โ† Back to list

๐Ÿ› Day 3: Types of Cyberattacks

Part of the 30-Day SOC Level 1 Training Series

0ccupi3R ยท 2025-08-15 10:47 ยท 0 claps ยท 2.9 min read
#siem #cybersecurity #security-operation-center #cyberattack #phishing
Open on Medium โ†—
Wiki topics: ๐Ÿ”’ ยท Cybersecurity

๐Ÿ› Day 3: Types of Cyberattacks

*Part of the 30-Day SOC Level 1 Training Series*

๐Ÿงฉ What Youโ€™ll Learn Today

As a SOC Level 1 analyst, youโ€™ll be expected to recognize and respond to various types of cyberattacks. This lesson introduces the most common attack types, how they work, and how they appear in real-world SOC operations and SIEM alerts.

๐Ÿ“˜ Key Attack Types & Definitions

1. Phishing and Spear Phishing

๐Ÿ“˜ Definition: Phishing is a social engineering technique where attackers impersonate trusted entities to trick users into revealing sensitive information. Spear phishing is a more targeted version aimed at specific individuals or roles within an organization.

๐Ÿง  Example: An employee receives an email that looks like itโ€™s from their bank, asking them to โ€œverifyโ€ their account by clicking a link. The link leads to a fake login page that steals credentials. In SIEM, this may appear as a user clicking a suspicious URL flagged by threat intelligence.

โ€œPhishing is like someone pretending to be your friend to steal your wallet โ€” except it happens through email or messages.โ€

2. Malware and Ransomware

๐Ÿ“˜ Definition: Malware refers to any malicious software designed to disrupt, damage, or gain unauthorized access to systems. Ransomware encrypts files and demands payment for decryption.

๐Ÿง  Example: A user downloads a fake PDF attachment that installs a keylogger, silently capturing passwords. In SIEM, this may show up as unusual process creation or outbound traffic to known malicious IPs.

โ€œRansomware is like a thief locking your house and asking for money to give you the key.โ€

3. Brute Force Login Attempts

๐Ÿ“˜ Definition: Brute force attacks involve systematically guessing passwords until the correct one is found.

๐Ÿง  Example: Authentication logs show 100+ failed login attempts from the same IP within 5 minutes. The SIEM triggers a brute force alert.

โ€œItโ€™s like trying every key on a keyring until one opens the door.โ€

4. Denial of Service (DoS) and Distributed DoS (DDoS)

๐Ÿ“˜ Definition: DoS and DDoS attacks flood a system or network with traffic, making it unavailable to legitimate users.

๐Ÿง  Example: Firewall logs show thousands of requests per second from multiple IPs targeting a single web server.

โ€œItโ€™s like a crowd blocking the entrance to a store so real customers canโ€™t get in.โ€

5. SQL Injection

๐Ÿ“˜ Definition: SQL Injection is a web application attack where malicious SQL code is inserted into input fields to manipulate or access databases.

๐Ÿง  Example: An attacker types ' OR '1'='1 into a login form, bypassing authentication and accessing user data. SIEM may detect this through abnormal query patterns in web logs.

โ€œItโ€™s like tricking a vending machine into giving you snacks without paying.โ€

6. Cross-Site Scripting (XSS)

๐Ÿ“˜ Definition: XSS allows attackers to inject malicious scripts into web pages viewed by other users.

๐Ÿง  Example: A comment box on a website allows JavaScript, which an attacker uses to redirect users to a fake login page.

โ€œItโ€™s like someone writing a trap into a public notice board that tricks others when they read it.โ€

7. Man-in-the-Middle (MITM)

๐Ÿ“˜ Definition: MITM attacks intercept communication between two parties to steal or alter data.

๐Ÿง  Example: An attacker intercepts login credentials sent over an unsecured Wi-Fi network.

โ€œItโ€™s like someone secretly listening to your phone call and writing down your credit card number.โ€

8. Insider Threats

๐Ÿ“˜ Definition: An insider threat involves someone within the organization misusing their access to cause harm.

๐Ÿง  Example: A disgruntled employee downloads sensitive data before leaving the company. SIEM may show large file transfers or access to restricted folders.

โ€œItโ€™s like a trusted employee stealing from the company vault.โ€

9. Suspicious DNS Queries

๐Ÿ“˜ Definition: Attackers often use DNS to communicate with command-and-control servers or exfiltrate data.

๐Ÿง  Example: DNS logs show queries to newly registered domains or domains flagged by threat intelligence feeds.

โ€œItโ€™s like someone secretly sending coded messages to a remote location.โ€

10. Unusual File Access or Modification

๐Ÿ“˜ Definition: Unauthorized access or changes to sensitive files may indicate data theft or malware activity.

๐Ÿง  Example: File integrity monitoring alerts show changes to system files or access to confidential documents by non-privileged users.

โ€œItโ€™s like someone sneaking into a locked cabinet and rearranging the contents.โ€

๐Ÿง  Summary

These attack types form the core of what SOC analysts monitor daily. Recognizing patterns in logs, alerts, and user behavior is key to early detection and response. For interviews, be ready to explain how these attacks appear in SIEM tools and what actions youโ€™d take as an L1 analyst.


๋ฉ”ํƒ€๋ฐ์ดํ„ฐ
post_id
f12419eb2d3d
slug
day-3-types-of-cyberattacks-f12419eb2d3d
url
https://medium.com/@0ccupi3R/day-3-types-of-cyberattacks-f12419eb2d3d
canonical_url
https://medium.com/@0ccupi3R/day-3-types-of-cyberattacks-f12419eb2d3d
author_url
https://medium.com/@0ccupi3R
status
ok
fetched_at
2026-06-16 19:09:56