31. SOC, SIEM and Incident Response
31.1 What a SOC Is
A Security Operations Centre (SOC) is the team that watches an organisation's systems around the clock, detects attacks and responds to them.
| Tier | Role | Typical work |
|---|---|---|
| L1 | Alert monitoring / triage analyst | Watches the SIEM dashboard, checks each alert, closes false positives, escalates real ones |
| L2 | Incident responder | Investigates escalated alerts deeply, contains the threat, collects evidence |
| L3 | Threat hunter / senior analyst | Hunts for hidden attackers, writes detection rules, handles major incidents |
| SOC manager | Lead | Processes, reporting, coordination with management and legal |
Other terms you will hear: MSSP (a company that runs a SOC for many clients), playbook or runbook (step-by-step instructions for a type of alert), ticket (each alert or incident is tracked as a ticket), shift (SOCs often run 24x7 in shifts).
Ravindra Bagale's Tip
Freshers la vatte SOC mhanje fakt screen baghne. Nahi! L1 cha khara skill mhanje "he alert khara aahe ka khota?" he patkan tharavne. Tyasathi networking (Chapter 1-3), Linux logs (Chapter 5-6) ani attacks (Part 10) samjun ghene garjeche aahe. Je tumhi aadhi shiklat te ithe kamala yete.
Practice task
Write in your own words what an L1 analyst does when an alert "Multiple failed SSH logins from one IP" appears. List three questions they should answer before escalating.