Telemetry & Log Sources
Where a SOC's records come from - Sysmon and Windows event channels, auditd, NetFlow, DNS, mail and control-plane trails - and what each can prove. Interviewers open with 'which logs would you check'.
on this pageshowhide
explore
- Evidence at the Source21 questions
- Process Execution Records4 questions
- Logon and Token Events5 questions
- Network Metadata Trails4 questions
- Control-Plane Audit Records4 questions
- Mailbox and SaaS Trails4 questions
- Surviving the Trip12 questions
- Coverage and Silent Sources4 questions
- Shared Field Schemas4 questions
- Host-Side Log Window4 questions
- Limits of the Record12 questions
- Timestamps You Cannot Trust4 questions
- Retention Against Dwell4 questions
- Analyst Access to Telemetry4 questions
questions
page 2 of 2A branch office's endpoint events arrive hours after their host timestamps — what does that break during an intrusion investigation?
basics
~20 sLate arrival breaks scheduled detections that scan a rolling window of event time, skews any timeline that mixes fast and slow sources, and makes the live picture of a host stale while you are deciding what to do about it.
An audit entry names an assumed-role session, not a person — how do you prove who acted?
basics
~20 sWalk the chain backwards. The session identifier in the entry links to the role-assumption call that created it, and that call's own identity is the caller. Repeat for each hop until you reach an identity authenticated by a human login.
Mailbox item-access auditing was never enabled — the owner asks whether the intruder read the CFO's mail. What can you honestly say?
basics
~20 sThat item access is not recorded in this tenant, so there is no evidence either way. An absent record proves nothing when the events were never generated. Report the mailbox as exposed for the window the intruder's session was live.
Windows command-line, script-block and module logging are off by default - which do you enable first?
basics
~20 sCommand-line capture on process creation first: it is the cheapest switch and turns a program name into a statement of what was asked of it. Script-block logging second, on the interpreters that matter. Module logging last, and rarely fleet-wide.
An auditor asks you to defend '94% endpoint log coverage' — which denominator and evidence do you present?
basics
~20 sName the denominator first — which authoritative asset list the figure is over — and prove the numerator from events indexed in a stated window, not agents enrolled. Present the missing six percent as a named, owned list.
Three log sources disagree by minutes about one intrusion - how do you produce an ordering you can defend?
basics
~20 sMeasure each source's offset using events that two sources both recorded, convert everything to UTC while keeping the raw fields, order by causality where the offsets overlap, and state the residual uncertainty instead of a false-precise second.
Investigators blame a 40-minute gap in a host's forwarded events on the intruder, but your deployment job stopped the agent — how do you settle it?
basics
~20 sA change record is a claim, not evidence. Corroborate it with the agent service's own stop and start records, the same gap on other hosts in that deployment ring, and the host's local channel, which kept recording while shipping stopped.
You reset a compromised cloud admin, yet privileged API calls continue — what do you hunt in control-plane audit?
basics
~20 sHunt every identity-creating and credential-adding event made inside the compromise window: new access keys, secrets or certificates added to an existing application or service principal, new service accounts, and roles newly trusted by an outside party.
A consented third-party app read mail and an executive asks whether MFA held. How do you answer?
basics
~10 sMFA held, and it is the wrong question. The user authenticated, then granted a third-party app a delegated mail-read scope; the app holds its own token under that grant and never faces a challenge.
In a collaboration-suite audit trail, a departing engineer touched 900 files in their final week, all within their entitlements — what does it support?
basics
~20 sThat specific accesses happened, through a specific channel, at specific times — not that anything wrong occurred. Entitled access is normal, so any claim rests on event type, volume, timing and channel measured against that person's own history.
The subject of an insider case sits inside the SOC's own reporting line. Who approves telemetry access, and how?
basics
~20 sApproval must leave the security line entirely — a standing alternate such as internal audit, privacy or the general counsel's office. The subject also administers the tooling, so evidence, retention and the audit trail must move beyond their control before collection starts.
A budget holder will fund six more months of security log retention only if you drop something else — how do you make the case?
basics
~20 sStop selling insurance and sell answerability: name the case questions the extra months make answerable and nothing else can. Offer an asymmetric horizon as the trade, and write down in advance what the shortened branch costs.
A shared-schema field rename would break forty live detections — how do you ship it?
basics
~20 sPublish both names for a fixed, announced window, migrate the consumers you can enumerate, then remove the old name on a stated date. A silent cut breaks content nobody warned; a permanent alias quietly becomes the schema.
Your Linux fleet owner refuses a fleet-wide auditd execve rule on CPU and disk grounds - what now?
basics
~20 sSplit the objection. Execve-only auditing is far cheaper than the broad syscall rule sets people picture, and most of the volume is your own configuration management. Negotiate a measured rule, then get any accepted gap named and owned.
showing 31–45 of 45