Logging & Monitoring
Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.
Term
description · examples · notesLogging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.
Description
This technology is the foundation for all other detective controls. Without adequate logging, it is impossible to determine what happened during an incident, who was involved, and which systems were affected.
Effective logging requires defining what is recorded, how long it is retained, where it is stored, and who has access to the records. Logs must be protected from unauthorized modification to remain valid for forensic analysis.
What people often say
- If logs are collected, threats are automatically detected.
- Retaining logs for three months is always sufficient.
Covers / does not cover
Covers
- Recording logins, resource access, and administrative actions
- Tracking changes in system and application configuration
- Foundation for forensic analysis after a security incident
- Enabling event correlation in a SIEM system
Does not cover
- Automatic threat detection (that requires correlation rules and analytics)
- Real-time attack prevention
- Monitoring encrypted network traffic without additional tools
Mentioned in the news
- 1. AVG 2026. VPN je osumnjičenom sakrio adresu, ali je Windows zadržao oznaku uređaja →
- 28. JUL 2026. Microsoftov AI sam testira mrežu i krpi propuste →
- 17. JUL 2026. Ukoliko imate 7-Zip stariji od 26.02 — ažurirajte ga →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 12. JUL 2026. Apple tuži OpenAI za krađu poslovnih tajni — firmu koju je prethodno pustio u svoje uređaje →
- 11. JUL 2026. Metin novi AI alat koristi sadržaj javnih Instagram naloga za generisanje slika — bez pitanja korisnika →
- 11. JUL 2026. Uloga VPN aplikacije je da štiti privatnost korisnika, ali veliki broj njih to ne radi u potpunosti →
Threats
reduces 60Threats it reduces. Select one to open its page.
- Ransomware→
- Supply Chain Attack→
- Spear Phishing→
- Account Takeover→
- Phishing→
- Business Email Compromise→
- Backdoor→
- Insider Threat→
- Zero-Day Exploitation→
- Remote Code Execution→
- Trojan→
- Accidental Data Leak→
- Privilege Escalation→
- Credential stuffing→
- Shadow IT→
- Whaling→
- SMS phishing - Smishing→
- Remote access trojan - RAT→
- Botnet Attacks→
- Authentication Bypass→
- Loader / Dropper→
- Fileless malware→
- SQL Injection→
- Token Theft→
- Brute-force attack→
- Cryptominer→
- IoT Device Compromise→
- Session Hijacking→
- Spyware→
- API Abuse→
- Password spraying→
- Third-Party Compromise→
- Malvertising→
- SSRF→
- Shared Account Abuse→
- Pass-the-Hash→
- Cross-Site Scripting→
- Insecure Deserialization→
- MFA Fatigue→
- Ransom DDoS→
- Privilege Misuse→
- Model theft / extraction→
- Prompt injection→
- Contractor Abuse→
- DNS Amplification→
- Deepfake Attack→
- Denial of Service / DoS→
- Distributed Denial of Service / DDoS→
- Pretexting→
- Service Abuse→
- voice phishing - Vishing→
- Resource Exhaustion→
- SCADA/OT Attack→
- Kerberoasting→
- Physical Access Attack→
- BGP Hijacking→
- Cross-Site Request Forgery→
- DNS Poisoning→
- Dependency Confusion→
- Path Traversal→
Techniques
neutralizes 41Techniques it neutralizes. Select one to open its page.
- Credential Abuse→
- Data Exfiltration→
- Malware Delivery→
- Social Engineering→
- Phishing→
- Lateral Movement→
- Command & Control→
- Configuration Abuse→
- Privilege Escalation→
- Reconnaissance→
- Impair Defenses→
- Persistence→
- AiTM→
- Double Extortion→
- Automation & Scripting→
- Resource Exhaustion→
- Brute Force→
- Cloud lateral movement→
- Encrypted C2 Channels→
- Living off the Land→
- OSINT→
- Process Injection→
- Service Abuse→
- Website Defacement→
- Pass-the-Hash→
- DNS Tunneling→
- In-Memory Execution→
- DLL Sideloading→
- Supply Chain Compromise→
- Data Destruction→
- Indicator Removal→
- Network Sniffing→
- Domain Account Discovery→
- Log Tampering→
- Physical Access→
- Fast-Flux DNS→
- Forge Kerberos Tickets→
- Timestomping→
- Access Token Manipulation→
- Domain Fronting→
- Watering Hole→