Video summary
A REAL Day in the life in Cybersecurity in Under 10 Minutes!
Main summary
Key takeaways
Summary
The video follows a cybersecurity analyst through a workday in their second year as a SOC analyst. Their responsibilities have expanded beyond routine monitoring to include meetings, security planning, compliance work, and development. They work from home most of the time and begin by reviewing their calendar to plan around meetings and tasks that require focused attention.
Daily monitoring and incident work
- Phishing reports in Splunk SOAR: The analyst reviews emails reported by users, checking suspicious wording, sender details, and links. They compare displayed link text with the underlying URL and use VirusTotal to help assess suspicious links.
- Automated response: Splunk SOAR playbooks use low-code workflows that connect functions and APIs to generate approval prompts for blocking senders and URLs. The analyst reviews and approves those actions.
- Splunk SIEM monitoring: Dashboards and search queries combine log data from different sources to identify events such as repeated failed logins and suspicious IP activity. The analyst investigates these detections and blocks activity when appropriate.
- Help-desk and incident tickets: Most tickets involve routine access requests, but reports of compromised users or devices can lead to deeper investigations. The analyst looks for indicators of compromise (IOCs), such as unusual network traffic that could suggest data exfiltration or activity outside working hours that could indicate a device takeover.
Compliance, endpoint security, and development
- ISO 27001: As part of the company’s certification effort, the analyst attends vendor and planning meetings and helps assess applications against security requirements, including encryption, backups, and archiving. They describe the process as tedious but useful experience.
- Vulnerability remediation with CrowdStrike: The analyst identifies endpoints running outdated applications and coordinates updates. The video also shows a CrowdStrike detection associated with a downloaded key-generator file, suspected of being malware or a potentially unwanted program (PUP). The platform blocked it automatically; otherwise, the analyst would have added its hash to the IOC block list.
- Dashboards and reporting: The analyst builds dashboards, including one that tracks suspicious IP scans and blocks. These reports help show management the security team’s activity and effectiveness.
The analyst says their role combines typical SOC duties with development work, partly because of their software engineering background. Daily tasks vary, but reviewing alerts and tickets in the morning is a consistent part of the job.
Guides and tutorials mentioned
- A video on SOAR automations for a closer look at playbooks and workflows.
- A Splunk basics video covering search queries and dashboards.
- A previous 2023 day-in-the-life video for comparison.
Main speaker
Tech with Jono — the SOC analyst featured in the video.
Rate this summary
Your feedback will help improve summaries.
Improve this summary
Reprocess with a stronger model when the summary feels incomplete or inaccurate.
Translate summary in another language
Ask questions to this video
Chat for follow-up questions, clarifications, and source-backed answers.