Skip to main content
KRITIS · Finance

SOC redesign at an international group

Rebuilding security monitoring at an international group: data sources consolidated, use cases prioritised, and daily threat hunting established.

Vom Flickenteppich zur belastbaren Erkennung Getrennte Quellen wurden konsolidiert, auf ein Schema gebracht und in priorisierte Use Cases ueberfuehrt. BEFORE SEPARATE SOURCES, NO SHARED PICTURE ONE SCHEME AFTER PRIORITISED USE CASES dailyTHREAT HUNTING FROM THREAT HUNTING, NOT FROM AN ALERT FINANCE · SECURITY MONITORING REBUILT

An international group had security monitoring that collected data but detected little. The rebuild therefore started not with the platform but with the sources and the use cases.

Project frame

Starting position and scope

A rebuild of the detection on the existing platform.

Environment

An international group with a landscape grown over time, several sites and a considerable number of connected systems.

Problem

The existing monitoring collected log data on a large scale but produced few alerts anyone followed up. Analysts worked mostly reactively on messages without context.

Approach

Consolidate the data sources, prioritise and develop use cases, establish threat hunting as a permanent part of the work.

Starting position

Collecting is not detecting

A SIEM that takes in everything produces cost and noise. Without normalisation, events from different sources cannot be correlated sensibly, and without prioritised use cases it is chance that decides what stands out.

So the first task was to order the sources: which are needed, which are missing, and which only produce volume.

Approach

From the sources to the hunt

In that order, because each step is the basis of the next.

1

Consolidate the sources

An inventory of the connected systems, normalisation onto a common schema, enrichment with asset and identity context.

2

Prioritise use cases

Not everything at once. Priority followed the techniques realistic for this environment, and what is detectable at all with the sources available.

3

Develop and measure the detection

Rules versioned, measured against their coverage and tuned. What produced too many false positives was sharpened rather than switched off.

4

Establish threat hunting

A daily hypothesis-driven search whose results flow back into the use cases. That turns detection into a cycle rather than a state.

Result

What changed measurably

The number of alerts went down and the share of those worked on went up. Analysts were no longer mostly clearing warnings but working on hypotheses. And the coverage could be quantified for the first time rather than asserted.

The most important effect was organisational: use case development became a permanent task of its own. Without it, any monitoring falls behind over the years.

What transfers

What you can take from this

Changing SIEM rarely solves the problem it gets blamed for. In most cases the cause lies with the sources and with missing use case work, and both survive a change of platform unchanged.

Anyone who does not measure coverage does not know what they detect. Mapping the rules onto a tactics and techniques model is the simplest way to make that question answerable.

Threat hunting supplies the feedback from which new use cases come.

Next step

A similar project?

Referenzdetails nennen wir nach Freigabe und im persönlichen Gespräch.