DOCS / EN

SOC L1 overview

Monitoring, triage, escalation, a note. An alert is not an incident.

SOC L1 in these docs means first line in the lab and in the service description, not a certificate and not a three-shift roster. There is no borrowed MTTA here and no “24/7 SOC-as-a-service”.

The lab goal is the same as in the architecture note:

event → log → detection → alert → triage → note

Workflow

  1. Alert or report
  2. Validate source (host, time with zone, account)
  3. Triage: true / false / cannot say
  4. Enrich with what the log actually has, not what “should be in Splunk”
  5. Escalate or close
  6. A note you can replay

The wider template (intake → facts → decision) is in the IR checklist. The first minutes are in the alert note.

What I write before I call it a case

  • time with zone, not “just now”
  • host (name / IP / Windows or Linux)
  • account or process if the log has it; empty stays empty
  • rule id, or channel + Event ID
  • one next question

Without that, escalation is a dashboard screenshot.

What L1 does not pretend

  • hunting “on a hunch” with no telemetry
  • containment without a host owner
  • that every alert is a breach
  • a NIST playbook nobody rehearsed end-to-end in the lab

See the SOC lab and the IR checklist before adding another dashboard. If you cannot replay the event on your own host, you do not understand the detection yet — and that is fine.

Want this in a lab or on production?

Docs stay free. The form is for scope, not a paywall.

The inquiry is stored on the server. The operator is notified on Telegram. There is no email autoresponder.