0% found this document useful (0 votes)
22 views2 pages

SOC L2 Quick Guide

The SOC Level 2 Analyst serves as the primary escalation point for SOC Level 1, focusing on deep investigation and containment of medium to high severity incidents. Key responsibilities include advanced log correlation, endpoint forensics, and threat investigation, while utilizing tools like SIEM and EDR/XDR. The role emphasizes automation, building detections, and preparing for advanced incident response and threat hunting roles.

Uploaded by

kirtikashyap761
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
22 views2 pages

SOC L2 Quick Guide

The SOC Level 2 Analyst serves as the primary escalation point for SOC Level 1, focusing on deep investigation and containment of medium to high severity incidents. Key responsibilities include advanced log correlation, endpoint forensics, and threat investigation, while utilizing tools like SIEM and EDR/XDR. The role emphasizes automation, building detections, and preparing for advanced incident response and threat hunting roles.

Uploaded by

kirtikashyap761
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SOC Level 2 (L2) Analyst – Quick Guide

Role Summary

• Primary escalation point for SOC L1

• Deep investigation, validation, and containment of threats

• Ownership of medium and high severity incidents

• Decision maker for escalation to IR/L3

Core Responsibilities

• Advanced log correlation in SIEM

• EDR/XDR endpoint forensics and process analysis

• Phishing, malware, and lateral movement investigations

• Host isolation and response actions

• Root cause analysis and impact assessment

Daily Workflow

• Review escalated alerts

• Collect evidence (logs, processes, hashes, network data)

• Confirm True Positive or False Positive

• Contain threat and recommend remediation

• Document and close or escalate

Tools to Master

• SIEM: Splunk / Sentinel / QRadar

• EDR/XDR: CrowdStrike / Defender / Cortex

• Threat Intel: VirusTotal / MISP

• Email & Cloud security platforms

• Ticketing: ServiceNow / Jira

Investigation Skills

• Process tree analysis

• Command-line behavior analysis


• MITRE ATT&CK; mapping

• IOC hunting and threat hunting basics

• Log parsing and timeline building

Escalate When

• Ransomware or active compromise detected

• Multiple hosts/users impacted

• Data exfiltration suspected

• Privilege escalation or domain compromise

Quick Career Focus

• Automate tasks with Python/PowerShell

• Build detections and use cases

• Practice AWS + Ubuntu lab simulations

• Prepare for Incident Response and Threat Hunting roles

Goal: Become fast, accurate, and ownership-driven. Think like an attacker, respond like a defender.

You might also like