🛡️ Cyber Defense & SOC · SOC Operations
Map log source coverage to attack surface
Inventory what you can see versus what attacks require, closing blind spots deliberately.
intermediate~35 minSOC AnalystsDetection EngineersThreat Hunters
Steps
- 1List top MITRE techniques relevant to your industry threat profile
- 2Map each to required telemetry source and current ingestion status
- 3Score coverage: full / partial / none per technique
- 4Prioritize gaps by likelihood × detection-value
- 5Fund onboarding of highest-value sources with success tests
- 6Re-map quarterly; infrastructure drifts silently
Common Pitfalls
- ▲Ingesting everything equally, cost exploding value flat
- ▲Coverage assumed rather than tested with synthetic events
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill soc-operations-log-source-coverageInstall globally
$ npx skills add aniruddhaadak80/skills --skill soc-operations-log-source-coverage -gTags
#visibility#logging#coverage#cyber-defense-ops#soc-operations