skip to content

Telemetry & Log Sources

Where a SOC's records come from - Sysmon and Windows event channels, auditd, NetFlow, DNS, mail and control-plane trails - and what each can prove. Interviewers open with 'which logs would you check'.

on this pageshow

explore

questions

page 2 of 2

A branch office's endpoint events arrive hours after their host timestamps — what does that break during an intrusion investigation?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Late arrival breaks scheduled detections that scan a rolling window of event time, skews any timeline that mixes fast and slow sources, and makes the live picture of a host stale while you are deciding what to do about it.

open as a page

An audit entry names an assumed-role session, not a person — how do you prove who acted?

level: seniorimportance: should knowfreq 48%

basics

~20 s

Walk the chain backwards. The session identifier in the entry links to the role-assumption call that created it, and that call's own identity is the caller. Repeat for each hop until you reach an identity authenticated by a human login.

open as a page

Mailbox item-access auditing was never enabled — the owner asks whether the intruder read the CFO's mail. What can you honestly say?

level: seniorimportance: should knowfreq 48%

basics

~20 s

That item access is not recorded in this tenant, so there is no evidence either way. An absent record proves nothing when the events were never generated. Report the mailbox as exposed for the window the intruder's session was live.

open as a page

Windows command-line, script-block and module logging are off by default - which do you enable first?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Command-line capture on process creation first: it is the cheapest switch and turns a program name into a statement of what was asked of it. Script-block logging second, on the interpreters that matter. Module logging last, and rarely fleet-wide.

open as a page

An auditor asks you to defend '94% endpoint log coverage' — which denominator and evidence do you present?

level: principalimportance: should knowfreq 40%

basics

~20 s

Name the denominator first — which authoritative asset list the figure is over — and prove the numerator from events indexed in a stated window, not agents enrolled. Present the missing six percent as a named, owned list.

open as a page

Three log sources disagree by minutes about one intrusion - how do you produce an ordering you can defend?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

Measure each source's offset using events that two sources both recorded, convert everything to UTC while keeping the raw fields, order by causality where the offsets overlap, and state the residual uncertainty instead of a false-precise second.

open as a page

Investigators blame a 40-minute gap in a host's forwarded events on the intruder, but your deployment job stopped the agent — how do you settle it?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

A change record is a claim, not evidence. Corroborate it with the agent service's own stop and start records, the same gap on other hosts in that deployment ring, and the host's local channel, which kept recording while shipping stopped.

open as a page

You reset a compromised cloud admin, yet privileged API calls continue — what do you hunt in control-plane audit?

level: seniorimportance: nice to knowfreq 36%

basics

~20 s

Hunt every identity-creating and credential-adding event made inside the compromise window: new access keys, secrets or certificates added to an existing application or service principal, new service accounts, and roles newly trusted by an outside party.

open as a page

In a collaboration-suite audit trail, a departing engineer touched 900 files in their final week, all within their entitlements — what does it support?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

That specific accesses happened, through a specific channel, at specific times — not that anything wrong occurred. Entitled access is normal, so any claim rests on event type, volume, timing and channel measured against that person's own history.

open as a page

Your proxy logs TLS SNI for a CDN hostname sanctioned apps also use — what can that metadata still distinguish?

level: seniorimportance: nice to knowfreq 36%

basics

~20 s

A shared CDN hostname is the same string for sanctioned and hostile traffic, so the name discriminates nothing. What the proxy record still gives you is the client side: which host, which user, and how rare that name is for that population.

open as a page

The subject of an insider case sits inside the SOC's own reporting line. Who approves telemetry access, and how?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Approval must leave the security line entirely — a standing alternate such as internal audit, privacy or the general counsel's office. The subject also administers the tooling, so evidence, retention and the audit trail must move beyond their control before collection starts.

open as a page

A budget holder will fund six more months of security log retention only if you drop something else — how do you make the case?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Stop selling insurance and sell answerability: name the case questions the extra months make answerable and nothing else can. Offer an asymmetric horizon as the trade, and write down in advance what the shortened branch costs.

open as a page

A shared-schema field rename would break forty live detections — how do you ship it?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Publish both names for a fixed, announced window, migrate the consumers you can enumerate, then remove the old name on a stated date. A silent cut breaks content nobody warned; a permanent alias quietly becomes the schema.

open as a page

Your Linux fleet owner refuses a fleet-wide auditd execve rule on CPU and disk grounds - what now?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Split the objection. Execve-only auditing is far cheaper than the broad syscall rule sets people picture, and most of the volume is your own configuration management. Negotiate a measured rule, then get any accepted gap named and owned.

open as a page

showing 31–45 of 45