Network Security Channel
2.76K subscribers
5.35K photos
3.42K videos
5.59K files
4.45K links
⭕️Start Channel From 2017⭕️
Security Operation Center (SOC)
Bug Bounty
Vulnerability
Pentest
Hardening
Linux
Reasearch
Security Network
Security Researcher
DevSecOps
Blue Team
Red Team
Download Telegram
استخدام #تهران #SOC

برای چند پروژه مهم SOC در شرکت ترنم، نیروی لایه یک جوان و تازه نفس و پای کار نیاز داریم. سابقه برامون مهم نیست خانم و اقا فرقی نداره حتی دانشجو هم باشی تا جایی که بتونیم با زمان کلاسهات هماهنگ میشیم. کار اموزی هم داریم و فعلا شیفت نداریم . محل استقرار محیط مشتری. حقوق هم تو مصاحبه راجع بهش توافق میکنیم. پس اگر مبانی امنیت رو میشناسی یکمی هم با اسپلانک اشنایی داری منتظر رزومه ات هستیم و جات تو تیم ما خالیه
ارسال رزومه
ahmadi@taranomtech.com
@sadeghahmadi3

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
Please open Telegram to view this post
VIEW IN TELEGRAM
❤‍🔥11🔥1👏1
Network Security Channel
Photo
🚨🔴 DARK WEB ≠ “MYSTERY LAND” — It’s an OSINT surface you can monitor (safely).

Not everything “dark web” is shady hacking content. For defenders, it’s mainly early signals: leaked creds, brand mentions, data dumps, threat actor chatter, and infrastructure breadcrumbs.

This graphic is a quick snapshot of dark web search + breach-intel tooling — useful for CTI, SOC, and incident response workflows:

🧭 Discovery & Search (Onion indexing)

Tools like Ahmia / Torch / Haystak / Tor66 / Onion Engine can help discover onion content and references.

🕵️ Leak & Breach Intelligence

Have I Been Pwned, DeHashed, Telemetry, Library of Leaks → fast checks for exposed accounts/domains and leaked datasets.

📌 CTI Collection

Sources like DeepDark CTI can support threat intel enrichment (always validate + cross-check).

🔗 Directories & Link Hubs

Pages like Onion.live / Tor.link / DarkwebDaily often act as link lists (high churn, high risk — treat as untrusted).

🔐 Crypto Hygiene

PGP tools matter for verification when you’re handling sensitive comms / proofs.

🛡 How defenders use this (legally + safely):

Brand monitoring (company name, domains, exec emails)
Credential exposure triage → force resets, MFA enforcement, conditional access
Ransomware leak-site monitoring (signals before PR/legal fire drills)
IR enrichment (match IOCs, victimology, TTP patterns)

⚠️ Safety note: If you’re doing this seriously, use isolated VM, tight OPSEC, and a clear legal policy. Most value comes from breach intel + monitoring, not browsing random onion links.

📩 Want a defender-only “Dark Web Monitoring Playbook” checklist (what to track, queries, and response steps)?
Comment “PLAYBOOK” or drop a 🔴 and I’ll share it.

#CyberSecurity #OSINT #ThreatIntelligence #CTI #BlueTeam #SOC #DFIR #IncidentResponse #BreachMonitoring #IdentitySecurity #SecurityOperations

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
1👏1
Network Security Channel
Photo
SOC, SIEM, and SOAR are often discussed separately.

👉 Get A Complete Set of Cybersecurity Template Bundle: https://excellog.biz/l/cybersecurity-complete-suit?layout=profile
✔️ Editable | ✔️ Practical | ✔️ Instant Download | ✔️ No learning curve
Get organized faster, work smarter, and manage with confidence.

But in modern cybersecurity operations, they work together as an end-to-end threat detection and response ecosystem.

Each component plays a distinct role in protecting the organization.

✔️ SOC - Security Operations Center
The operational team responsible for monitoring, investigating, and responding to security incidents.
SOC analysts analyze alerts, hunt threats, contain attacks, and coordinate incident response.

✔️ SIEM - Security Information & Event Management
The detection engine that collects and analyzes security logs from across the environment.
It aggregates data from firewalls, endpoints, servers, cloud platforms, and applications to identify suspicious activity.

✔️ SOAR - Security Orchestration, Automation & Response
The automation layer that orchestrates workflows and executes response actions automatically.
SOAR reduces manual effort by automating tasks such as alert enrichment, threat intelligence lookups, ticket creation, and containment actions.

When combined, they create a powerful security workflow:

Logs & Events → SIEM Detection → SOC Investigation → SOAR Automated Response

The objective is simple:

• Detect threats faster
• Respond to incidents quickly
• Reduce analyst workload
• Improve consistency in security operations

Modern security teams measure success through key metrics such as:

• MTTD - Mean Time to Detect
• MTTR - Mean Time to Respond

Organizations that integrate SOC, SIEM, and SOAR effectively build faster, smarter, and more automated security operations.

For cybersecurity professionals:

Which capability is the biggest challenge in SOC environments today?

▪️ Reducing false positives
▪️ Automating incident response
▪️ Integrating security tools
▪️ Threat detection accuracy
▪️ Analyst skill shortages

Interested to hear your perspective 👇

#CyberSecurity #SOC #SIEM #SOAR #SecurityOperations #ThreatDetection #IncidentResponse #CyberDefense #SecurityAutomation

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
1
Roadmap to Becoming a Cybersecurity Expert

If you've wondered where to start in cybersecurity, this roadmap breaks it down beautifully. Whether you're a beginner or a tech professional pivoting into security, this step-by-step guide shows you exactly what to focus on next.

1. Computer Basics - Understand OS, networking, and file systems.

2. Networking firewalls. Learn IP, DNS, ports, protocols, and

3. Operating Systems Get hands-on with Windows, Linux, and macOS.

4. Cybersecurity Fundamentals – Study threats, attacks, and defense strategies.

5. Ethical Hacking - Explore footprinting, scanning, exploitation, and reporting.

6. Network & Web Security Secure apps, servers, and data flows.

etc. 7. Tools - Master Wireshark, Nmap, Metasploit, Burp Suite,

8. Incident Response recover from attacks. Learn how to detect, respond, and

9. Certifications (choose your path!). CEH, CompTIA Security+, OSCP, CISSP

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer

#CyberSecurity2026 #SOC
Network Security Channel
SOC Analyst Technical Assessment.pdf
🚨 A real SOC Analyst does not just close alerts.
They investigate, correlate, contain, and communicate.

I’ve been reviewing a SOC Analyst Technical Assessment, and it highlights something many people still misunderstand about the role:

Being a SOC Analyst is not just about staring at dashboards.
It is about making the right judgment under pressure.

What stood out to me most is how realistic the assessment is.

It tests the exact skills that matter in the real world:

SIEM alert triage
• separating true positives from false positives
• prioritizing incidents correctly
• recognizing brute force, phishing, malware, and benign IT activity

Log analysis and threat hunting
• identifying suspicious RDP activity
• spotting privilege escalation
• noticing command-line abuse
• correlating firewall, Windows, EDR, and SMB-related events

Attack chain thinking
• mapping activity to the MITRE ATT&CK stages
• understanding initial access, execution, persistence, privilege escalation, defense evasion, and exfiltration

Incident response under pressure
• isolating affected systems
• blocking SMB spread
• identifying IOCs
• building timelines
• recommending containment and remediation actions

Written communication
• turning technical findings into an executive summary
• explaining business impact
• giving clear next steps after a ransomware incident

That is the part I like most:

A strong SOC Analyst is not just technical.

They must also be able to:
• think critically,
• connect small signals,
• understand attacker behavior,
• write clearly,
• and explain risk in a way the business can act on.

The uncomfortable truth?

A lot of people think SOC work is repetitive.

But real SOC work is where:
• false positives waste time,
• missed signals become breaches,
• and one bad decision can change the impact of an incident.

This assessment proves something important:

SOC is not about tools alone.
It is about analysis quality.

👇 Don’t just like comment:

What do you think is the most important SOC Analyst skill today?

A) Alert triage
B) Log correlation
C) Threat hunting
D) Incident response
E) Reporting and communication

Comment A / B / C / D / E I’m curious what security professionals value most in real environments.

#SOC #SOCAnalyst #CyberSecurity #SIEM #ThreatHunting #IncidentResponse #LogAnalysis #BlueTeam #ThreatDetection #MITREATTACK #Ransomware #EDR #SecurityOperations #InfoSec #CyberDefense #DFIR #DetectionEngineering #SecurityMonitoring #AnalystMindset #CyberCareer

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
1👍1
🛡 Wazuh Mastery Pack · 01 of 15 — Installation & Setup

The single most repeated question from juniors picking up Wazuh:
"Where do I even start?"

This first cheat sheet gets a Wazuh stack from zero to producing alerts in under 30 minutes — Manager, Indexer, Dashboard, Agents, all the ports you must open, and the verification one-liners I run before walking away from any new install.

A few non-obvious things people miss on day one:
- The all-in-one assistant script (wazuh-install.sh -a) is a lab/PoC tool — don't ship it to prod
- /var/ossec/wazuh-install-files.tar contains your initial creds. Move it to a vault. Lose it = full reinstall.
- Prefer TCP/1514 over UDP for event ingest — UDP silently drops events under load
- Always run /var/ossec/bin/wazuh-control configtest before restarting the manager

If you're starting your Wazuh journey this week, this one is for you.


#Wazuh #SIEM #SOC #CyberSecurity #BlueTeam #InfoSec #OpenToWork

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
1
🛡 Wazuh Mastery Pack · 02 of 15 — CLI Commands

The Wazuh GUI is great. The CLI is where you actually solve problems at 2am.

This cheat sheet is the muscle memory I wish I'd had on day one — service control, agent management, live log testing with wazuh-logtest, cluster operations, and the file paths you'll touch a thousand times.

Three commands every Wazuh operator should burn into memory:

🔹 /var/ossec/bin/wazuh-control configtest
→ validates ossec.conf BEFORE you restart in production. Has saved me from at least three outages.

🔹 /var/ossec/bin/wazuh-logtest
→ paste a raw log line, see exactly which decoder and which rule fires (or doesn't). Single best tool for tuning custom rules.

🔹 /var/ossec/bin/agent_control -l
→ shows every agent and its connection status. Faster than the dashboard when you just need a quick health check.

If you operate Wazuh and aren't using these, you're doing it the hard way.

#Wazuh #SIEM #SOC #BlueTeam #DevSecOps #CLI #InfoSec

📱 Channel : @Engineer_Computer
2
🛡 Wazuh Mastery Pack · 03 of 15 — Configuration Files

Wazuh's power lives in three XML files:

🔹 /var/ossec/etc/ossec.conf — manager's brain
🔹 /var/ossec/etc/shared/default/agent.conf — central agent policy
🔹 /var/ossec/etc/rules/local_rules.xml — your custom detections

This cheat sheet ships ready-to-paste blocks for all three — the global section, the <remote> block agents connect through, central agent policy that pushes to every endpoint, and a working custom rule template.

The single biggest mistake I see in custom rules:
👉 Using rule IDs below 100000.
The 1–9999 range is owned by Wazuh's built-in ruleset. Collide with it and your rule will silently lose to the built-in. Always use 100000 and above for your custom detections.

If you're tuning Wazuh this week, save this one.

#Wazuh #SIEM #SOC #DetectionEngineering #InfoSec #BlueTeam

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
2
🛡 Wazuh Mastery Pack · 04 of 15 — Rules & Decoders

Detection engineering with Wazuh comes down to two artifacts:

📜 Decoders — pull structure out of unstructured logs
🚨 Rules — turn structured fields into alerts

This cheat sheet is the anatomy of both: alert levels 0–16 and what they actually mean, the rule ID ranges that keep you from colliding with built-ins, the chained-rule pattern (if_matched_sid + frequency + timeframe) that detects brute-force behavior, and a working decoder for a custom application log.

A practice that separates senior detection engineers from juniors:
👉 Every rule should map to a MITRE ATT&CK technique.
<mitre><id>T1110</id></mitre>

It costs nothing, takes seconds, and makes your alerts speak the same language as every threat report on the planet.

#Wazuh #DetectionEngineering #SIEM #MITREATTACK #SOC #ThreatHunting #InfoSec

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
1
🛡 Wazuh Mastery Pack · 05 of 15 — Wazuh API Anything you can do in the Wazuh dashboard, you can automate via the REST API on port 55000. This cheat sheet is the muscle: token auth, the endpoints I hit weekly, filtering and pagination, and curl one-liners you can drop into a Bash script today. Three workflows the API unlocks:
🔹 Mass-restart agents after a rule change → PUT /agents/restart (no more clicking through 200 hosts)
🔹 Auto-decommission stale agents → GET /agents?lastKeepAlive&status=disconnected → DELETE the list
🔹 Pipe rule and SCA data into your own dashboards → no need to touch OpenSearch directly Tokens expire in 15 minutes by default. Re-auth in your script, don't hardcode them.

#Wazuh #API #SIEM #Automation #SOC #DevSecOps #InfoSec

🔹 Share & Support Us 🔹
📱 Channel : @Engineer_Computer
1