01 - Introduction to SOC Operations
A **Security Operations Center (SOC)** is a centralized function within an organization employing people, processes, and technology to continuously mo...
02 - Alert Triage and Investigation
When a SIEM or EDR tool triggers an alert, the Tier 1 analyst executes a structured workflow to determine its validity.
03 - SOC Automation and SOAR
SOAR platforms aim to reduce the manual workload on Tier 1 analysts by automating repetitive tasks, enriching alerts with threat intelligence, and exe...
04 - Threat Hunting Methodology
Threat hunting is the proactive, iterative process of searching through networks and datasets to detect and isolate advanced threats that evade existi...
05 - SOC Tooling and Dashboards
Building a highly effective SOC doesn't require millions of dollars in licensing. Many organizations start with or heavily utilize open-source and fre...
06 - Hands-on Lab: Automated Alert Triage
In this self-contained lab, we will build a Python-based SOC Alert Enricher. It simulates receiving an alert containing an IP address, queries a (simu...
07 - References and Further Reading
Comprehensive security guide and practical technical implementation handbook.
Security Operations Center (SOC) Operations Guide
Welcome to the **SOC Operations Guide**. A Security Operations Center (SOC) is the nerve center of an organization's defensive posture, responsible fo...