Learning Outcome
4
Identify key technical and soft skills.
3
Differentiate between L1, L2, and L3 Analysts.
2
Describe daily SOC Analyst activities.
1
Explain SOC Analyst roles and responsibilities.
In a hospital emergency room, nurses continuously monitor patients and look for signs of trouble.
Patient monitoring = Security Monitoring
When a patient shows unusual symptoms, the nurse raises an alert and checks what may be wrong.
Unusual symptoms = Security Alert;
Checking the problem = Initial Investigation
The doctor examines the patient, reviews their condition, and determines how serious the problem is.
Doctor's examination = Alert Investigation and Threat Analysis
If the patient has a serious condition, the doctor involves a specialist for deeper treatment.
Specialist = Senior SOC Analyst / Tier 2 or Tier 3 Analyst;
Escalation = Incident Escalation
The hospital manager oversees the overall emergency operation and ensures everything runs smoothly.
Hospital manager = SOC Manager / Security Team Lead
Who is a SOC Analyst?
A SOC Analyst is a cybersecurity professional responsible for monitoring, detecting, investigating, and responding to security threats and incidents.
They act as a first line of defense by monitoring security systems and protecting networks, applications, systems, and data.
Importance of a SOC Analyst
Continuously monitor security events
Detect threats early
Respond quickly to incidents
Protect sensitive information
Support business continuity
Improve security posture
Purpose of a SOC Analyst
SOC Analysts help detect and respond to threats such as malware, phishing, ransomware, insider threats, and unauthorized access.
Monitor security events
Detect malicious activities
Investigate suspicious behavior
Reduce security risks
Support compliance requirements
Role in Protecting Digital Assets
SOC Analysts protect data, networks, applications, devices, and cloud resources by:
Preventing unauthorized access
Detecting malicious activities
Protecting confidential information
Supporting incident response
Core Roles of a SOC Analyst
Monitoring Security Events
Continuously monitor systems, networks, and security tools for unusual activities.
Failed login attempts
Unusual network traffic
Malware alerts
Unauthorized access
Detecting Threats
Analyze alerts and security events to identify threats such as:
Malware
Phishing
Brute-force attacks
Insider threats
Investigating Security Incidents
Analyze suspicious activities to determine the cause, scope, and impact.
Review logs
Examine alerts
Analyze network traffic
Collect evidence
Supporting Incident Response
Assist response teams in containing and mitigating incidents.
Identify affected systems
Gather incident information
Coordinate with response teams
Monitor recovery
Key Responsibilities
Security Monitoring
Monitor systems and networks for suspicious activities.
1
Alert Analysis
Review alerts and identify genuine threats.
2
Log Analysis
Analyze server, firewall, application, and security logs.
3
Threat Detection
Identify IOCs and signs of malicious activity.
4
Incident Investigation
Determine the cause and impact of incidents.
5
Incident Escalation
Escalate complex incidents to senior teams.
6
Daily Activities
Review security dashboards
Monitor SIEM alerts
Analyze logs
Investigate suspicious activities
Communicate with security teams
Security Team Hierarchy
Executive Leadership
CEO: Leads overall business strategy.
CFO: Manages finances and security budgets.
Company Owner: Sets organizational objectives and supports security initiatives.
Security Leadership
CISO: Leads cybersecurity strategy, policies, and risk management.
CIO: Oversees IT operations and technology investments.
CTO: Leads technology innovation and infrastructure.
Security Management
SOC Manager:
Manages SOC analysts
Oversees incident response
Reports security metrics
Improves SOC operations
Security Team Lead:
Coordinates daily activities
Supports analysts during investigations
Security Operations Team
SOC Analyst: Monitors and investigates security events.
Security Engineer: Designs and maintains security solutions.
Incident Responder: Handles active incidents and recovery.
Threat Hunter: Searches for hidden threats.
Penetration Tester: Tests systems for security weaknesses.
GRC Specialist: Manages Governance, Risk, and Compliance.
SOC Analyst Tier Structure
Tier 1 (L1): First point of contact for security alerts.
Monitor alerts
Perform initial investigation
Create and document ticketsa
Tier 2 (L2): Handles more complex investigations.
Analyze incidents
Validate threats
Support containment and remediation
Tier 3 (L3): Senior analysts handling advanced threats.
Investigate sophisticated attacks
Perform malware analysis
Conduct threat hunting
Skills Required for a SOC Analyst
Technical Skills
Soft Skills
Networking: IP, DNS, HTTP, protocols, and network communication
Log Analysis: Identify suspicious activities in logs
Operating Systems: Windows, Linux, and servers
Analytical thinking
Attention to detail
Problem-solving
Communication
Tools Used by SOC Analysts
Splunk,
IBM QRadar, Microsoft Sentinel
CrowdStrike Falcon, Microsoft Defender for Endpoint
Snort, Suricata
Palo Alto Networks, Fortinet,
Cisco Firepower
ServiceNow, Jira
SIEM
EDR
IDS/IPS
Firewalls
Ticketing
Challenges Faced by SOC Analysts
Alert Fatigue: Large numbers of alerts make genuine threats harder to identify.
False Positives: Alerts may indicate suspicious activity without being actual incidents.
Large Data Volumes: Massive amounts of logs require continuous analysis.
Evolving Threats: New attack techniques require analysts to stay updated.
Career Path of a SOC Analyst
Summary
5
SOC Analysts support cybersecurity and business continuity.
4
Analysts are divided into L1, L2, and L3 based on expertise.
3
SOC teams have leadership, management, and operational levels.
2
They protect digital assets and reduce cybersecurity risks.
1
SOC Analysts monitor, detect, investigate, and respond to threats.
Quiz
Which SOC Analyst tier performs the initial investigation of alerts?
B. L2 Analyst
C. L1 Analyst
D. SOC Manager
A. L3 Analyst
Quiz-Answer
C. L1 Analyst
Which SOC Analyst tier performs the initial investigation of alerts?
A. L3 Analyst
B. L2 Analyst
D. SOC Manager