SOC Level 2 (L2) Analyst – Quick Guide
Role Summary
• Primary escalation point for SOC L1
• Deep investigation, validation, and containment of threats
• Ownership of medium and high severity incidents
• Decision maker for escalation to IR/L3
Core Responsibilities
• Advanced log correlation in SIEM
• EDR/XDR endpoint forensics and process analysis
• Phishing, malware, and lateral movement investigations
• Host isolation and response actions
• Root cause analysis and impact assessment
Daily Workflow
• Review escalated alerts
• Collect evidence (logs, processes, hashes, network data)
• Confirm True Positive or False Positive
• Contain threat and recommend remediation
• Document and close or escalate
Tools to Master
• SIEM: Splunk / Sentinel / QRadar
• EDR/XDR: CrowdStrike / Defender / Cortex
• Threat Intel: VirusTotal / MISP
• Email & Cloud security platforms
• Ticketing: ServiceNow / Jira
Investigation Skills
• Process tree analysis
• Command-line behavior analysis
• MITRE ATT&CK; mapping
• IOC hunting and threat hunting basics
• Log parsing and timeline building
Escalate When
• Ransomware or active compromise detected
• Multiple hosts/users impacted
• Data exfiltration suspected
• Privilege escalation or domain compromise
Quick Career Focus
• Automate tasks with Python/PowerShell
• Build detections and use cases
• Practice AWS + Ubuntu lab simulations
• Prepare for Incident Response and Threat Hunting roles
Goal: Become fast, accurate, and ownership-driven. Think like an attacker, respond like a defender.