All Modules SOC OPERATIONS

SOC Operations · Complete Guide

Eight chapters covering how a Security Operations Center actually runs day to day: analyst tiers and shift models, alert triage and prioritization, the SIEM and SOAR pipeline behind every alert, incident handling workflow and escalation, case management and documentation discipline, and the metrics that show whether any of it is working. Built for analysts moving from "what does this alert mean" to "how does this whole operation function," and for anyone preparing for their first SOC role.

8 CHAPTERS
~11 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
SOC tiers alert triage SIEM SOAR incident handling case management MTTD / MTTR career paths

ALL CHAPTERS

/
01
BEGINNER 25 min

SOC Foundations: Mission, Tiers & Shift Models

What a SOC does and why it exists, the L1/L2/L3 analyst tier model, in-house versus MSSP delivery models, and the shift patterns that keep a SOC running around the clock.

SOC tiers shift models SOC vs NOC
02
BEGINNER 30 min

Alert Triage & Prioritization

The alert lifecycle, severity versus priority scoring, why alert fatigue happens and what fights it, disposition vocabulary, and a practical triage runbook walkthrough.

alert triage severity scoring alert fatigue
03
INTERMEDIATE 35 min

SIEM & Log Management

SIEM architecture from collection to correlation, which log sources to onboard first, correlation rules versus behavioral analytics, and the detection content lifecycle.

SIEM log management correlation rules
04
INTERMEDIATE 35 min

SOAR & Automation

What SOAR adds on top of a SIEM, playbook anatomy, orchestration versus full automation, common enrichment patterns, and the real risks of over-automating response.

SOAR playbooks automation
05
INTERMEDIATE 30 min

Incident Handling Workflow

The SOC-scoped incident workflow from confirmation through initial containment and handoff, escalation paths across analyst tiers, severity-based communication, and handing off an active incident across shifts.

incident handling escalation communication
06
INTERMEDIATE 30 min

Case Management & Documentation

Why documentation matters to a SOC, the ticket lifecycle, what good investigation notes look like, disposition and closure codes, and common documentation pitfalls.

case management documentation ticketing
07
ADVANCED 30 min

Metrics & KPIs

Why metrics matter to a SOC, the core time-based metrics (MTTD, MTTA, MTTR), coverage metrics mapped to ATT&CK, SOC maturity models, and common metrics pitfalls.

metrics KPIs SOC maturity
08
ADVANCED 30 min

SOC Team Structure & Career Growth

Roles beyond L1-L3, burnout causes and mitigation, purple teaming as a bridge into technique-focused work, and career paths and certifications.

SOC roles career growth purple teaming

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • No prior SOC experience required, Chapter 1 builds the tier model and terminology from scratch
  • Basic security fundamentals help (the Fundamentals module is a good starting point if any of that feels unfamiliar)
  • General awareness of what a SIEM and MITRE ATT&CK are is useful but not assumed going in
  • No coding or query-language experience required, this module covers workflow and process, not query syntax

WHAT YOU WILL KNOW AFTER

  • How a SOC is structured across analyst tiers, delivery models, and shift coverage
  • How to triage and prioritize an alert queue, and why alert fatigue happens
  • How a SIEM's collection-to-correlation pipeline actually works, and what SOAR adds on top of it
  • How to run an incident through escalation and communication without confusing SOC-scoped handling with full incident response
  • What good case documentation looks like, and the disposition codes a SOC uses to close a ticket
  • How to read MTTD, MTTA, and MTTR, and why metrics need to be paired with quality checks to avoid being gamed
  • What roles a SOC career grows into beyond L1-L3, and which certifications map to which stage

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.