4. Indicators used by the SOC
First of all, indicators deemed "technical" can be compiled. These indicators are based on a multi-pronged approach:
-
track a number of feared risks as a security incident tracking service provider (PDIS: prestataire de détection d'incidents de sécurité, certified by ANSSI), including :
risks of virus propagation ;
the risk of a privilege elevation attack, enabling an attacker to remove the security features of an information system (e.g. disabling antivirus software);
data exfiltration scenarios ;
usurpation of a user's professional account;
for each of these feared risks, the applicable sources of alerts are listed and grouped into several sets...
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
Indicators used by the SOC