0.4 C
New York
Wednesday, February 4, 2026

New Analyst’s SOC Journey: XDR & Endace Investigations


Further Contributor: Pradnya Padaki

Stepping right into a Safety Operations Centre (SOC) at Cisco Reside Melbourne for the primary time was an expertise charged with pleasure and barely nervous. Beforehand, my solely understanding of SOCs got here from listening to buyer tales and dealing with their challenges—I had recognized the stress, urgency, and teamwork required solely by their eyes, by no means having been in these footwear myself.

Opposite to my expectations of a drawn-out onboarding, the method was surprisingly swift (taking lower than 10-20 minutes). Due to Duo, I used to be rapidly given entry to all of the important instruments: Cisco XDR, Splunk, firewall dashboards, and extra from the duo listing. This seamless entry calmed my nerves and made me really feel immediately welcome.

After that, it was all about getting comfy with the instruments and escalation processes. As a Tier 1/Tier 2 analyst, my day by day routine revolved round Cisco XDR, which introduced collectively incident alerts from each nook of the community. Every alert got here filled with context and intelligence, making investigations a lot much less overwhelming.

One in every of my highlights was utilizing Endace for the primary time. This instrument gave me the flexibility to dive into packet-level particulars, filter knowledge quickly, and transition from high-level incidents to granular packet captures. Correlating metadata and community flows grew to become easy and even satisfying, serving to me clear up issues with far more confidence.

Through the occasion, I used to be regularly placed on the spot to share my firsthand expertise of working in a SOC for the primary time, significantly reflecting on my day two investigations. This inspired me to look at rigorously and assume deeply concerning the operational realities. Many shoppers confirmed eager curiosity, recognizing that my expertise might quickly mirror their very own, which made these interactions particularly beneficial and motivating.

The primary day was all about orientation: understanding the workflow, attending to know the instruments, and creating the mindset wanted for efficient investigations. With assist from skilled colleagues, I realized to triage incidents, test risk intel, dive into logs, and seek the advice of with the group earlier than making choices. By the day’s finish, my preliminary nervousness had reworked into pleasure.

On day two, I took on incidents independently, performing full triage and drafting escalation experiences myself.

Background: Throughout my preliminary SOC project, an alert was generated by Cisco XDR highlighting that an inner endpoint was making connections to a number of IP addresses recognized for malicious exercise.

Detection: Cisco XDR flagged the suspicious conduct, visualizing the connections between one inner asset and several other high-risk exterior hosts. This raised fast issues about potential malware or command-and-control exercise (see Cisco XDR investigation beneath).

Investigation: To validate and additional analyze the incident, I used Endace for in-depth packet inspection. Filtering for the particular IP and utility revealed a constant move of visitors matching file switch patterns. Additional evaluation confirmed that the visitors was generated by a BitTorrent utility working on the endpoint (see Endace screenshot beneath).

endace investigationendace investigation
Cisco Live Melbourne 2025 Endace investigationCisco Live Melbourne 2025 Endace investigation

Response motion: From the primary alert in Cisco XDR, I carried out a complete investigation to rapidly confirm the violation of insurance policies. As a Tier 2 analyst, my response included correlating knowledge from a number of sources, conducting packet captures with Endace to rule out malware, and assessing the broader impression on the surroundings.  As soon as the investigation confirmed Bittorrent utilization because the supply of suspicious visitors, the case was formally escalated to make sure acceptable follow-up, together with person training and enhanced community controls to mitigate recurrence. The affected endpoint was flagged for additional monitoring, and the applying was disabled to forestall ongoing peer-to-peer file sharing. An in depth incident report was compiled, outlining dangers reminiscent of malware publicity, bandwidth consumption, and privateness vulnerabilities related to unauthorized Bittorrent exercise.

End result & Reflection: Seeing the investigation by preliminary alert to root trigger dedication—leveraging each Cisco XDR and Endace—marked a serious milestone in my SOC journey. This end-to-end incident dealing with not solely strengthened procedural self-discipline however considerably boosted my confidence in dealing with real-world threats.

By the tip of the occasion, I noticed the true essence of a SOC isn’t nearly instruments or dashboards. It’s about individuals: collaboration, belief, shared curiosity, and supporting one another. Whilst a newcomer, I used to be welcomed, trusted, and inspired—which made a world of distinction.

In abstract, my first SOC expertise turned preliminary nerves into real confidence. I entered as an observer and left feeling like a part of the group—a journey outlined by assist, studying, and the fun of fixing real-world safety challenges.

Take a look at the opposite blogs by my colleagues within the Cisco Reside Melbourne 2026 SOC.


We’d love to listen to what you assume! Ask a query and keep linked with Cisco Safety on social media.

Cisco Safety Social Media

LinkedIn
Fb
Instagram
X



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

0FansLike
0FollowersFollow
0SubscribersSubscribe
- Advertisement -spot_img

Latest Articles