Ravindra BagaleCourses & study guides

31. SOC, SIEM and Incident Response

31.1 What a SOC Is

A Security Operations Centre (SOC) is the team that watches an organisation's systems around the clock, detects attacks and responds to them.

Tier Role Typical work
L1 Alert monitoring / triage analyst Watches the SIEM dashboard, checks each alert, closes false positives, escalates real ones
L2 Incident responder Investigates escalated alerts deeply, contains the threat, collects evidence
L3 Threat hunter / senior analyst Hunts for hidden attackers, writes detection rules, handles major incidents
SOC manager Lead Processes, reporting, coordination with management and legal

Other terms you will hear: MSSP (a company that runs a SOC for many clients), playbook or runbook (step-by-step instructions for a type of alert), ticket (each alert or incident is tracked as a ticket), shift (SOCs often run 24x7 in shifts).

Ravindra Bagale's Tip

Freshers la vatte SOC mhanje fakt screen baghne. Nahi! L1 cha khara skill mhanje "he alert khara aahe ka khota?" he patkan tharavne. Tyasathi networking (Chapter 1-3), Linux logs (Chapter 5-6) ani attacks (Part 10) samjun ghene garjeche aahe. Je tumhi aadhi shiklat te ithe kamala yete.

Practice task

Write in your own words what an L1 analyst does when an alert "Multiple failed SSH logins from one IP" appears. List three questions they should answer before escalating.