What Is a SOC? What Does a SOC Analyst Do?
A Security Operations Centre (SOC) is the team and process that watch for cyber threats, triage alerts, contain damage and document decisions — often 24×7 in larger orgs. A SOC analyst investigates alerts from SIEM, EDR, email and cloud tools, follows playbooks, escalates when needed and writes clear notes. Tools matter; calm process and ownership matter more.
Friends! "I want a SOC job" — but what is a SOC? Not dashboard wallpaper. SOC = people + process + telemetry. Analyst = understand alert true/false, contain, escalate, document. Today: role map — L1/L2, Target-era lesson (alert existed but response was weak), ethics. SIEM deep dive is in a separate guide.
मित्रांनो! "SOC job पाहिजे" – पण SOC म्हणजे काय? Dashboard wallpaper नाही. SOC = people + process + telemetry. Analyst = alert समजून true/false, contain, escalate, document. आज role map – L1/L2, Target-era lesson (alert असला तरी response weak), ethics. SIEM deep dive अलग guide मध्ये आहे.
मित्रों! "SOC job चाहिए" – लेकिन SOC क्या है? Dashboard wallpaper नहीं. SOC = people + process + telemetry. Analyst = alert समझकर true/false, contain, escalate, document. आज role map – L1/L2, Target-era lesson (alert था फिर भी response weak), ethics. SIEM deep dive अलग guide में है.
Quick answer
SOC + analyst role in vertical lines:
- Collect signals (SIEM, EDR, email security, IdP, cloud audit, firewall).
- Triage the queue by severity, asset value and age.
- Investigate: what happened, which user/host, is it expected?
- Decide: false positive, true positive benign, or incident.
- Contain with playbooks (disable user, isolate host, block indicator).
- Escalate to L2 / IR / engineering when depth or blast radius grows.
- Document timeline, actions and detection gaps.
Tiny mental model:
Telemetry → Queue → Triage → Investigate → Contain / Close → Notes → Improve detection
No notes = tribal knowledge that vanishes on shift change
What do I need before this guide?
- Optional: What is SIEM?.
- Optional: Analyse a phishing email like a SOC analyst.
- Optional: IR first 24 hours.
What is a SOC?
Telemetry feeds the SOC queue. L1 analysts triage, contain or escalate, then document the decision.
Telemetry SOC queue ला feed करते. L1 analysts triage, contain किंवा escalate करतात, मग decision document करतात.
Telemetry SOC queue को feed करती है. L1 analysts triage, contain या escalate करते हैं, फिर decision document करते हैं.
A SOC is not only a dark room with screens. It is:
- Mission — detect and respond to threats affecting the organisation.
- People — analysts, detection engineers, IR leads, managers.
- Process — playbooks, severity definitions, escalation paths, SLAs.
- Technology — SIEM, EDR, SOAR, threat intel, ticketing.
- Metrics — mean time to detect / respond, false-positive rate, coverage gaps (honest ones).
Small companies may run a “virtual SOC” with two people and Microsoft 365 + EDR alerts — the role pattern is the same.
What does a SOC analyst do day to day?
Vertical L1 day:
- Join shift; read handoff notes from the previous analyst.
- Work the alert queue oldest-critical first.
- Open an alert; pull related events (same user, host, IP).
- Check change tickets / admin calendars for expected activity.
- Mark false positive with a real reason — or open an incident ticket.
- Run approved containment steps; page L2 when unsure.
- Write five-line notes: time (IST), asset, hypothesis, action, next check.
SOC tiers (simple)
- L1 — triage, known playbooks, quality notes.
- L2 — deeper investigation, malware / identity pivots, tuning suggestions.
- L3 / hunt / IR — major incidents, detection engineering, forensics liaison.
Fresher openings are often L1 — employers hire calm documentation as much as tool logos.
Real incident lesson: Target (2013) — alerts without effective response
Public reporting on the Target 2013 breach described security tools generating alerts that did not translate into effective containment in time. The lasting SOC lesson is organisational, not tool-brand:
- Signals without owners fail.
- Escalation paths must be practised, not only written.
- After-hours coverage and clear severity matter.
- Care-take — every critical alert class needs a named playbook and a human who can act.
- Care-take — tune noisy rules so analysts trust the queue.
Red Team vs Blue Team (SOC view)
Red Team — what attackers try (high level)
- Blend into normal admin activity.
- Move slowly to avoid threshold alerts.
- Disable or evade logging after a foothold.
Blue Team — how SOC responds
- Baseline “normal” for VIP users and crown-jewel hosts.
- Correlate identity + endpoint + email + cloud.
- Preserve evidence while containing.
- Feed lessons into better detections (Sigma / SIEM rules — see related guides).
How do I think like a beginner SOC analyst?
Step 1 — Learn the queue language
- Severity, priority, asset criticality, confidence.
- True positive vs false positive vs benign true positive.
- IOC (indicator) vs IOA (behaviour) — high-level awareness.
- SLA: how fast criticals must be touched.
Step 2 — Build a repeatable note template
- Alert name and time (IST + UTC if the ticket asks).
- User / host / source IP.
- What you checked (three pivots minimum).
- Decision and why.
- Actions taken and who you notified.
Step 3 — Practise on safe material
- Phishing sample triage (phishing SOC guide).
- Lab SIEM alerts you generate yourself (Wazuh-style labs in the SIEM guide).
- Never “practise” by attacking random internet hosts.
Step 4 — Know when to escalate
- Domain admin / global admin identity risk.
- Ransomware notes or mass encryption signals.
- Customer data exfiltration themes.
- Uncertainty after playbook steps — escalate early, not after hoping.
Step 5 — Soft skills companies actually hire
- Clear writing under time pressure.
- Asking for help without ego.
- Ethics: no peeking at data outside ticket need-to-know.
- Shift handoffs that spare the next analyst from rework.
Ravindra Bagale's Tip
💡 In interviews do not open with "I am a Splunk expert". Say: "L1 triage — I write the false-positive reason, follow the contain playbook, escalate when blast radius is large." Target-era lesson: a tool without an owner still fails. Keep lab notes PDF in the portfolio. Got the pattern? Stay alert!
Ravindra Bagale's Tip – मराठी
💡 Interview मध्ये "मी Splunk expert" पहिला बोलू नका. बोला: "L1 triage — false positive reason लिहतो, contain playbook follow करतो, escalate जदीत blast radius मोठा." Target-era lesson: tool असेल तरी owner नाही तर fail. Lab notes PDF portfolio मध्ये ठेवा. समजलं का pattern? ध्यान ठेवा!
Ravindra Bagale's Tip – हिंदी
💡 Interview में "मैं Splunk expert हूँ" पहले मत बोलो. बोलो: "L1 triage — false positive reason लिखता हूँ, contain playbook follow करता हूँ, escalate जब blast radius बड़ा." Target-era lesson: tool हो तब भी owner नहीं तो fail. Lab notes PDF portfolio में रखो. समझ में आया pattern? ध्यान रखो!
Quick vocabulary
- Playbook — step-by-step response for a known alert type.
- False positive — alert that fired but was not malicious.
- Containment — limit blast radius without destroying evidence.
- Handoff — shift notes so the next analyst continues cleanly.
- Detection debt — known gaps or noisy rules waiting for engineering time.
Sample L1 note (copy and adapt)
Time (IST): 2026-09-29 21:10
Alert: Impossible travel / rare country IdP login
User: a.shaikh@learnfast.example
Checks: MFA success? device new? VPN ticket? mailbox rules?
Decision: Escalate L2 — MFA success from new ASN + new inbox rule
Actions: Disabled session; ticket INC-1042; pages on-call
Next: L2 identity deep dive by 22:00 IST
Care-take — SOC hygiene
- Never close criticals with “looks fine” and zero notes.
- Do not delete evidence to “clean the disk” mid-incident.
- Follow privacy rules — analysts see sensitive data.
- Keep playbooks versioned; update after every major miss.
- Sleep and shift limits — exhausted analysts miss slow attacks.
- Detection debt backlog visible to management.
How do I fix common SOC beginner mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Alert fatigue | Untuned rules | Tune top noisy rules weekly with owners |
| “I closed it” with no ticket text | Rush culture | Mandatory five-line template |
| Same phishing wins weekly | No user feedback loop | Report metrics + short awareness notes |
| Escalation too late | Fear of bothering L2 | Written thresholds; praise early escalate |
| Tool worship | Resume keywords only | Practise process on one lab stack deeply |
| Ignoring cloud IdP alerts | “Not my queue” silo | Identity alerts are often the real start |
Try it at home
Paper SOC drill (no hacking):
- Write your five-line L1 note template.
- Pick three fictional alerts (failed VPN, new mailbox forward, EDR suspicious script) and decide close / contain / escalate with reasons.
- Read the phishing SOC guide and practise on a sample email you create yourself.
- List five log sources a tiny company should ship first.
- Do not scan or touch systems you do not own.
Learn it properly
Course lessons:
Related guides:
Got it? SOC = people + process + telemetry. Analyst = triage, contain, escalate, document. Notes and playbook beat tool logos. Do not forget the Target-era lesson. Next: learn incident report writing soft skill.
समजलं का? SOC = people + process + telemetry. Analyst = triage, contain, escalate, document. Tool logo पेक्षा notes आणि playbook. Target-era lesson विसरू नका. आता incident report writing soft skill शिका.
समझ में आया? SOC = people + process + telemetry. Analyst = triage, contain, escalate, document. Tool logo से notes और playbook. Target-era lesson मत भूलो. आगे incident report writing soft skill सीखो.
Frequently asked questions
What is a SOC?
The team and process that detect, triage and respond to cyber threats using telemetry and playbooks.
What does an L1 SOC analyst do?
Triages alerts, follows playbooks, documents decisions and escalates when needed.
Do I need Splunk to get hired?
Concepts transfer across SIEMs; proof of triage notes often beats logo lists.
What did Target 2013 teach SOCs?
Public lessons stressed that alerts without effective ownership and escalation still fail.
Is this offensive training?
No. Defensive operations and career orientation only.
Where are related guides?
SIEM, phishing SOC, Sysmon, IR 24h and incident report writing guides on this site.