1. Blue Team — Tổng quan
Blue Team Responsibilities:
Detection:
├── SIEM monitoring & alerting
├── EDR/XDR event analysis
├── Network traffic analysis (NDR)
├── Log correlation & anomaly detection
└── Threat intelligence integration
Response:
├── Incident triage & classification
├── Containment & eradication
├── Forensic investigation
├── Recovery & lessons learned
└── Post-incident reporting
Engineering:
├── Detection rule development
├── Playbook/runbook creation
├── Tool integration & automation
├── Log source onboarding
└── Detection gap analysis
Blue Team Stack:
┌──────────────────────────────────┐
│ SOAR (Cortex XSOAR, Tines) │
├──────────────────────────────────┤
│ SIEM (Splunk, Elastic, Wazuh) │
├──────────────────────────────────┤
│ EDR (CrowdStrike, Defender) │
├──────────────────────────────────┤
│ NDR (Zeek, Suricata, Corelight)│
├──────────────────────────────────┤
│ Threat Intel (MISP, OTX) │
└──────────────────────────────────┘
2. Sigma Rules — Detection-as-Code
# Sigma rule — Detect credential dumping (Mimikatz)
title: Potential Credential Dumping via Mimikatz
id: 0d65a640-3f85-4f8c-8f76-74810a5b1234
status: stable
level: critical
description: Detects Mimikatz credential dumping activity
author: xDev Security Team
date: 2026/01/15
tags:
- attack.credential_access
- attack.t1003.001
- attack.t1003.002
logsource:
category: process_creation
product: windows
detection:
selection_binary:
Image|endswith:
- '\mimikatz.exe'
- '\mimi.exe'
selection_cmdline:
CommandLine|contains:
- 'sekurlsa::logonpasswords'
- 'sekurlsa::wdigest'
- 'lsadump::sam'
- 'lsadump::dcsync'
- 'token::elevate'
selection_access:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1010'
- '0x1038'
- '0x1fffff'
condition: selection_binary or selection_cmdline or selection_access
falsepositives:
- Legitimate security tools accessing LSASS
fields:
- User
- CommandLine
- ParentImage
- TargetImage
# Sigma rule — Detect reverse shell
title: Potential Reverse Shell Connection
id: 1a2b3c4d-5e6f-7890-abcd-reverseshell01
status: experimental
level: high
description: Detects processes spawning interactive reverse shells
logsource:
category: process_creation
product: linux
detection:
selection_bash:
CommandLine|contains:
- 'bash -i >& /dev/tcp/'
- 'bash -c "sh -i'
- '/bin/sh -i'
selection_netcat:
CommandLine|contains:
- 'nc -e /bin/sh'
- 'ncat -e /bin/bash'
- 'nc.traditional -e'
selection_python:
CommandLine|contains:
- 'python -c "import socket,subprocess,os'
- 'python3 -c "import socket'
- 'import pty;pty.spawn'
selection_socat:
CommandLine|contains:
- 'socat exec:'
- 'socat tcp-connect:'
condition: selection_bash or selection_netcat or selection_python or selection_socat
falsepositives:
- Legitimate remote administration tools
- Development/testing activities
# Convert Sigma rules to SIEM queries
# Install sigmac (Sigma converter)
pip install sigma-cli pySigma-backend-splunk pySigma-backend-elasticsearch
# Convert to Splunk query
sigma convert -t splunk -p sysmon sigma_rule.yml
# Convert to Elasticsearch (EQL)
sigma convert -t elasticsearch -p ecs_windows sigma_rule.yml
# Convert to QRadar AQL
sigma convert -t qradar sigma_rule.yml
# Batch convert all rules
sigma convert -t splunk -p sysmon rules/ -o splunk_rules/
3. SIEM Detection — Wazuh/Elastic
# Wazuh custom detection rules
# /var/ossec/etc/rules/custom_rules.xml
5710
SSH brute force detected: 5+ failed logins in 2 min
T1110
5901
useradd
New user account created
T1136.001
550
chmod +s|chmod u+s|chmod 4
SUID bit set on file — potential privilege escalation
T1548.001
550
rm.*\.log|truncate.*\.log|echo.*>.*\.log
Log file tampering detected
T1070.002
4. Threat Hunting
Threat Hunting Process:
Hypothesis
│
▼
Data Collection → What logs do we need?
│
▼
Investigation → Search for indicators
│
├── Found? → Incident Response
│
└── Not found? → Refine hypothesis or new detection rule
│
▼
Documentation → Update playbooks, detections
Hunting Hypotheses (examples):
1. "An attacker has compromised a service account
and is performing lateral movement via SSH"
→ Hunt: Unusual SSH sessions from service accounts
2. "A compromised CI/CD pipeline is deploying
malicious container images"
→ Hunt: Container images from untrusted registries
3. "Data exfiltration is occurring via DNS tunneling"
→ Hunt: Unusually long DNS queries, high DNS volume
# Threat Hunting Queries (Elastic/KQL)
# Hunt: Unusual outbound connections
# process.name:("curl" OR "wget" OR "python" OR "nc") AND
# destination.ip:* AND NOT destination.ip:(10.* OR 172.16.* OR 192.168.*)
# Hunt: Scheduled tasks created
# event.category:"process" AND process.name:"crontab" AND
# process.args:("-e" OR "-l")
# Hunt: SSH from unusual sources
# event.category:"authentication" AND event.action:"ssh_login" AND
# source.ip:* AND NOT source.ip:(10.0.0.* OR 192.168.1.*)
# Hunt: Large file transfers
# network.bytes > 100000000 AND
# destination.port:(443 OR 80 OR 8443) AND
# event.category:"network"
# Hunt: DNS tunneling indicators
# dns.question.name:* AND
# length(dns.question.name) > 50
# Group by source.ip, count unique dns.question.name > 100
5. SOC Metrics & KPIs
SOC Performance Metrics:
Detection:
├── MTTD (Mean Time to Detect) Target: < 1 hour
├── Detection Coverage (ATT&CK %) Target: > 80%
├── False Positive Rate Target: < 10%
└── True Positive Rate Target: > 90%
Response:
├── MTTR (Mean Time to Respond) Target: < 4 hours
├── MTTC (Mean Time to Contain) Target: < 1 hour
└── MTTR (Mean Time to Remediate) Target: < 24 hours
Operational:
├── Alert Volume per analyst/day Target: < 50
├── Alerts auto-resolved (SOAR) Target: > 60%
├── Playbook coverage Target: > 80%
└── Analyst satisfaction score Target: > 7/10
Reporting Dashboard:
├── Weekly: Alert trends, top detections
├── Monthly: MTTD/MTTR trends, coverage gaps
└── Quarterly: ATT&CK coverage heat map
6. Tổng kết
- Sigma Rules: Detection-as-code — write once, convert to any SIEM
- SIEM: Wazuh/Elastic/Splunk for log correlation and alerting
- Threat Hunting: Hypothesis-driven search for undetected threats
- SOC Metrics: MTTD, MTTR, detection coverage, false positive rate
- Stack: SIEM + EDR + NDR + SOAR + Threat Intel
Bài tiếp theo sẽ kết hợp Red + Blue thành Purple Team — Collaborative Security.