day in the life of a soc cyber security analyst (you NEED to learn these security tools RIGHT NOW!)

  Рет қаралды 36,009

Mad Hat

Mad Hat

Күн бұрын

Пікірлер: 122
@bigbojangles4585
@bigbojangles4585 Жыл бұрын
Bro your content is exceptional! The videos you created about your job have been incredibly helpful. I've learned so much from them, but I'm still struggling with how to apply what I'm learning to real-life situations. That's why I find the stories you share so valuable, they help connect the dots and make the information more relatable. I have an idea for a future video(you have some similar content): it would be great if you could share some of the things you wish you had known before starting your job, or things you felt were unnecessary to learn. Additionally, it would be interesting to hear about the skills or knowledge that actually helped you in your job and made you feel more prepared.
@madhatistaken
@madhatistaken Жыл бұрын
Thank you for watching, I'm glad to hear it's somewhat helpful! Definitely adding that to the upcoming video ideas, there's a lot I would do differently going back. Awesome idea! 💚
@bigbojangles4585
@bigbojangles4585 Жыл бұрын
@@madhatistaken HELL YEAH, I DID AN IRL FIST PUMP WHEN I READ THIS. I honestly don't know where it even came from, I never do that.
@madhatistaken
@madhatistaken Жыл бұрын
@@bigbojangles4585 😅 I hope it's worthy of your excitement. I'll try to provide some good info in it 💚
@shuttlecrab
@shuttlecrab Жыл бұрын
Well freaking said
@Jesse_Johnson
@Jesse_Johnson Жыл бұрын
Open up your CherryTree 🍒. Take notes kids. This is the real OG shizz right here.
@madhatistaken
@madhatistaken Жыл бұрын
😎
@octaviouswilliams1091
@octaviouswilliams1091 Жыл бұрын
My guy, your content is super entertaining and informative! Please keep it coming.
@madhatistaken
@madhatistaken Жыл бұрын
I'm glad to hear it was helpful! I'll keep trying to provide informational and somewhat humorous security content, thank you for watching! 💚
@clacketyclack
@clacketyclack Жыл бұрын
Hiya bud, just wanted to say you have a new subscriber! I’m currently 15 years working a non IT job and thinking of doing a career change. Your stuff is a mix of really informative, high value content and belly laugh inducing skits. Thanks for what you do.
@jamest9638
@jamest9638 Жыл бұрын
Love your humor with all your videos, keep this runnin! I myself, taking notes to aid me heading into the blue team side of things. You rock!
@madhatistaken
@madhatistaken Жыл бұрын
Thank you for watching! 💚 Keep keepin on with the learning! I'm learning tons daily 😅
@chaya6344
@chaya6344 Жыл бұрын
Keep us update if you manage to move up on a different position. Great video as always!
@madhatistaken
@madhatistaken Жыл бұрын
I shall make awkward update videos as I progress through! 😅 Thank you for watching! 💚
@shuttlecrab
@shuttlecrab Жыл бұрын
Entertaining: ✅ Informative: ✅ Easy to understand: ✅ Inspiring: ✅ Really glad I came across your videos. The first one was the review of the google cyber cert with coursera, which was also mega helpful. Looking forward to watching more of your content. Keep up the good work and best of luck in your endeavours!
@madhatistaken
@madhatistaken Жыл бұрын
Thank you for the kind words of support! I'll keep trying to make helpful stuff that is edu-taining. 🫡💚 Hope the Google cert was helpful!
@quintonswader3041
@quintonswader3041 4 ай бұрын
Thank you for all of your videos. Between you and OTW I have a better understanding of what "Cyber Security" truly is. I now have an idea of what direction I would like to go in the industry.
@miguelothemelo7396
@miguelothemelo7396 Жыл бұрын
Been looking into data analytics and cybersecurity. For a second job would love to make it my main career. Thanks for the knowledge
@evemackenzie6138
@evemackenzie6138 Жыл бұрын
Wow i didnt know that soc analyst's life is so interesting! Cant wait to finish my courses and get a job as a soc analyst!
@SnipesRuntheNavy
@SnipesRuntheNavy Жыл бұрын
Great channel man!!
@madhatistaken
@madhatistaken Жыл бұрын
Thank you! I'm tryin 😅💚
@CyberFraudDawg
@CyberFraudDawg Жыл бұрын
It feels nice to know that there are "experts" out there that are about 2 youtube videos smarter than I am. There's still hope for me.
@madhatistaken
@madhatistaken Жыл бұрын
I'm not an expert, but I've been told confidence goes a long way. I don't like to think I'm smarter than others, but the old adage "if you're the smartest person in the room, you're in the wrong room" comes to mind. I'm just trying to learn and feel like my learning curve in my current position is coming to a plateau, I find myself frustrated when I ask my fellow junior analysts questions only to get information I've already pointed out 😕 and I'm not blunt enough to say "I already knew that" and so I will listen as they explain for a few minutes. I know you're probably just as qualified (probably more) to do this job, but I hope I can at least be entertaining 😅
@Strive117
@Strive117 Жыл бұрын
Great videos, gonna learn the terms / tools and just paste that into the Resume and we'll see how it goes.
@madhatistaken
@madhatistaken Жыл бұрын
Fluff up your resume with buzz words for sure! I'm suspicious with my last batch of applications. Thinking there's a lot of automation involved and just pumping applications through a bot 😅Let us know if you land some solid interviews!
@jurielle3231
@jurielle3231 Жыл бұрын
Man great content, subscribed, I'm also a new hire SOC Analyst this was a great help on what to expect!
@AugustusAsgeir
@AugustusAsgeir Жыл бұрын
So grateful for you bro... goin towards this path myself
@jesseC0806
@jesseC0806 Жыл бұрын
Insightful! Awesome video mad! Thank you!
@madhatistaken
@madhatistaken Жыл бұрын
Thank you for watchin'!💚
@YankeeTM
@YankeeTM Жыл бұрын
Could you make a video on how you deal with suspicious outbound connections? Loving your videos!!!
@trapizonn3603
@trapizonn3603 Жыл бұрын
I’m happy i stumbled upon your channel i will make sure to utilize this information.
@romanxxxx
@romanxxxx Жыл бұрын
love your style of content its dope
@madhatistaken
@madhatistaken Жыл бұрын
💚
@0ijm3409fiwrekj
@0ijm3409fiwrekj Жыл бұрын
4:30 If you can share, what was your other EDR solution? was it SentinelOne?
@fahadmussadaq8222
@fahadmussadaq8222 Жыл бұрын
Hey Mad Great Video, Can you please make a video on how you landed the remote job and how can we connect with a recruiter who can help us land an entry level job. Thanks
@Denspion
@Denspion 9 ай бұрын
I'm currently working toward a bachelors in Cyber Security, and I'm still early on in the process, I do consider myself tech savvy and IT literate, though even just preparing for my CompTia A+ Core 1 and Core 2 certs, feel I may be in a bit deep. Now I know I need to learn Python and command code and more down the road, just want to make sure i'm not in over my head.
@Bangarang341
@Bangarang341 5 ай бұрын
i digs me this content, my dude
@franklinmccullough85
@franklinmccullough85 Жыл бұрын
Comment for algorithm. Plus I'm curious how your journey to 100K is going. Looking forward to your progress!
@madhatistaken
@madhatistaken Жыл бұрын
Me too!🤞🤞🤞 Maybe I'll get the Facebook job and spill all the security secret sauce and beans to all y'all 😅
@jacobferguson35
@jacobferguson35 Жыл бұрын
Wooo let's get you going on the algorithm hit all the buttons!!
@domnuinginer2011
@domnuinginer2011 5 ай бұрын
Thanks for the video! What's the other EDR solution you've mentioned that complemented the Crowdstrike one?
@jasonsmart3141
@jasonsmart3141 10 ай бұрын
Is your job as a SOC analysts very stressful? Medium or low stress?
@thtnydude
@thtnydude Жыл бұрын
So I just wanted to say, I have been so sure that I wanted to be a Red Teamer, and I just want to say that you're making Blue Team look cool.
@vinyldown8490
@vinyldown8490 Жыл бұрын
I would love to see more triaging 101. basic stuff. thank you
@vinyldown8490
@vinyldown8490 Жыл бұрын
I mean, how do you go to investigate a specific alert, how do you assume if something is malicious /suspicious or not. I work as soc level 1 and the impostor syndrome hits me hard
@madhatistaken
@madhatistaken Жыл бұрын
@@vinyldown8490 I treat every alert as guilty until proven innocent 😅 Regardless of where the alerts is generated (SIEM, EDR, etc.) I check what conditions were met in the alert to cause it to fire. Was it a process, installation, cmd line, etc. I treat installations with more scrutiny and have to dig up where the installation came from, what is normal file paths for the installation, who is installing and why would they need it, file hashes, check for process injections, potentially side loaded dlls. I just run through the surrounding processes to see if there is anything out of the ordinary. Sometimes it's just checking all the artifacts and activity and just knowing that all of it as a whole is benign. If I'm not sure on something I'll ask other analysts to check over what I've found so far. If I'm still not sure I'll reach out/escalate to senior analysts. My boss said it just takes time for you to get better at understanding and identifying what is suspicious/malicious in OUR environment and that every organization is different.
@madhatistaken
@madhatistaken Жыл бұрын
Maybe I can make a triaging 101 video where I go through a few alerts at once and then let people guess what's malicious and not before moving on in the video 🤔It's unfortunate how many false positives there are because it gives you a false sense of security 😅
@vinyldown8490
@vinyldown8490 Жыл бұрын
@@madhatistaken thanks this is great. Two things, 1st how many alerts do you have each day. In my previous job I has 15 a day and I could do that. In the Qradar I am right now, we have 200qradar offences per day, and all of that would be impossible. ( tuning is almost an unknown word in the organization I am in right now)
@madhatistaken
@madhatistaken Жыл бұрын
@vinyldown8490 I'm definitely on the 20 alert end like your previous position. If you're expected to bust through that many alerts then I imagine understanding baseline is even more important so you can make quicker decisions. Our security department used to have thousands of alerts daily and 30 security analysts before it was overhauled with different security tools, tuned, and the IR team brought down to roughly 10. Funny enough our SIEM used to be Qradar, but my bosses didn't like it 😅 If you're handling primarily SIEM alerts then checking the user field, URLs, IPs, and a few other artifacts might be good places to check for baseline normal behavior.
@cybershark77
@cybershark77 Жыл бұрын
New subs. Yeaah Awesome humor also insightful vid 🤙 more vids pls 🤙
@madhatistaken
@madhatistaken Жыл бұрын
💚
@orlovskyconsultinggbr2849
@orlovskyconsultinggbr2849 Жыл бұрын
I would like to hear some sort of review of the tools which used in the enterprise, because people there a lots of people.
@chriscyphercat
@chriscyphercat Жыл бұрын
'We're all exactly where we need to be in life", yeah bud! You just slayed the imposter syndrome dragon right there!
@eagletvv4926
@eagletvv4926 Жыл бұрын
Great video thanks :)
@zorooverluffy2665
@zorooverluffy2665 Жыл бұрын
Great video
@madhatistaken
@madhatistaken Жыл бұрын
💚
@anounTT
@anounTT Жыл бұрын
I noticed you didn't mention reading the python file and seeing exactly what it was doing.
@Msam109
@Msam109 Жыл бұрын
Great content madhat. Are the baselines written in companies SOP or you just have to figure it out
@madhatistaken
@madhatistaken Жыл бұрын
Our company doesn't have a baseline, I'm not sure most would as that would be difficult to create and upkeep. The threat rules have suppressions and false positives in the coding notes which does provide some insight to baseline behavior, however most alerts are more one of a kind where I have to use a combination of previous knowledge on what is normal behavior from operating system process and programs AND a lot of figuring it out as I go along. Since there's so much available old/new software that I've never heard of. I often have to research the reputation and weigh the business use case to determine whether or not an uncommonly used program should be allowed to remain installed on an endpoint.
@vicariousviews007
@vicariousviews007 Жыл бұрын
What can you recommend to study between gaining certs in coding & security+ and gaining employment to ensure one is ready to understand the necessary fundamentals for the interview process?
@jerk_berk
@jerk_berk Жыл бұрын
If you’re just breaking in, I’d honestly recommend doing the google IT support and the Google cyber security cert. those certs won’t land you a job by themselves, but the info they provide with a beginner friendly presentation, it’s great 👍🏽
@TigerTarim-z7l
@TigerTarim-z7l Жыл бұрын
Please teach about Crowd strike and fishing Email
@tracetv8115
@tracetv8115 Жыл бұрын
Can you drop a few names of the tools u use? I not, maybe some smiliary tools that are good to start with?
@yuverris
@yuverris Жыл бұрын
just how many cybersecurity positions can in a company also is coding/programming required for the majority ? and btw I really like your videos man great mix of decent content and humour
@CybSengh
@CybSengh Жыл бұрын
Coding isn't really require unless you are a cybersecurity engineer. Cybersecurity analysts have many premade tools for doing what they need, but can also write their own scripts to do specific things they need.
@everything-om3zx
@everything-om3zx Жыл бұрын
any suggestion on how i can get a job? i applied to more then 400 jobs and i cant get any, i have eJPT, Security +, Cysa +, some other certification of completion and i also studied cyber security in a University bootcamp. and i still cant get any interview.
@madhatistaken
@madhatistaken Жыл бұрын
If you're not getting any interviews your resume might need tweaking and/or you might need to apply to more jobs. I applied to over 1000 and only heard back from 15 or so and only got recruiter interviews over the phone from about 6 or so. Have you researched resume tips? Do you have any projects, home labs, achievements in hacking sites, CTFs etc listed on it? Hard to say without looking at your resume if it's OK and you just need to apply to more but I'd say you're more than qualified to be landing some interviews.
@PlasmaBurns
@PlasmaBurns Жыл бұрын
"I've been saying all along that my biggest fear is that someone would program a machine to give a wrong answer. If that were to happen, the machine would still work fine, we just wouldn't know it." - Avi Rubin Professor, Computer Science Johns Hopkins University. "Why am I always being asked to prove these systems aren't secure? The burden of proof ought to be on the vendor. You ask about the hardware. 'Secret.' The software? 'Secret.' What's the cryptography? 'Can't tell you because that'll compromise the secrecy of the machines.'... Federal testing procedures? 'Secret'! Results of the tests? 'Secret'! Basically we are required to have blind faith." - Dr. David L. Dill Professor, Computer Science Stanford University Good luck with all that. its like learning that most if not all VPN companies are CIA honey hole front companies.
@madhatistaken
@madhatistaken Жыл бұрын
Not sure how the secrecy of the vendor provided software is concerning in this particular position. A lot to unpack there. If you're quoting to argue the tools aren't worth learning (I think that's what you're implying), knowing how they function fundamentally still helps in understanding how our data is being "protected", even if it does become fully AI or is "trade secret". Also, I agree that it's highly likely VPN companies are CIA backed, knowledge is power and they have a lot of money to back them up. I don't do anything of value for them on my computers. I do enjoy learning how to know you're being watched/tracked.
@PlasmaBurns
@PlasmaBurns Жыл бұрын
@@madhatistaken Hmm. if what you say is true then I have the Ultimate test for you. If you really want to see just how far reaching their control of information goes on all global platforms I can tell you, even show you as I have first hand experience. Example. to understand their control mechanisms you simply unleash information we are not supposed to have. I have spent 10 years now gathering and releasing specific information that is 100% forbidden. I have the US Air Force, US Navy, FBI, DHS, Israeli Defense Forces, Anti Defamation League and a dozen or so other govt agencies/private corps all on camera working together to stage attacks on Americans.. I could write a book on how they control/eliminate banned info. I can also name them, show their faces, and their crimes on HD video. Sounds crazy right? Of course, but the problem is I can prove it all. It would be interesting to melt the system with reality but I lack the knowledge on how to do that
@abdelmalekamine7318
@abdelmalekamine7318 10 ай бұрын
What do you think about splunk?
@dropz285
@dropz285 Жыл бұрын
What best helped you read Python logs better?
@jeffu3248
@jeffu3248 Жыл бұрын
🔥🔥🔥🔥
@algorworld7447
@algorworld7447 Жыл бұрын
I'm weak that he encrypted a sock at the beginning.
@RandomVideos-hm3kg
@RandomVideos-hm3kg Жыл бұрын
in order to be a Sec analyst 4 do you need code languages?
@richritcherson9347
@richritcherson9347 Жыл бұрын
You've mentioned in other videos that you have a degree, but what would you say is the minimum requirement for a soc analyst? As in, education and certs?
@madhatistaken
@madhatistaken Жыл бұрын
Requirements vary widely by company and position. Some positions you can get with just the sec+ and some cyber security projects on your resume. Others will require a bachelors plus several certs to even be considered. I suppose sec+ (if you don't have a bachelors) would be the minimum. The job market is really difficult at the moment, so people need to adopt a continual learning mindset throughout their job application process (and career too) where you continue your education through either certifications or formal college education until you can land that entry job.
@kiiturii
@kiiturii Жыл бұрын
​@@madhatistakenwhat exactly would a cybersecurity project be? Building your own labs or? What type of projects would look good on a resume?
@evanj51
@evanj51 Жыл бұрын
im commenting because you said to. Hello World.
@___m16
@___m16 Жыл бұрын
Can yoi do these cyber security jobs working at home once you land a job ?
@dancarpenter419
@dancarpenter419 Жыл бұрын
Is a SOC analyst still a good starting career path ?
@nahidsarker69
@nahidsarker69 Жыл бұрын
Bro r u an instant responder or SIEM splunk engineer who sits in front of a monitor to monetize the log that are come from the whole system?
@madhatistaken
@madhatistaken Жыл бұрын
Both! My job has me doing a lot of different things. With opportunities to do more if I find the time.
@nahidsarker69
@nahidsarker69 Жыл бұрын
@@madhatistaken Bro,i want to be a splunk engineer but don't know the whole certificate or knowledge/experience path. Does it need expert lvl of coding(i hate coding) or how hard it is to be a splunk engineer? Please make a complete video on it🙏. I can't find any video which contains all these informations and i think u can tell it better than anyone bcz u r in this role r8 now🔥
@grimmcat9727
@grimmcat9727 7 ай бұрын
Nice
@muthannah-8
@muthannah-8 7 ай бұрын
Is soc analyst a 12hr shift type job or a 9 to 5?
@trancefighter
@trancefighter Жыл бұрын
hey bro what vm do you recommend for setting up a home lab on a Mac?
@madhatistaken
@madhatistaken Жыл бұрын
We used VirtualBox and VMWare all throughout my bachelors courses. I preferred VirtualBox for how easy it was to setup/use. You can even install a copy of KaliLinux on it so you don't have to deal with dual boot 😅 M1/M2 chips made compatibility tough...
@jainabaceesay5147
@jainabaceesay5147 Жыл бұрын
Hi Mad Hat, do I need a degree to break into Cybersecurity? I have a BSC degree in Economics. You are my last hope before I start to give up
@madhatistaken
@madhatistaken Жыл бұрын
You definitely don't need a degree to get into cyber. A lot of government jobs might still require it, however certifications are quickly becoming highly sought after in the private sector. Having a bachelors even unrelated to cyber still shows you're willing to put in the work paired with a few choice certs, you will stand above someone with just certs. Just have to put in the effort to learn the content needed for whatever niche you decide to go after in cyber as it has many roles. A couple of my coworkers now started out from general IT and even a security guard at the company front desk prior to getting into their security analyst roles. My last job I had a coworker who was wicked smart and had a criminal justice degree who transitioned into azure cloud engineering from helpdesk. It's definitely possible! 💚Just have to study up and apply to relevant jobs!
@jainabaceesay5147
@jainabaceesay5147 Жыл бұрын
@@madhatistaken Thank you so much, I will definitely follow this guideline
@ThatFlyGuy98
@ThatFlyGuy98 Жыл бұрын
What state are YOOU froom? I’m in Chicago area soo I’m assuming it won’t be hard to find a cyber gig cas it’s a huge market
@madhatistaken
@madhatistaken Жыл бұрын
I'm originally from California. Currently still on the West coast. Definitely still a huge market right now, proving your qualifications and experience is the hard part though with everyone and their family applying to these remote jobs 😅
@alexandruaxentioi3006
@alexandruaxentioi3006 Жыл бұрын
Is the voice real?
@madhatistaken
@madhatistaken Жыл бұрын
Indeed it is
@alexandruaxentioi3006
@alexandruaxentioi3006 Жыл бұрын
@@madhatistaken h4xor
@Shokeilive
@Shokeilive Жыл бұрын
Do you ever have downtime?
@madhatistaken
@madhatistaken Жыл бұрын
There was a good bit of downtime when I started, but a few months in we were all given documentation to do plus I was taken on to do the threat detection project. We aren't micromanaged, so I can make some down time provided the ticket queue is taken care of. My boss and his boss have given talks on how "we're all adults" and as long as work is getting done, then we have some freedom in our daily work. Really is an awesome work environment, albeit the pay is less than average 😅
@--Morpheus--
@--Morpheus-- Жыл бұрын
​@@madhatistakenwould you say 60k is too high for a tabula rasa entry soc role?
@AlienWarTycoon
@AlienWarTycoon Жыл бұрын
This whole process will be replaced or augmented by AI in the next 2 years. Probably not a great career choice for budding security pros
@madhatistaken
@madhatistaken Жыл бұрын
Same could be said about programming?
@AlienWarTycoon
@AlienWarTycoon Жыл бұрын
@@madhatistaken I don't know about that. I think that it will be able to give great coding samples to integrate into your application but I don't see it generating a full application debugged and ready for production in the next two years
@madhatistaken
@madhatistaken Жыл бұрын
@@AlienWarTycoon Sweet, I'll pivot to programming once I'm replaced 😎
@CyDETECT
@CyDETECT 8 ай бұрын
@@AlienWarTycoonif false positives are still a big problem in todays industry how could you possibly think that soc analyst would be replaced?
@AlienWarTycoon
@AlienWarTycoon 8 ай бұрын
@@CyDETECT I was not talking about today.
@thelitepredator
@thelitepredator Жыл бұрын
How many months into the job 😂
@madhatistaken
@madhatistaken Жыл бұрын
Too many months
@louiepecan
@louiepecan Жыл бұрын
Literally my favorite channel right now📠💯
@madhatistaken
@madhatistaken Жыл бұрын
💚🙂
@poopsmith4478
@poopsmith4478 Жыл бұрын
I hope cyber security isn't a pipe dream I need a new career
@madhatistaken
@madhatistaken Жыл бұрын
Anyone can get into it if they put in the time and effort! It's an exciting career 🥳
@ryenoe733
@ryenoe733 Жыл бұрын
It’s a great day when I find a mad hat video 🫡
Kerberos Authentication Explained | A deep dive
16:52
Destination Certification
Рет қаралды 344 М.
Cyber Security Certificate Tier List - UPDATED (2023)
22:34
UnixGuy | Cyber Security
Рет қаралды 176 М.
From Small To Giant Pop Corn #katebrush #funny #shorts
00:17
Kate Brush
Рет қаралды 68 МЛН
escape in roblox in real life
00:13
Kan Andrey
Рет қаралды 81 МЛН
Cyber Security Paths | The LAST Roadmap You'll Ever Need
22:04
How I Would Learn Cyber Security (If I Could Start Over)
13:00
you DON'T need helpdesk!!!
10:29
Mad Hat
Рет қаралды 32 М.
Top 10 Cyber Security Analyst Tools
9:25
Mad Hat
Рет қаралды 22 М.
An Entire Cyber Security Degree in 15 Minutes
15:39
Mad Hat
Рет қаралды 69 М.
how to apply in 2024 and ACTUALLY get a job
17:37
Mad Hat
Рет қаралды 44 М.
My First Day As A SOC Analyst
10:01
Mad Hat
Рет қаралды 65 М.