Lab Overview
Room Objective
Understand why and how people are targeted in cyber attacks and how the SOC helps defend them. The room explores the human element as the weakest link in cybersecurity, covers common social engineering attack types, and teaches how SOC analysts detect and mitigate attacks targeting people.
Methodology / Approach
Worked through each task sequentially, engaging with the interactive security dashboard to practice real analyst decisions. Applied the two-layer defence model (Mitigation + Detection) to each scenario, making live decisions on whether to block, disable, or investigate each case.
Walkthrough
Key Concepts Covered
- The human element: Humans are targeted because of the access they can provide to websites, mailboxes, databases, and corporate networks. Humans are consistently the weakest link in cybersecurity.
- Social engineering: Attacks that manipulate human psychology rather than exploiting technical flaws. Designed to be trustworthy and emotional (urgency, fear, curiosity).
- Phishing: Most common social engineering method. Estimated 3.4 billion malicious emails sent daily. Fake login pages harvest credentials.
- Malware downloads: Attackers distribute malware through fake software downloads, fake CAPTCHAs, malicious QR codes, and SEO poisoning.
- Deepfakes: AI-generated audio/video used to impersonate executives or colleagues. Real case: finance worker tricked into wiring $25 million via deepfake video call.
- Impersonation: Attackers pretend to be IT support, HR, or management over phone/chat to manipulate victims.
- Mitigation vs Detection: Mitigation prevents or reduces attacks (anti-phishing tools, AV/EDR, awareness training, access management). Detection catches what slips through — the SOC's core role.
Tasks & Findings
Practical Scenario — Employees at Risk