to investigate.
Scenario 2: You are hunting for insider threats. What data would you collect and what patterns would you look for?
Scenario 3: You find an unusual file on a server. What steps would you take to investigate?
Threat Hunting Exercise: In groups of 4, you will be given a sample dataset (logs). Work together to create a hypothesis, investigate the data, analyse it, and develop a response plan. Present your findings to the class.
My Threat Hunt: Create a threat hunting plan for a small business. Include a hypothesis, data sources, analysis methods, and a response plan. Write a report on your findings.
Task: Build a simple dashboard that displays threat hunting data. Include sections for hypotheses, investigations, findings, and responses. Present your dashboard to the class.
Assignment: Find a real-world dataset of security logs (or use sample data). Conduct a threat hunt and document your process. Write a report on your hypothesis, investigation, analysis, response, and review.
Challenge: Write a complex threat hunting plan that includes multiple hypotheses, data sources, analysis techniques, and response actions. Include a review process and a plan for continuous improvement.
Fill-in-the-Blank Answers: 1. Threat hunting, 2. automated, 3. hypothesis, 4. anomaly, 5. Data, 6. Investigation, 7. Analysis, 8. Response, 9. Review, 10. Threat hunting, 11. Thinking, 12. hunting, 13. Practice, 14. threat, 15. Data.
True or False: 1F, 2T, 3F, 4T, 5F, 6T, 7T, 8F, 9T, 10T.
Multiple Choice Answers: 1B, 2B, 3B, 4B, 5A, 6B, 7B, 8A, 9B, 10A, 11B, 12B, 13A, 14B, 15A.
In the next module, we will learn about advanced incident response. You will learn how to handle complex incidents, how to use advanced tools, and how to lead a response team. We will also look at real-world incidents and how they were handled.
Before next class: Review the incident response steps. Think about how threat hunting fits into incident response.
π‘οΈ You have completed Module Eight β keep up the great work! π‘οΈ
Hello, security responder! You have learned how to hunt for threats, use tools like MySQL, and even how to think like a hacker. Now, in Module Nine, we will learn about incident response β what to do when a threat becomes a real attack. Incident response is like being a firefighter: you need to act fast, stay calm, and follow a plan. Let's learn how to respond to cyber emergencies!
In Module Eight, you learned about threat hunting and advanced detection. You learned how to find hidden threats before they cause damage. But what happens when a threat actually breaks through? That's when incident response begins.
Incident response is the process of handling a security breach. It includes detecting the attack, containing it, eradicating the cause, and recovering from it. It also includes documenting everything and learning from the experience.
In this module, we will learn the step-by-step process of incident response. We will also learn about the roles of different team members, the tools they use, and how to communicate during a crisis. By the end, you will be ready to help your team respond to any cyber emergency.
Remember: Stay calm, follow the plan, and work as a team.
After this module, you will be able to:
Chidi is 10 years old and lives in Lagos. His mother works at a hospital. One day, the hospital's computers were attacked by ransomware. All the patient records were locked. The hospital staff were panicking.
Chidi's mother called the incident response team. The team leader, Mr. Ade, gave clear instructions: "Stay calm. Follow the plan."
The team first detected the attack β they found that the ransomware came from an email attachment. Then they contained it β they disconnected the infected computers from the network. They eradicated the ransomware by removing it from all systems. Finally, they recovered the data from backups and got the hospital running again.
Chidi watched the whole process. He was amazed at how organised the team was. He asked Mr. Ade, "How did you know what to do?" Mr. Ade said, "We have a plan. We call it incident response. We practise it regularly, so we're ready for anything."
Chidi decided that he wanted to be part of an incident response team when he grows up.
Question for you: Have you ever had to respond to an emergency? What did you do?
Definition: Incident response is the process of handling a security breach. It includes detecting, containing, eradicating, recovering, and learning from the incident.
Why it is important: A fast and effective response can limit damage, save money, and protect people.
Simple explanation: It's like a fire drill β you have a plan to follow when there's a fire.
Real-life example: A company discovers a hack and follows a plan to stop it.
School example: A school's computer system is attacked and the IT team follows an incident response plan.
Home example: A family member's account is hacked and they change passwords and report it.
Nigerian example: A bank is attacked and the security team responds to protect customer money.
Incident Response Steps: 1. Detection 2. Containment 3. Eradication 4. Recovery 5. Lessons Learned
Mini summary: Incident response is a plan to handle security breaches.
Definition: An incident response plan is a document that tells you what to do during a security breach. It's like a step-by-step guide.
Why it is important: Having a plan means you don't panic β you know what to do.
Simple explanation: It's like a recipe for handling emergencies.
Real-life example: A company has a plan that includes who to call, what to do, and how to recover.
School example: A school has a plan for cyber attacks.
Home example: A family has a plan for if a device is hacked.
Nigerian example: A bank has a detailed incident response plan.
Incident Response Plan Contents: - Roles and responsibilities - Communication plan - Steps to contain and recover - List of tools - Review process
Mini summary: An incident response plan is a guide for handling breaches.
Definition: Detection is the first step β you need to know that something is wrong. This can come from alerts, logs, or even a user report.
Why it is important: The earlier you detect an incident, the less damage it can cause.
Simple explanation: It's like noticing that your door is open when you left it closed.
Real-life example: An alert from a SIEM system shows multiple failed logins.
School example: A teacher notices that a student is accessing files they shouldn't.
Home example: A parent notices an unknown device on their Wi-Fi.
Nigerian example: A bank's fraud detection system flags a suspicious transaction.
Detection Sources: - Alerts from security tools - Logs - User reports - Threat intelligence
Mini summary: Detection is finding out that something is wrong.
Definition: Containment means stopping the attack from spreading. You isolate the affected systems to prevent further damage.
Why it is important: Containment limits the damage and stops the attacker from moving further.
Simple explanation: It's like closing a door to stop a fire from spreading.
Real-life example: A company disconnects an infected server from the network.
School example: A school disconnects a compromised computer from the school network.
Home example: A family disconnects an infected device from Wi-Fi.
Nigerian example: A bank disables an account that is being attacked.
Containment Actions: - Disconnect infected systems - Block suspicious IPs - Disable compromised accounts - Change passwords
Mini summary: Containment stops the attack from spreading.
Definition: Eradication means removing the cause of the attack β like deleting malware or closing vulnerabilities.
Why it is important: If you don't remove the cause, the attack will happen again.
Simple explanation: It's like removing a fire's fuel so it can't start again.
Real-life example: A company removes a virus from all infected computers.
School example: A school removes a virus from a computer lab.
Home example: A family removes malware from a device.
Nigerian example: A bank removes a Trojan from its system.
Eradication Steps: - Delete malware - Patch vulnerabilities - Close backdoors - Reset passwords
Mini summary: Eradication removes the cause of the attack.
Definition: Recovery means restoring systems to normal operation. You bring back data from backups and get things running again.
Why it is important: Recovery gets your business back to work.
Simple explanation: It's like rebuilding a house after a fire.
Real-life example: A company restores data from backups.
School example: A school restores student records from a backup.
Home example: A family restores files from a backup.
Nigerian example: A bank restores customer data from backups.
Recovery Steps: - Restore from backups - Test systems - Monitor for recurrence - Communicate with stakeholders
Mini summary: Recovery restores systems to normal.
Definition: Lessons learned means analysing the incident to understand what happened and how to prevent it in the future.
Why it is important: Learning from mistakes makes your security stronger.
Simple explanation: It's like reviewing a test to see what you got wrong so you can do better next time.
Real-life example: A company writes a report on the incident and implements new security measures.
School example: A school updates its security policies after an attack.
Home example: A family uses stronger passwords.
Nigerian example: A bank improves its fraud detection systems.
Lessons Learned Steps: - Analyse the incident - Identify gaps - Implement improvements - Train staff
Mini summary: Lessons learned help you improve for next time.
Definition: An incident response team has different roles: Incident Commander, Lead Investigator, Communications Lead, and Recovery Lead.
Why it is important: Everyone knows what they need to do, which makes the response faster and more efficient.
Simple explanation: It's like a football team β each player has a different position.
Real-life example: A company has a designated Incident Commander who leads the response.
School example: A school has a team of teachers and IT staff to respond to incidents.
Home example: A family has a plan for who does what during a crisis.
Nigerian example: A bank has a dedicated incident response team.
Incident Response Team Roles: - Incident Commander: leads the response - Lead Investigator: gathers evidence - Communications Lead: handles communications - Recovery Lead: restores systems
Mini summary: Each team member has a specific role.
Definition: Tools are software and hardware that help the team detect, contain, and recover from incidents.
Why it is important: Tools help you work faster and more effectively.
Simple explanation: It's like using a fire extinguisher to put out a fire.
Real-life example: A SIEM tool is used to collect and analyse logs.
School example: A school uses antivirus software to detect malware.
Home example: A family uses a security app to monitor devices.
Nigerian example: A bank uses fraud detection software.
Incident Response Tools: - SIEM: collects logs - EDR: monitors endpoints - Forensic tools: gather evidence - Backup and recovery tools
Mini summary: Tools help the team respond faster.
Definition: Communication means sharing information with stakeholders β like employees, customers, and regulators β during and after an incident.
Why it is important: Good communication builds trust and helps people understand what's happening.
Simple explanation: It's like telling people what's going on during a fire drill.
Real-life example: A company notifies customers about a data breach.
School example: A school informs parents about a cyber incident.
Home example: A parent tells the family about a security issue.
Nigerian example: A bank informs customers about a fraud attempt.
Communication Steps: - Identify stakeholders - Prepare messages - Choose channels - Provide updates - Be transparent
Mini summary: Good communication is key during an incident.
Definition: Ransomware is a type of malware that locks your files and demands payment. Handling it requires a specific response.
Why it is important: Ransomware attacks are very common and can cause huge damage.
Simple explanation: It's like someone locking your room and asking for money to unlock it.
Real-life example: A hospital's patient records are locked by ransomware.
School example: A school's exam papers are locked by ransomware.
Home example: A family's photos are locked by ransomware.
Nigerian example: A bank's transaction data is locked by ransomware.
Ransomware Response: 1. Detect the attack 2. Isolate infected systems 3. Do not pay the ransom 4. Remove the malware 5. Restore from backups 6. Review and improve
Mini summary: Ransomware attacks require a specific response.
Definition: A data breach is when sensitive information is accessed or stolen. Handling it requires a careful response.
Why it is important: Data breaches can lead to identity theft and financial loss.
Simple explanation: It's like someone stealing your diary.
Real-life example: A company's customer information is stolen.
School example: A school's student records are accessed by an unauthorised person.
Home example: A family member's personal information is exposed.
Nigerian example: A bank's customer data is breached.
Data Breach Response: 1. Detect the breach 2. Contain the breach 3. Investigate the extent 4. Notify affected parties 5. Improve security
Mini summary: Data breaches require a careful response.
Definition: Forensics is the process of collecting and analysing evidence from a security incident for legal or investigative purposes.
Why it is important: Evidence can be used to catch attackers and in court.
Simple explanation: It's like collecting fingerprints at a crime scene.
Real-life example: A company preserves logs to help law enforcement.
School example: A school preserves logs to find who hacked the system.
Home example: A family preserves logs to show what happened.
Nigerian example: A bank preserves transaction logs for evidence.
Forensics Steps: - Preserve evidence - Analyse logs - Document findings - Hand over to authorities
Mini summary: Forensics helps collect evidence.
Definition: Practice means running through an incident response exercise with a team to prepare for a real incident.
Why it is important: Practice helps you be ready for a real incident.
Simple explanation: It's like a fire drill β you practice so you're ready for a real fire.
Real-life example: A company runs a simulated attack to test their response.
School example: A school practices responding to a cyber attack.
Home example: A family practices what to do if a device is hacked.
Nigerian example: A bank runs a simulation of a cyber attack.
Practice Scenario: - Simulate an attack - Follow the incident response plan - Use tools to investigate - Contain and recover - Review the exercise
Mini summary: Practice ensures you're ready for a real incident.
Definition: An incident responder is someone who can handle security breaches effectively. You have become one!
Why it is important: Your skills can help protect organisations from cyber attacks.
Simple explanation: You are now a digital firefighter.
Real-life example: You can help a company respond to a breach.
School example: You can help your school respond to an attack.
Home example: You can help your family respond to a cyber incident.
Nigerian example: You can help a bank respond to a fraud attempt.
You β Learned incident response β Can protect systems! π¨
Mini summary: You are now an incident responder β congratulations!
Step 1: Detect β alert triggered Step 2: Contain β disconnect infected systems Step 3: Eradicate β remove malware Step 4: Recover β restore from backups Step 5: Learn β write a report and improve
Detection
|
V
Containment
|
V
Eradication
|
V
Recovery
|
V
Lessons Learned
| Step | What It Does | Example |
|---|---|---|
| Detection | Find the problem | Alert from SIEM |
| Containment | Stop the spread | Disconnect infected system |
| Eradication | Remove the cause | Delete malware |
| Recovery | Restore systems | Restore from backups |
| Lessons Learned | Improve for next time | Update security policies |
| Role | Responsibility |
|---|---|
| Incident Commander | Leads the response |
| Lead Investigator | Gathers evidence |
| Communications Lead | Handles communications |
| Recovery Lead | Restores systems |
0 min Detection
|
10 min Containment
|
30 min Eradication
|
60 min Recovery
|
90 min Lessons Learned
Congratulations! You have completed Module Nine of your Security Operation Centre Analyst training. You have learned about incident response β the process of handling security breaches. You now know the steps: detection, containment, eradication, recovery, and lessons learned. You have learned about the roles of the incident response team, the tools they use, and how to communicate during a crisis. You are now a skilled incident responder!
Match the term to its description:
| Term | Description |
|---|---|
| Detection | Finding something wrong |
| Containment | Stopping the spread |
| Eradication | Removing the cause |
| Recovery | Restoring systems |
| Lessons Learned | Improving for next time |
Scenario 1: You are a SOC Analyst. You detect multiple failed logins from an unknown IP address. What steps do you take?
Scenario 2: A ransomware attack has occurred at a hospital. You need to respond quickly. Write a plan using the incident response steps.
Scenario 3: After an incident, you need to document what happened. Write a summary of the incident, the actions taken, and recommendations for improvement.
Incident Response Simulation: In groups of 4, you will simulate an incident response. One group member plays the attacker, one plays the Incident Commander, one plays the Lead Investigator, and one plays the Recovery Lead. Work through an incident scenario and present your findings.
My Incident Response Plan: Create an incident response plan for a small business. Include detection, containment, eradication, recovery, and lessons learned steps. Also include what tools you would use at each step.
Task: Build a simple dashboard that shows the status of incident response. Include sections for detection, containment, eradication, recovery, and lessons learned. Use MySQL to power the dashboard.
Assignment: Write a detailed incident response report for a simulated attack. Include a timeline of events, the actions taken, and recommendations for improvement. Use MySQL queries to support your findings.
Challenge: Write a complex incident response plan that includes detection, containment, eradication, recovery, and lessons learned. Include a documentation template and a review checklist.
Fill-in-the-Blank Answers: 1. Incident response, 2. detection, 3. Containment, 4. Eradication, 5. Recovery, 6. Lessons learned, 7. Incident Commander, 8. Forensics, 9. communication, 10. Ransomware, 11. Data breach, 12. Containment, 13. Eradication, 14. Recovery, 15. incident.
True or False: 1T, 2F, 3T, 4F, 5F, 6F, 7T, 8T, 9F, 10T.
Multiple Choice Answers: 1B, 2B, 3B, 4C, 5C, 6B, 7B, 8B, 9B, 10B, 11A, 12B, 13A, 14B, 15B.
In Module Ten, we will explore advanced security tools and technologies. You will learn about SIEM, SOAR, and other tools that SOC Analysts use every day. We will also look at the future of cybersecurity and how you can stay ahead of the curve.
Before next class: Review the tools you have learned so far. Think about what other tools might be useful for a SOC Analyst.
π You have completed Module Nine β keep up the great work! π
Hello, security champion! You have completed nine modules of your SOC Analyst training. You have learned about threats, detection, hunting, and incident response. Now, in Module Ten, we will look at advanced security tools and the future of the Security Operation Centre. We will explore how technology is changing and how you can stay ahead. Let's finish strong!
In Module Nine, you learned about incident response and how to handle security breaches. You learned about the steps, the team, and the tools. Now, in Module Ten, we will go further. We will explore advanced tools that SOC Analysts use to protect organisations. We will also look at the future of cybersecurity β how AI, automation, and new technologies are changing the game.
This module is a celebration of everything you have learned. It will give you a glimpse into the future and prepare you for the next steps in your career. By the end, you will understand how SOCs are evolving and how you can be a part of that evolution.
Remember: The future belongs to those who prepare for it today.
After this module, you will be able to:
Tunde is 10 years old and lives in Ibadan. He loves technology and dreams of becoming a cybersecurity expert. One day, he visited his uncle, who works as a SOC Analyst at a large bank. His uncle showed him the security control room β a room filled with screens, lights, and data.
Tunde was amazed. He saw how the team used advanced tools to monitor the bank's network. They had a SIEM system that collected logs from everywhere. They also had an EDR system that watched every computer for threats. But the most exciting thing was the AI β it could detect threats faster than any human.
His uncle said, "This is the future, Tunde. AI and automation are changing everything. But the most important tool is still the human mind. We use these tools to help us make better decisions."
Tunde was inspired. He realised that technology is just a tool β the real power comes from the people who use it. He decided that he would continue learning and become a leader in cybersecurity.
Question for you: What technology excites you the most about the future?
Definition: Advanced security tools are software and systems that help SOC Analysts detect, investigate, and respond to threats more effectively.
Why it is important: Tools make analysts faster, more accurate, and more efficient.
Simple explanation: It's like having a superpower β tools give you abilities you wouldn't have on your own.
Real-life example: A SIEM system that collects and analyses logs from thousands of devices.
School example: A school uses monitoring software to track computer usage.
Home example: A family uses a smart security system to monitor their home.
Nigerian example: A bank uses advanced fraud detection software.
Advanced Tools: - SIEM (Security Information and Event Management) - EDR (Endpoint Detection and Response) - SOAR (Security Orchestration, Automation, and Response) - AI (Artificial Intelligence) - Threat Intelligence Platforms
Mini summary: Advanced tools help analysts work better and faster.
Definition: SIEM stands for Security Information and Event Management. It collects and analyses security data from across the organisation.
Why it is important: SIEM gives analysts a central view of security events.
Simple explanation: It's like the brain of the SOC β it gathers and processes information.
Real-life example: A company uses SIEM to monitor all login attempts.
School example: A school uses SIEM to track who is accessing the network.
Home example: A family uses a SIEM-like tool to monitor smart devices.
Nigerian example: A bank uses SIEM to monitor transactions.
SIEM Functions: - Collects logs - Analyses data - Generates alerts - Creates reports
Mini summary: SIEM is the central hub for security data.
Definition: EDR stands for Endpoint Detection and Response. It monitors individual devices like computers, phones, and servers for threats.
Why it is important: Endpoints are often the target of attacks. EDR helps protect them.
Simple explanation: It's like having a security guard on every device.
Real-life example: An EDR system detects malware on a laptop.
School example: A school uses EDR to protect student laptops.
Home example: A family uses EDR to protect their phones and computers.
Nigerian example: A bank uses EDR to monitor employee devices.
EDR Functions: - Monitors endpoints - Detects threats - Responds to incidents - Provides visibility
Mini summary: EDR protects individual devices.
Definition: SOAR stands for Security Orchestration, Automation, and Response. It helps automate repetitive tasks and responses.
Why it is important: Automation saves time and reduces human error.
Simple explanation: It's like having a robot assistant that does boring tasks for you.
Real-life example: A SOAR system automatically blocks an IP address after a certain number of failed logins.
School example: A school uses SOAR to automatically block suspicious websites.
Home example: A family uses automation to turn off devices when not in use.
Nigerian example: A bank uses SOAR to automatically respond to fraud alerts.
SOAR Functions: - Automates tasks - Orchestrates workflows - Responds to incidents - Reduces manual work
Mini summary: SOAR automates security tasks.
Definition: AI (Artificial Intelligence) is technology that can learn and make decisions. In cybersecurity, AI helps detect threats faster and more accurately.
Why it is important: AI can process huge amounts of data and find patterns that humans might miss.
Simple explanation: It's like having a super-smart robot that helps you find clues.
Real-life example: AI detects a new type of malware before it spreads.
School example: AI helps a school monitor network traffic.
Home example: AI helps a smart security camera recognise faces.
Nigerian example: A bank uses AI to detect fraudulent transactions.
AI in Security: - Detects anomalies - Analyses patterns - Predicts threats - Automates responses
Mini summary: AI helps find and stop threats faster.
Definition: A Threat Intelligence Platform (TIP) collects and analyses information about threats from many sources.
Why it is important: TIPs help analysts understand the threat landscape and prepare for attacks.
Simple explanation: It's like having a news feed that tells you about all the latest dangers.
Real-life example: A TIP alerts analysts about a new ransomware campaign.
School example: A school uses a TIP to stay informed about threats to students.
Home example: A family uses a TIP to stay safe online.
Nigerian example: A bank uses a TIP to track fraud trends.
TIP Functions: - Collects threat data - Shares intelligence - Helps prevent attacks - Informs decision-making
Mini summary: TIPs provide information about threats.
Definition: Automation is using technology to perform tasks without human intervention. In the SOC, automation helps with repetitive tasks.
Why it is important: Automation frees up analysts to focus on more complex problems.
Simple explanation: It's like having a robot helper that does the boring jobs.
Real-life example: An automated system blocks a suspicious IP address.
School example: A school's system automatically updates antivirus software.
Home example: A family uses automation to turn off lights and lock doors.
Nigerian example: A bank uses automation to process fraud alerts.
Automation Benefits: - Saves time - Reduces errors - Increases efficiency - Allows focus on critical tasks
Mini summary: Automation makes the SOC more efficient.
Definition: Machine Learning is a type of AI that allows systems to learn from data without being explicitly programmed.
Why it is important: Machine Learning helps systems adapt to new threats and patterns.
Simple explanation: It's like teaching a computer to learn from experience.
Real-life example: A system learns what normal network traffic looks like and alerts on anomalies.
School example: A school's system learns patterns of student behaviour and alerts on unusual activity.
Home example: A smart home system learns when you are usually home and adjusts settings.
Nigerian example: A bank's system learns patterns of customer behaviour and flags unusual transactions.
Machine Learning in Security: - Learns from data - Adapts to new threats - Improves over time - Detects unknown threats
Mini summary: Machine Learning helps systems learn and adapt.
Definition: The human element means that people are still the most important part of the SOC. Technology is a tool, but people make the decisions.
Why it is important: Machines can't replace human intuition, creativity, and judgment.
Simple explanation: It's like having a supercar β it's fast, but you still need a driver.
Real-life example: An analyst investigates an alert and makes a critical decision.
School example: A teacher uses technology to teach, but still makes decisions about students.
Home example: A parent uses a smart home system but still makes decisions about safety.
Nigerian example: A bank analyst uses fraud detection software but makes the final decision.
Human Element: - Intuition - Creativity - Judgment - Decision-making
Mini summary: People are the most important part of the SOC.
Definition: Continuous learning means always learning new things. In cybersecurity, things change fast, so you need to keep learning.
Why it is important: Staying updated helps you stay ahead of threats.
Simple explanation: It's like learning to ride a new bike β you need to keep practising.
Real-life example: An analyst takes a course on a new security tool.
School example: A teacher attends a workshop on new technology.
Home example: A parent learns about new online safety tools.
Nigerian example: A bank analyst attends a training session on fraud trends.
Ways to Learn: - Online courses - Certifications - Conferences - Reading blogs and books - Practising hands-on
Mini summary: Always keep learning to stay ahead.
Definition: A career path is the journey you take in your professional life. For a SOC Analyst, it starts with entry-level roles and can lead to senior positions.
Why it is important: Knowing the career path helps you plan your future.
Simple explanation: It's like a road map for your career.
Real-life example: An entry-level SOC Analyst becomes a senior analyst, then a manager.
School example: A student starts with basic computer skills and progresses to advanced cybersecurity.
Home example: A person starts with a hobby and turns it into a career.
Nigerian example: A graduate starts as a junior SOC Analyst and works their way up.
Career Path: 1. Junior SOC Analyst 2. SOC Analyst 3. Senior SOC Analyst 4. SOC Manager 5. Security Director
Mini summary: A clear career path helps you plan your future.
Definition: A SOC toolkit is the collection of tools and skills you need as an analyst.
Why it is important: Having the right tools makes you more effective.
Simple explanation: It's like a carpenter's toolbox β you need the right tools for the job.
Real-life example: An analyst uses SIEM, EDR, and threat intelligence platforms.
School example: A student uses learning tools like textbooks and software.
Home example: A family uses security tools like locks and alarms.
Nigerian example: A bank uses fraud detection tools and analytics.
SOC Toolkit: - Technical skills - Communication skills - Problem-solving skills - Security tools - Certifications
Mini summary: Build your toolkit to be an effective analyst.
Definition: Certifications are official credentials that show you have certain skills. They are valuable for career advancement.
Why it is important: Certifications help you stand out and prove your knowledge.
Simple explanation: It's like a medal that shows you are an expert.
Real-life example: An analyst earns a Certified Ethical Hacker (CEH) certification.
School example: A student earns a certificate in cybersecurity.
Home example: A person earns a certification in a skill they learned.
Nigerian example: A bank analyst earns a certification in fraud prevention.
Popular Certifications: - CompTIA Security+ - Certified Ethical Hacker (CEH) - CISSP - GIAC - SOC Analyst certifications
Mini summary: Certifications show your expertise.
Definition: The future of cybersecurity is constantly evolving. New threats and technologies will continue to emerge.
Why it is important: Understanding the future helps you prepare.
Simple explanation: It's like looking ahead on a road trip β you need to know where you're going.
Real-life example: More organisations will use AI and automation.
School example: Schools will use more advanced security tools.
Home example: Families will use more smart security devices.
Nigerian example: Nigerian businesses will adopt more advanced security measures.
Future Trends: - AI and Machine Learning - Automation - Cloud Security - IoT Security - Increased cyber threats
Mini summary: The future of cybersecurity is exciting and evolving.
Definition: You have completed your training and are ready to start your career as a SOC Analyst.
Why it is important: You have the knowledge and skills to protect organisations.
Simple explanation: You are now a security champion!
Real-life example: You can apply for entry-level SOC Analyst roles.
School example: You can help your school improve its security.
Home example: You can help your family stay safe online.
Nigerian example: You can contribute to Nigeria's cybersecurity industry.
You β Learned everything β Ready to protect the world! π
Mini summary: You are ready to start your career as a SOC Analyst!
Step 1: Learn the basics Step 2: Get certified Step 3: Gain experience Step 4: Build your toolkit Step 5: Keep learning Step 6: Network with others Step 7: Advance your career
SIEM (Central Data)
|
V
EDR (Endpoint Monitoring)
|
V
SOAR (Automation)
|
V
Threat Intelligence (Information)
|
V
AI (Advanced Analysis)
| Tool | What It Does | Benefit |
|---|---|---|
| SIEM | Collects and analyses logs | Centralised view |
| EDR | Monitors endpoints | Device protection |
| SOAR | Automates tasks | Saves time |
| AI | Analyses patterns | Faster detection |
| Threat Intel | Provides information | Informed decisions |
| Level | Title | Responsibilities |
|---|---|---|
| Entry | Junior SOC Analyst | Monitor alerts, basic analysis |
| Mid | SOC Analyst | Investigate incidents, use tools |
| Senior | Senior SOC Analyst | Lead investigations, mentor others |
| Leadership | SOC Manager | Manage team, strategy |
| Executive | Security Director | Overall security strategy |
Module 1: Introduction to SOC
|
Module 2: Cybersecurity Basics
|
Module 3: Networking
|
Module 4: Operating Systems
|
Module 5: SQL and Databases
|
Module 6: MySQL for Security
|
Module 7: Threat Hunting
|
Module 8: Incident Response
|
Module 9: Advanced Detection
|
Module 10: Future of SOC (YOU ARE HERE!)
|
YOU ARE READY! π
Congratulations! You have completed Module Ten β the final module of your Security Operation Centre Analyst training. You have learned about advanced security tools like SIEM, EDR, SOAR, AI, and Threat Intelligence Platforms. You have explored the future of cybersecurity and how AI and automation are changing the field. You have also learned about career paths, certifications, and the importance of continuous learning. You are now ready to start your career as a SOC Analyst!
Match the tool to its description:
| Tool | Description |
|---|---|
| SIEM | Collects and analyses security data |
| EDR | Monitors individual devices |
| SOAR | Automates security tasks |
| AI | Technology that learns and makes decisions |
| Threat Intelligence | Provides information about threats |
Scenario 1: You are a SOC Analyst. A new threat has been detected by your Threat Intelligence Platform. You need to respond. What steps do you take?
Scenario 2: Your organisation is considering implementing AI in the SOC. What are the benefits and risks?
Scenario 3: You are building your career as a SOC Analyst. What certifications and skills should you focus on?
Future of SOC Presentation: In groups of 4, research and present on the future of the Security Operation Centre. Include technologies, challenges, and opportunities. Present your findings to the class.
My Career Plan: Create a career plan for yourself as a SOC Analyst. Include the steps you will take, the certifications you will earn, and your goals. Present your plan to the class.
Task: Build a roadmap for the future of a Security Operation Centre. Include technologies, strategies, and goals. Present your roadmap to the class.
Assignment: Write a report on how AI and automation are changing the SOC. Include examples from real-world organisations and recommendations for implementation.
Challenge: Write a comprehensive career plan for a SOC Analyst. Include education, certifications, experience, and goals. Also include a plan for continuous learning and professional development.
Fill-in-the-Blank Answers: 1. SIEM, 2. EDR, 3. SOAR, 4. AI, 5. Threat, 6. Automation, 7. Certifications, 8. learning, 9. Continuous, 10. People, 11. career, 12. toolkit, 13. Advanced, 14. evolving, 15. career.
True or False: 1T, 2T, 3T, 4F, 5T, 6F, 7F, 8T, 9F, 10T.
Multiple Choice Answers: 1A, 2A, 3A, 4A, 5A, 6A, 7A, 8A, 9A, 10A, 11A, 12A, 13A, 14A, 15A.
Congratulations on completing the Security Operation Centre Analyst Level Three course! You have learned so much β from the basics of cybersecurity to advanced threat hunting and incident response. You are now ready to apply your skills in the real world.
As a next step, consider pursuing certifications like CompTIA Security+, CEH, or CISSP. Look for internships or entry-level roles to gain experience. Continue learning and staying updated on the latest threats and technologies. The world needs more cybersecurity professionals like you!
Thank you for being a part of this course. We wish you all the best in your cybersecurity journey!
π You have completed the Security Operation Centre Analyst Level Three course β congratulations! π