Security Operations Center (SOC) Operations Guide
Overview
Welcome to the SOC Operations Guide. A Security Operations Center (SOC) is the nerve center of an organization's defensive posture, responsible for continuous monitoring, detection, and response to cybersecurity threats. This guide explores the architecture of modern SOC operations, practical incident triage techniques, threat hunting methodologies, and SOC automation (SOAR) principles.
Prerequisites
Before diving into SOC Operations, you should have:
- Basic understanding of enterprise networking (TCP/IP, DNS, HTTP)
- Familiarity with operating system internals (Windows and Linux)
- Conceptual understanding of common cyber attacks (e.g., Phishing, Malware, Credential Dumping)
- Basic Python scripting skills (for the automation and SOAR labs)
Learning Objectives
By the end of this module, you will be able to:
- Understand the tiered structure of a SOC and essential performance metrics (MTTD, MTTR).
- Execute an alert triage workflow and distinguish true positives from false positives.
- Leverage MITRE ATT&CK frameworks to contextualize alerts and incidents.
- Implement automated alert enrichment using Python (SOAR principles).
- Conduct hypothesis-driven threat hunts using SIEM queries (KQL, Sigma).
- Deploy and operate open-source SOC tools (Wazuh, MISP, Shuffle).
Navigation
| Chapter | Description |
|---|---|
| 01 - Introduction | SOC Structure, Tiers (1/2/3), and Core Metrics (MTTD/MTTR) |
| 02 - Alert Triage & Investigation | Workflow, Playbooks, True Positives vs. False Positives |
| 03 - SOC Automation & SOAR | SOAR workflows, Automated Enrichment, Python scripts |
| 04 - Threat Hunting | Hypothesis-driven hunting, Persistence mechanisms, KQL/Sigma |
| 05 - Tooling & Dashboards | Wazuh, Shuffle SOAR, MISP, OpenSearch, Dashboarding |
| 06 - Hands-On Lab | Python SOC Alert Enricher and Automated Triage Pipeline |
| 07 - References | Frameworks, Documentations, and Reading Materials |