LevelBlue Blog
Tag: Soc
LevelBlue SOC Analysts See Sharp Rise in Cyber Threats: Stay Vigilant
December 11, 2024 | Dustin Swening and Kenneth Ng
This holiday season our SOC analysts have observed a sharp uptick in cyber threat activity. Specifically, they’ve seen a rise in attempted ransomware attacks, which started during the American Thanksgiving holiday period (November 25–31, 2024) and are expected to continue throughout the holiday season. We’re sharing details on the threat actors involved, their tactics, as well as… Read more →
Stories from the SOC: Registry Clues to PDF Blues: A Tale of PUA Persistence
November 21, 2024 | Jeff Kieschnick
Executive Summary Establishing persistence on a system allows a threat actor continued access or process execution across system restarts or other changes. For this reason, monitoring for and investigating persistence indicators are key components of any robust cybersecurity platform. Two common persistence techniques are using AutoStart Execution of programs during system boot or logon (T1547) and abusing scheduled task functions … Read more →
Reducing Alert Fatigue by Streamlining SOC Processes
October 7, 2024 | Katrina Thompson
The content of this post is solely the responsibility of the author. LevelBlue does not adopt or endorse any of the views, positions, or information provided by the author in this article. We wanted to know what was going on within our vast networks; modern tools have made it possible for us to know too much. Some data… Read more →
The modern next gen SOC powered by AI
February 21, 2024 | Matt Mui
AI is among the most disruptive technologies of our time. While AI/ML has been around for decades, it has become a hot topic with continued innovations in generative AI (GenAI) from start-up OpenAI to tech giants like Microsoft, Google, and Meta. When large language models (LLMs) combined with big data and behavior analytics, AI/ML can supercharge productivity and… Read more →
Cybersecurity operations in 2024: The SOC of the future
January 17, 2024 | Theresa Lanowitz
This is part two of a three-part series written by LevelBlue evangelist Theresa Lanowitz. It’s intended to be future-looking, provocative, and encourage discussion. The author wants to assure you that no generative AI was used in any part of this blog. Part one: Unusual, thought-provoking predictions for cybersecurity in 2024 Part three: Four cybersecurity trends you should know… Read more →