Eight chapters covering how a Security Operations Center actually runs day to day: analyst tiers and shift models, alert triage and prioritization, the SIEM and SOAR pipeline behind every alert, incident handling workflow and escalation, case management and documentation discipline, and the metrics that show whether any of it is working. Built for analysts moving from "what does this alert mean" to "how does this whole operation function," and for anyone preparing for their first SOC role.
No chapters match “”.
What a SOC does and why it exists, the L1/L2/L3 analyst tier model, in-house versus MSSP delivery models, and the shift patterns that keep a SOC running around the clock.
The alert lifecycle, severity versus priority scoring, why alert fatigue happens and what fights it, disposition vocabulary, and a practical triage runbook walkthrough.
SIEM architecture from collection to correlation, which log sources to onboard first, correlation rules versus behavioral analytics, and the detection content lifecycle.
What SOAR adds on top of a SIEM, playbook anatomy, orchestration versus full automation, common enrichment patterns, and the real risks of over-automating response.
The SOC-scoped incident workflow from confirmation through initial containment and handoff, escalation paths across analyst tiers, severity-based communication, and handing off an active incident across shifts.
Why documentation matters to a SOC, the ticket lifecycle, what good investigation notes look like, disposition and closure codes, and common documentation pitfalls.
Why metrics matter to a SOC, the core time-based metrics (MTTD, MTTA, MTTR), coverage metrics mapped to ATT&CK, SOC maturity models, and common metrics pitfalls.
Roles beyond L1-L3, burnout causes and mitigation, purple teaming as a bridge into technique-focused work, and career paths and certifications.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
Daily workflow queries across auth, network, endpoint, and cloud. Built for the fast, repeatable lookups a Tier 1 analyst runs during the triage pass covered in Chapter 2.
Detection rule library across KQL, Sigma, and XQL. A direct source of the correlation-rule content the SIEM pipeline in Chapter 3 depends on.
Multi-source IOC analysis across VirusTotal, Shodan, OTX, and AbuseIPDB. Exactly the kind of enrichment lookup a SOAR playbook automates, as covered in Chapter 4.
A 7-step phishing investigation tracker with a live IOC aggregator, a working example of the case management and disposition discipline covered in Chapter 6.