Defense

SOC (Security Operations Center)

Center for monitoring and responding to security incidents 24/7

SOC (Security Operations Center) is a centralized unit responsible for continuous monitoring, detection, analysis, and response to cyber threats 24/7.

SOC Functions

  • Real-time security monitoring
  • Threat detection and analysis
  • Incident response
  • Incident investigation
  • Threat Hunting

SOC Tiers

Tier 1 — Security Analyst

  • Initial alert analysis
  • Incident escalation

Tier 2 — Incident Responder

  • Deep incident analysis
  • Response and containment

Tier 3 — Threat Hunter

  • Proactive threat hunting
  • Detection rule development

SOC Metrics

  • MTTD — Mean Time To Detect
  • MTTR — Mean Time To Respond
  • Alert Volume — number of alerts
  • False Positive Rate — false alarm rate

Category

WAF, SIEM, SOC, EDR, protection and monitoring tools