Security monitoring is the continuous collection, correlation and analysis of telemetry from systems, networks and applications to detect indicators of compromise and policy violations. It feeds detection rules, baselines and analytics that surface suspicious behaviour for investigation and response. As a discipline it spans log aggregation, intrusion detection, threat intelligence enrichment and alerting, and is a core function of a security operations centre.
Overview
- Telemetry from hosts, networks and applications is normalised and centralised for analysis.
- Detection logic combines signatures, behavioural baselines and threat intelligence to flag anomalies.
- Alerts are triaged and escalated, feeding investigation and containment workflows.
- Coverage and tuning balance sensitivity against alert fatigue from false positives.
Mechanisms
- A SIEM aggregates and correlates events across many sources in near real time.
- Anomaly Detection models learn normal behaviour and surface statistically unusual activity.
- Enrichment with Threat Intelligence adds context such as known-bad indicators.
- Alerting and dashboards route findings to analysts with severity and context.
Applications
- Driving the detection function of a Security Operations Centre.
- Triggering Incident Response when high-confidence indicators appear.
- Feeding Vulnerability Management with evidence of exploited weaknesses.
- Demonstrating control effectiveness through Audit Logging and reporting.