Understanding active security monitoring
As the name implies, active security monitoring is aimed at actively interrogating the monitored environment for security incidents and other relevant security-related information. It is about rolling up our sleeves and actively interacting with the environment to see how well our security program is holding up, or to even get a feel for our security posture.
Some forms of active security monitoring include the following:
- Network scanning to interrogate and examine network-connected devices
- Host-based agents that can scan the host for security-related issues and malicious content
- Manually examining endpoints for signs of malicious activity and content
Let's look at each of them in detail.
Network scanning
In this section, we will discuss the various methods around network scanning. We will look at common tools and techniques and discuss the applicability of those tools and techniques to uncover certain types...