How security operations work
Day zero at ACME-CORP. Before you touch a queue, you need the map: what the SOC defends, what data it sees, and how work moves from a raw event to a closed incident.
Concept
Read this before opening the workspace
A Security Operations Centre is the function that detects, investigates and responds to attacks against an organisation. It is not a tool — it is people working a queue of signals produced by tools, under a defined process, against a clock.
The operating loop is always the same: telemetry is collected, detections turn telemetry into alerts, analysts triage alerts into verdicts, confirmed threats become incidents, incidents drive response, and every incident feeds improvements back into detection. Everything you learn in this curriculum sits somewhere on that loop.
Key terms
- Telemetry
- Raw security-relevant data collected from endpoints, network, identity and cloud.
- Detection
- Logic that turns telemetry into an alert when it matches suspicious behaviour.
- Triage
- The fast first assessment: is this real, is it urgent, who is affected.
- Incident
- A confirmed or highly likely compromise that requires a coordinated response.
Learning objectives
- Describe the collect → detect → triage → respond → improve loop
- Name what each SOC role contributes to that loop
- Locate each loop stage inside this console
Prerequisites
- · No prior SOC experience required