Attackers only need to win once. Defenders win by knowing their estate better than the people attacking it. This module is the blue-team brain.
You can’t detect what you don’t record. The non-negotiables:
Ship logs off-box immediately (attackers delete local ones), sync clocks via NTP so timelines make sense, and retain long enough to investigate last month’s breach this month.
A SIEM aggregates logs and turns them into alerts through correlation rules:
5+ failed logins then 1 success on the same account in 10 min Service account using interactive login Office IP logging in from two countries simultaneously
The enemy is alert fatigue: 500 untriaged alerts = no security. Good detections are behavioral (MITRE ATT&CK techniques like T1110 brute force) rather than signature-only. Every rule needs tuning, an owner, and a documented response.
Hacker crossover: the best pentesters write findings as detection gaps — “this attack chain generated no alert” is executive gold. Try spotting your own patterns: the arcade’s Phish or Fish game is literally detection training.
NIST’s lifecycle — memorize as PICERL:
Classic exam trap: containment before eradication (don’t clean a machine that’s still connected). Real-world trap: skipping lessons learned and getting re-breached identically.
Boring beats clever. The controls that actually stop breaches:
If you remember one line: attackers automate everything common, so uncommon configurations are free defense. Now flip perspectives again with the AD module if you skipped it — blue team needs both sides.