
π Cybersecurity Β· Data Flow
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
Drawing diagramβ¦
Data flow for a SIEM pipeline: endpoint EDR, firewalls, identity provider, cloud audit logs and application logs are collected by agents and syslog forwarders into a log pipeline, parsed into a common schema, enriched with asset inventory, user directory and threat intelligence (IP/domain reputation), stored in hot and cold storage, evaluated by detection rules and UEBA, and alerts create cases for SOC analysts in the SOAR platform.
flowchart LR EDR[Endpoint EDR] --> COL[Collectors and syslog] FW[Firewalls] --> COL IDP[Identity Provider] --> COL CLOUD[Cloud audit logs] --> COL APP[Application logs] --> COL COL --> PARSE[Parse to common schema] PARSE --> ENR[Enrichment] ASSET[(Asset inventory)] --> ENR DIR[(User directory)] --> ENR TI[(Threat intelligence)] --> ENR ENR --> HOT[(Hot storage - 30 days)] HOT --> COLD[(Cold storage - 1 year)] HOT --> DET[Detection rules and UEBA] DET -->|Alerts| SOAR[SOAR case management] SOAR --> SOC[SOC Analysts]
A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.
The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.