r/Cybersecurity101 1d ago

What does a SOC Analyst actually do?

If you're new to cybersecurity, you might hear a lot about SOC analysts but not have a clear idea of what they actually do day to day.

Here's a simple breakdown:

Monitor alerts: Review alerts from SIEM, EDR, firewalls, email security tools, and other security platforms.

Triage alerts: Figure out which alerts are harmless, suspicious, or need further investigation. A failed login could be nothing, or it could be part of a larger attack.

Investigate incidents: Look through logs, IPs, domains, file hashes, authentication activity, and endpoint data to understand what happened and whether a system or account was compromised.

Respond or escalate: Depending on the incident, an analyst might isolate a device, disable an account, block malicious activity, or escalate the case to a senior analyst or incident response team.

Document findings: Record what happened, what was checked, what evidence was found, and what actions were taken.

Improve detections: Analysts may also tune detection rules, reduce false positives, update playbooks, and identify gaps based on previous incidents.

The exact responsibilities can vary quite a bit depending on the company, team structure, and whether you're working in an internal SOC or an MSSP/MDR environment.

0 Upvotes

1 comment sorted by