SOC L1 in these docs means first line in the lab and in the service description, not a certificate and not a three-shift roster. There is no borrowed MTTA here and no “24/7 SOC-as-a-service”.
The lab goal is the same as in the architecture note:
event → log → detection → alert → triage → note
Workflow
- Alert or report
- Validate source (host, time with zone, account)
- Triage: true / false / cannot say
- Enrich with what the log actually has, not what “should be in Splunk”
- Escalate or close
- A note you can replay
The wider template (intake → facts → decision) is in the IR checklist. The first minutes are in the alert note.
What I write before I call it a case
- time with zone, not “just now”
- host (name / IP / Windows or Linux)
- account or process if the log has it; empty stays empty
- rule id, or channel + Event ID
- one next question
Without that, escalation is a dashboard screenshot.
What L1 does not pretend
- hunting “on a hunch” with no telemetry
- containment without a host owner
- that every alert is a breach
- a NIST playbook nobody rehearsed end-to-end in the lab
See the SOC lab and the IR checklist before adding another dashboard. If you cannot replay the event on your own host, you do not understand the detection yet — and that is fine.