B13.2 What SOC Analysts Do
Learn how security operations center analysts review alerts, gather evidence, distinguish suspicious activity from normal behavior, document cases, follow playbooks, and escalate incidents.
Lesson Progress
What SOC Analysts Do
High School Beginner • B13: Cybersecurity Careers and Certifications • Lesson 2 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
SOC Analysts Turn Noisy Alerts Into Defensible Decisions
Security tools may generate thousands of alerts. Analysts must decide which ones are urgent, which need more evidence, which are explained by approved activity, and which should be escalated to incident responders or specialists.
Learning Objective
Explain alert triage, evidence review, case documentation, playbooks, escalation, and closure.
Learning Objective
Distinguish high-priority evidence from harmless or approved activity.
Learning Objective
Write clear fictional case notes that another analyst could understand and continue.
Why This Matters
Fast but Unsupported Decisions Can Create More Risk
Closing a real incident too early can leave an organization exposed. Escalating every harmless alert wastes time. Strong SOC work depends on evidence, context, clear notes, and appropriate authority.
Visual Diagram
The Beginner SOC Workflow
SOC analysts move from alert intake to evidence review, documented decisions, and appropriate escalation or closure.
Receive and prioritize
Review the alert source, severity, asset, user, time, and possible business impact.
Gather evidence
Compare approved logs, account activity, device events, tickets, and known context.
Decide and document
Record what the evidence supports, what remains uncertain, and which action is justified.
Escalate or close
Send important cases to the correct response team or close explained alerts with clear notes.
Core Concept
Triage Is Structured Reasoning Under Time Pressure
Analysts review the alert source, affected asset, user, timing, severity, related events, business context, and known changes. They then document what the evidence supports and choose the safest next step.
Key Vocabulary
Terms for Security Operations
Security operations center
A team or function that monitors security events, reviews alerts, investigates evidence, documents findings, and supports incident response.
Alert triage
The first review used to decide an alert's priority, relevance, possible impact, and next action.
False positive
An alert that appears suspicious but is explained by normal, approved, or harmless activity.
Escalation
Passing an alert or incident to a person or team with the authority, expertise, or responsibility to continue the response.
Case notes
Clear documentation of evidence, actions, decisions, timestamps, owners, and unresolved questions.
Playbook
An approved set of response steps for a common alert or incident type.
Professional Decision-Making
SOC Analyst Decision Board
Strong analysts balance speed with accuracy, evidence with context, and independent work with timely escalation.
Priority
Review question
Which asset, user, data, service, or business process could be affected?
Strong analyst action
Prioritize based on evidence, exposure, criticality, scope, and time sensitivity.
Evidence
Review question
Which approved logs, tickets, account events, device alerts, or owner confirmations explain the activity?
Strong analyst action
Gather enough trusted context to support the next decision without altering evidence.
Documentation
Review question
Could another analyst understand what happened and continue the case?
Strong analyst action
Record timestamps, evidence, actions, reasoning, owners, and unanswered questions clearly.
Escalation
Review question
Does the case exceed the analyst's authority, skill, scope, or response playbook?
Strong analyst action
Escalate promptly to the correct team with organized evidence and a clear summary.
Fake SOC Dashboard
Alert Triage Review Panel
This fictional panel compares alerts, evidence, business context, likely explanations, and response decisions.
Unusual login alert
New location, expected user, successful MFA, approved travel
Document the context and decide whether the alert can be safely closed or requires more verification.
Malware warning
Security tool blocks a suspicious file on a managed laptop
Preserve evidence, isolate through approved procedures, and escalate to incident response.
Repeated failed logins
Many attempts against one account from unfamiliar sources
Check account ownership, timing, source pattern, lockout status, and related alerts.
Policy violation
Approved software installed outside the normal maintenance window
Verify the change ticket and avoid treating unusual timing as automatic malicious activity.
Resolved alert
Normal scheduled backup caused high network activity
Close with evidence, owner confirmation, and a clear explanation for future analysts.
Fake Dashboard
Fake SOC Shift Dashboard
Training dashboard using fictional alerts, assets, users, tickets, severity labels, evidence, and case decisions.
Alerts reviewed
38
Fictional identity, endpoint, email, network, cloud, and policy alerts.
Escalated cases
7
Evidence or impact required incident response or specialist review.
Explained alerts
23
Approved changes, normal behavior, scheduled tasks, or duplicate detections.
Fake SOC Alert
Multiple Failed Logins Followed by a Successful MFA Login
Source: Fake Identity Monitoring • Time: 8:42 AM
Fake Log Panel
Fake SOC Investigation Log
08:14:03 ALERT type='failed_logins' user='student_portal_admin' 08:17:28 SOURCE attempts='18' locations='multiple_unfamiliar' 08:22:11 AUTH success='true' mfa='approved' location='new' 08:27:46 USER_CONTEXT travel='not_documented' change_ticket='none' 08:33:19 RELATED_ALERT endpoint='new_device' email='none' 08:38:54 DECISION severity='high' escalation='identity_response' 08:42:06 CASE notes='completed' owner='soc_shift_lead'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Should This Alert Be Closed or Escalated?
What is the safest analyst decision?
Common Mistakes
Mistakes That Weaken SOC Work
Safe Career Lab
Triage a Fictional SOC Alert Queue
Fake Alert Queue
Beginner SOC Shift
A fictional analyst reviews unusual login, blocked malware, scheduled backup traffic, after-hours software installation, public-link exposure, and repeated password-reset alerts.
Analyst Review Steps
- Identify the alert source, asset, user, time, and severity.
- Review trusted context and related evidence.
- Separate facts, assumptions, and unanswered questions.
- Choose close, monitor, investigate, or escalate.
- Write clear case notes and identify the next owner.
- Follow approved playbooks and protect all evidence.
Scenario Decision Lab
A High-Severity Alert Has an Approved Explanation
A fictional high-severity network alert occurs during a documented backup test approved by the infrastructure team.
Scenario Decision Lab
A Malware Alert Appears on a Managed Laptop
A fictional endpoint tool blocks a suspicious file and reports that the user attempted to open it.
Defender Habits
SOC Analyst Checklist
Check Your Understanding
B13.2 Mini Quiz: What SOC Analysts Do
Choose your answers first. Explanations appear only after submission.
1. What is alert triage?
2. What is a false positive?
3. Why are case notes important?
4. When should an alert be escalated?
5. What should a SOC analyst never request from a user?
Portfolio Prompt
Portfolio Prompt
Create a one-page fictional SOC case report. Include alert summary, affected asset, user, timeline, severity, evidence, business context, facts, assumptions, unanswered questions, decision, escalation path, and final case notes.
Key Takeaways
What You Should Remember
Navigation