There is no universal list that is valid for all companies.

It must be defined according to:

  • the risk
  • architecture
  • critical assets
  • regulatory obligations
  • attack scenarios
  • storage capacities
  • the objectives of the SOC.

However, certain sources are generally given priority.

Identify

  • authentications
  • chess
  • privilege changes
  • account creation
  • deletions
  • group modifications.

Endpoint

  • process
  • network connections
  • security events
  • system modifications
  • EDR alerts.

Network

  • firewall
  • VPN
  • proxy
  • DNS
  • IDS/IPS
  • network equipment.

Cloud

  • authentications
  • administrative activities
  • resource modifications
  • access to data
  • security events.

Applications

  • authentication
  • administrative actions
  • errors
  • access to data

configuration changes.

Categories: