August 25, 2026
Yohooo! š Day 2 of my SOC learning journey!

By saurabh
1 min read
Yohooo! š Day 2 of my SOC learning journey! Today I focused on understanding the core concepts behind Security Operations Center (SOC) monitoring, detection, and incident response. š What I learned today: ⢠SOC WorkflowāāāData Collection ā Aggregation ā Monitoring & Detection ā Analysis ā Incident Response ⢠ContainmentāāāIsolating a threat to prevent further spread or damage ⢠EradicationāāāRemoving the threat, malicious files, compromised credentials, and addressing the root cause ⢠SOC TriageāāāValidating alerts, determining severity, gathering information, and prioritizing genuine incidents ⢠Events vs LogsāāāUnderstanding what happened vs. the recorded information about what happened ⢠AlertsāāāNotifications generated when potentially suspicious activity is detected ⢠True Positive vs False PositiveāāāSeparating real threats from legitimate activity incorrectly flagged ⢠IOC (Indicator of Compromise)āāāIPs, domains, file hashes, registry entries, and other evidence that can indicate compromise ⢠Log Management & Log ForwardersāāāUnderstanding how security logs are collected and centralized into a SIEM ⢠CIA TriadāāāConfidentiality, Integrity & Availability ⢠SOC RolesāāāL1, L2, L3, SOC Manager and SOC Engineer One key takeaway from today: "The goal of a SOC is not just to generate alerts, but to turn security noise into meaningful signals and respond effectively." Still learning, practicing, and building my cybersecurity fundamentals step by step. š»š