> For the complete documentation index, see [llms.txt](https://cyber-reaper.gitbook.io/my-soc-analyst-guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cyber-reaper.gitbook.io/my-soc-analyst-guide/security-operations-fundemantals/readme.md).

# The SOC and Its Role

## What is a SOC

**SOC** (stands for Security and Operations Center) is a centralized unit withing an organization that deals with security issues, incidents, and events.

Primary objectives of a **SOC**:

1. Minimize the impact of cyber-attacks.
2. Protect sensitive data.
3. Ensure meeting CIA triad of the organization's assets.

**SOC** can vary between organizations based on their:

1. Size
2. Industry
3. Budget
4. Maturity Level

***

## What SOC teams do

**SOC** members collaborate together to:

1. **Monitor**
   1. Continuous observation for unusual activity.
   2. Utilization of monitoring tools (IDS, SIEM, etc.) for real-time visibility.
   3. Early detections of potential security threats.
2. **Detect**\
   Once potential security incidents are identified through monitoring, SOC analyst employs various detection techniques to confirm
   1. Confirm security events identified during monitoring.
   2. Utilize threat detection techniques.
   3. Identify known indicators of compromise (IOCs).
3. **Analyze**
   1. Perform in-depth investigations to understand security incidents.
   2. Examine affected systems, build a timeline of events.
   3. Trace tactics, techniques, and procedures (TTPs)
4. **Respond**
   1. Formulate a response plan based on findings.
   2. Contain threats, mitigate impact, and restore normal operations.
   3. Collaborate with internal teams and stakeholders.

<figure><img src="https://640280274-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTzv07YfbRoOaw7kmThoN%2Fuploads%2FgP7LyDPr0R1vRylIh4rU%2Fimage.png?alt=media&amp;token=e816d4a5-8eeb-467a-b635-fcc6c1fb401e" alt="" width="298"><figcaption></figcaption></figure>

***

## The evolution of the SOC

For a pretty long time, SOC has been imagined as a giant room filled with rows of desks and hundreds of screens and a bunch of analysts sitting shoulder-to-shoulder.

However, as the modern SOC evolved especially in the wake of things like the rise of remote work and the digital transformation of businesses, the old picture of the SOC is no longer as common.

Instead, the concept of a centralized SOC has undergone a transformation. So, rather than a physical room housing a large team of analysts, today's SOC is increasingly virtualized and distributed in many cases. This became with the advancement of cloud technology and virtual private networks and collaboration platforms and now SOC teams are able to operate from almost anywhere in the world without the need for a centralized physical location.

Also, the concept of a SOC has evolved over time, also the priorities and functions within a SOC have shifted to meet the changing landscape of threats and challenges.

At a high level we can notice the changes from a primary focus on the **Availability Monitoring** to more **Reactive Monitoring** to **Proactive Monitoring** and now to a **Proactive Automation.**

***

## What forms a SOC

1. **People**\
   The personnel withing a SOC that forms the human element or the backbone of operations.\
   It includes analysts, responders, engineers, etc.
2. **Process**\
   The descriptive processes that streamline the operations and ensure consistency, efficiency, and agility to manage and respond to incidents. Sometimes it contains specific incident response playbooks or detection and response processes that the team can follow during the life cycle of an incident or event. For example, IR plans, playbooks, etc.
3. **Technology**\
   Technology provides the tools and infrastructure necessary for the people withing the SOC to do their job and follow processes. For example, SIEM, EDR, IDS/IPS, etc.

<figure><img src="https://640280274-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FTzv07YfbRoOaw7kmThoN%2Fuploads%2Fc7aSlYDUet6z6b7NtNSB%2Fimage.png?alt=media&amp;token=1163e8f2-cb24-4d5e-938e-58267c4f97d7" alt="" width="333"><figcaption></figcaption></figure>

***

## Reactive vs Proactive functions

### Reactive

1. Monitoring and Detection
   1. Network and system logs, alerts
   2. SIEM, IDS, log analysis
   3. Alert triage
2. Incident Response
   1. Investigate, contain, and mitigate threats
   2. Collect evidence and artifacts
   3. Engage with stakeholders
3. Forensic Analysis
   1. In-house or third-party
   2. Determine cause and scope
   3. Preserve evidence and engage legal
4. Malware Analysis
   1. In-house or third-party
   2. Sandbox and reverse engineer malware
   3. Study malware behavior
   4. Collect indicators of compromise

### Proactive

1. Threat Intelligence
   1. Gather and analyze intelligence
   2. Study emerging threats, vulnerabilities, and attacks
   3. Feed intel into detection tools for proactive defense
2. Threat Hunting
   1. Search for malicious activity or intrusions
   2. Logs, network traffic, endpoint telemetry
   3. Utilize threat intelligence to hunt for known indicators
3. Vulnerability Management
   1. Identify and address vulnerabilities
   2. Scan, assess, and patch
   3. Coordinate remediation activity
4. Security Awareness Training
   1. Promote security awareness withing the organization
   2. Educate best practices, policies, and precedures
   3. Mitigate human error leading to incidents
