SOC Level 1 (L1) Analyst – Practical Handbook
1. Role Overview
• First line of defense in Security Operations Center (SOC)
• 24x7 monitoring of SIEM, EDR, Email, Cloud and Network alerts
• Initial triage, validation, and basic containment
• Escalate confirmed threats to L2/L3 or Incident Response
2. Daily Responsibilities
• Monitor dashboards and alerts continuously
• Classify alerts: True Positive / False Positive / Benign
• Perform initial investigation and evidence collection
• Follow SOPs and playbooks
• Document findings and update tickets
• Escalate suspicious activity quickly
3. Investigation Checklist
• Check alert source and severity
• Review timestamp and affected host/user
• Analyze IP, domain, hash reputation
• Validate logs and process behavior
• Correlate events in SIEM
• Decide: close or escalate
4. Core Tools to Master
• SIEM: Splunk / QRadar / Sentinel
• EDR/XDR: CrowdStrike / Defender / Cortex
• Email Security: Mimecast / Proofpoint
• Threat Intel: VirusTotal / AbuseIPDB
• Ticketing: ServiceNow / Jira
5. Common Alert Types
• Phishing or malicious email
• Malware detection
• Brute force or login anomalies
• Suspicious PowerShell or command execution
• Data exfiltration attempts
• Web or proxy malicious traffic
6. Basic Commands for L1 (Linux/Windows)
• Windows: tasklist, netstat -ano, ipconfig, whoami, dir
• Linux: ps aux, netstat -tulnp, top, cat, grep, tail -f
• Check running processes and network connections
• Collect logs and artifacts safely
7. Escalation Criteria
• Confirmed malware or ransomware behavior
• Credential compromise or lateral movement
• Data exfiltration indicators
• Multiple hosts impacted
• High severity alerts or business impact
8. Documentation Best Practices
• Clear summary of issue
• Timeline of events
• Evidence collected
• Actions performed
• Final decision with reason
9. Daily Skill Improvement Plan
• Practice log analysis daily
• Study one new detection rule every day
• Reproduce attacks in lab (AWS + Ubuntu)
• Learn MITRE ATT&CK; mapping
• Review previous incidents
10. Career Path
• SOC L1 → SOC L2 → SOC L3 → Incident Response → SOC Manager
• Focus on investigation depth, automation and threat hunting
• Develop scripting skills (Python/PowerShell)
End of Guide. Practice daily to become an expert SOC analyst.