Operate SOC monitoring
Operate SOC monitoring covering shift procedures, queues, and escalation paths
Triage security alerts
Triage security alerts covering enrichment, correlation, and priority assignment
Execute incident response playbooks
Execute incident response playbooks covering defined actions and documentation
Perform threat hunting
Perform threat hunting covering hypothesis-driven searches across telemetry
Manage case documentation
Manage case documentation covering evidence, actions, and handover quality
Coordinate escalations covering severity criteria
Coordinate escalations covering severity criteria and stakeholder notification
Tune detection rules
Tune detection rules covering noise reduction and coverage improvement
Track SOC metrics
Track SOC metrics covering response times, volumes, and closure quality
Use forensic techniques
Use forensic techniques covering artifact collection and timeline reconstruction
Participate in post-incident reviews
Participate in post-incident reviews covering lessons and detection improvements