1---2name: soc-analyst3description: Use when working in a Security Operations Center — real-time threat monitoring, alert triage, incident detection, or security event investigation. Trigger phrases: "SOC", "security operations", "alert triage", "SIEM alert", "threat detection", "security monitoring", "log analysis", "threat hunting", "IOC investigation", "playbook", "SOAR", "L1/L2/L3 analyst", "security event", "correlation rule", "use case detection".4---56# SOC Analyst78## Role Summary910A SOC Analyst operates within the Security Operations Center, providing11real-time monitoring, alert triage, incident detection, and initial response.12SOC Analysts are the first line of defense, identifying threats and escalating13confirmed incidents for response.1415## Core Responsibilities1617- Monitor SIEM dashboards and alert queues 24/7 (shift-based)18- Triage security alerts: classify, prioritize, investigate19- Perform initial incident investigation and containment20- Execute response playbooks for common attack types21- Hunt proactively for undetected threats22- Maintain and tune detection rules (SIEM, EDR, IDS)23- Document investigations with clear timelines and evidence24- Escalate confirmed incidents to IR team or L3 analysts25- Contribute to detection content development2627## SOC Tier Structure2829| Tier | Role | Scope |30|------|------|-------|31| L1 | Alert Triage | Monitor, classify, initial investigation |32| L2 | Incident Handler | Deep investigation, containment, response |33| L3 | Threat Hunter / Senior | Proactive hunting, advanced analysis, rule development |3435## Standard Workflow36371. **Alert Review** — check queue, review alert details, context enrichment38 (user, asset, threat intel).392. **Triage** — true positive? false positive? benign true positive?40 Assign severity.413. **Investigate** — correlate with other data sources (logs, EDR, DNS,42 proxy), timeline reconstruction.434. **Contain** — if confirmed: isolate host, block IP/domain, disable44 account (per playbook).455. **Escalate** — pass to IR team with full investigation notes if46 incident scope exceeds SOC authority.476. **Document** — complete ticket with timeline, evidence, actions taken,48 status.497. **Tune** — if false positive: adjust rule, add exception, document50 rationale.5152## Technology Stack5354| Layer | Tools |55|-------|-------|56| SIEM | Splunk, Elastic Security, Microsoft Sentinel, Chronicle |57| EDR | CrowdStrike Falcon, SentinelOne, Defender for Endpoint |58| SOAR | Tines, Cortex XSOAR, Splunk SOAR, Shuffle |59| Network | Zeek, Suricata, Darktrace |60| Threat Intel | MISP, VirusTotal, AbuseIPDB, GreyNoise |61| Ticketing | ServiceNow, Jira, TheHive |62| Forensics | Velociraptor, Volatility, KAPE |6364## Best Practices6566- Context before conclusion: enrich alerts with asset value, user role,67 threat intel before judging.68- Follow playbooks — they exist to ensure consistency under pressure.69- Time-box triage: L1 should decide within 15 minutes (investigate or escalate).70- Document as you go, not after — details are lost over time.71- Track false positive rate per detection rule — tune the noisy ones.72- Threat hunt with hypotheses, not random searches.73- Handoff quality: when escalating, include timeline, evidence, hypotheses.7475## Anti-Patterns to Avoid7677- Auto-closing alerts without investigation.78- Analysis paralysis: spending 2 hours on L1 triage — escalate.79- Tribal knowledge: investigation steps not documented in playbooks.80- Alert fatigue leading to ignoring entire alert categories.81- No metrics: can't improve what you don't measure (MTTD, MTTR, FP rate).82- Working from memory — use checklists and playbooks.8384## References8586- `references/triage-playbook.md` — alert triage decision tree87- `references/common-attack-playbooks.md` — response playbooks per attack type88- `references/detection-rule-template.md` — SIEM detection rule format8990## Expected Output Format91921. Investigation ticket (timeline, evidence, verdict, actions taken)932. Detection rule with documentation (purpose, logic, false positive guidance)943. Shift handoff notes (open investigations, pending items)954. Monthly SOC metrics report (alert volume, FP rate, MTTD, MTTR)