0% found this document useful (0 votes)
41 views3 pages

SOC L1 Analyst Guide

The SOC Level 1 Analyst Handbook outlines the responsibilities and skills required for the first line of defense in a Security Operations Center, including continuous monitoring, initial triage, and escalation of threats. It provides a checklist for investigations, common alert types, core tools to master, and escalation criteria. Additionally, it emphasizes the importance of documentation, daily skill improvement, and potential career progression within the SOC framework.

Uploaded by

kirtikashyap761
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
41 views3 pages

SOC L1 Analyst Guide

The SOC Level 1 Analyst Handbook outlines the responsibilities and skills required for the first line of defense in a Security Operations Center, including continuous monitoring, initial triage, and escalation of threats. It provides a checklist for investigations, common alert types, core tools to master, and escalation criteria. Additionally, it emphasizes the importance of documentation, daily skill improvement, and potential career progression within the SOC framework.

Uploaded by

kirtikashyap761
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SOC Level 1 (L1) Analyst – Practical Handbook

1. Role Overview

• First line of defense in Security Operations Center (SOC)

• 24x7 monitoring of SIEM, EDR, Email, Cloud and Network alerts

• Initial triage, validation, and basic containment

• Escalate confirmed threats to L2/L3 or Incident Response

2. Daily Responsibilities

• Monitor dashboards and alerts continuously

• Classify alerts: True Positive / False Positive / Benign

• Perform initial investigation and evidence collection

• Follow SOPs and playbooks

• Document findings and update tickets

• Escalate suspicious activity quickly

3. Investigation Checklist

• Check alert source and severity

• Review timestamp and affected host/user

• Analyze IP, domain, hash reputation

• Validate logs and process behavior

• Correlate events in SIEM

• Decide: close or escalate

4. Core Tools to Master

• SIEM: Splunk / QRadar / Sentinel

• EDR/XDR: CrowdStrike / Defender / Cortex

• Email Security: Mimecast / Proofpoint

• Threat Intel: VirusTotal / AbuseIPDB

• Ticketing: ServiceNow / Jira

5. Common Alert Types


• Phishing or malicious email

• Malware detection

• Brute force or login anomalies

• Suspicious PowerShell or command execution

• Data exfiltration attempts

• Web or proxy malicious traffic

6. Basic Commands for L1 (Linux/Windows)

• Windows: tasklist, netstat -ano, ipconfig, whoami, dir

• Linux: ps aux, netstat -tulnp, top, cat, grep, tail -f

• Check running processes and network connections

• Collect logs and artifacts safely

7. Escalation Criteria

• Confirmed malware or ransomware behavior

• Credential compromise or lateral movement

• Data exfiltration indicators

• Multiple hosts impacted

• High severity alerts or business impact

8. Documentation Best Practices

• Clear summary of issue

• Timeline of events

• Evidence collected

• Actions performed

• Final decision with reason

9. Daily Skill Improvement Plan

• Practice log analysis daily

• Study one new detection rule every day

• Reproduce attacks in lab (AWS + Ubuntu)

• Learn MITRE ATT&CK; mapping

• Review previous incidents


10. Career Path

• SOC L1 → SOC L2 → SOC L3 → Incident Response → SOC Manager

• Focus on investigation depth, automation and threat hunting

• Develop scripting skills (Python/PowerShell)

End of Guide. Practice daily to become an expert SOC analyst.

You might also like