There is no universal list that is valid for all companies.
It must be defined according to:
- the risk
- architecture
- critical assets
- regulatory obligations
- attack scenarios
- storage capacities
- the objectives of the SOC.
However, certain sources are generally given priority.
Identify
- authentications
- chess
- privilege changes
- account creation
- deletions
- group modifications.
Endpoint
- process
- network connections
- security events
- system modifications
- EDR alerts.
Network
- firewall
- VPN
- proxy
- DNS
- IDS/IPS
- network equipment.
Cloud
- authentications
- administrative activities
- resource modifications
- access to data
- security events.
Applications
- authentication
- administrative actions
- errors
- access to data
configuration changes.