What a SOC actually does
A Security Operations Centre is the function responsible for detecting, investigating, and coordinating response to security events. In smaller organisations it may be one person; in larger ones it may be a dedicated team, an external service, or both. The size varies. The core work does not.
Most SOCs organise around three activities: monitoring for events that suggest something is wrong, triaging those events to separate signal from noise, and coordinating response when something real is confirmed.
Why alert fatigue is the real enemy
The failure mode of nearly every SOC is the same: too many alerts, too many false positives, and analysts who develop the reasonable habit of dismissing warnings quickly. Genuine incidents then sit in the queue alongside the noise.
The remedy is detection engineering: treating detection rules as software, tuning them against real data, retiring the ones that generate more noise than signal, and writing new ones aimed at behaviour attackers actually exhibit.
Where threat hunting fits
Alerts tell you what your tooling already knows to look for. Threat hunting is the proactive search for what it does not. A hunter forms a hypothesis (“if an attacker had domain administrator access, what traces would we see?”), queries the environment against that hypothesis, and either finds evidence or eliminates it.
The purpose is not only to catch things detection missed. Good hunts also produce new detection rules, better data collection, and a clearer picture of what normal actually looks like in the environment.
What good SOC operations look like
- Detection coverage mapped to a known adversary framework rather than to whatever the tooling shipped with
- Regular tuning cycles, so noisy rules are retired instead of ignored
- Documented handoffs between triage, investigation, and response
- Time-based metrics (mean time to detect, to acknowledge, to contain) tracked and used to improve
- Threat hunts scheduled as work, not squeezed in between alerts
Related in the Knowledge Base
- Incident Response: Playbooks, Forensics, and Why Preparation Wins
- Security Automation (SOAR): Where Automation Helps, Where It Hurts
- Continuous Threat Exposure Management (CTEM): Beyond Periodic Scans
Know what an attacker sees before they do.
A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.
Free PDF · No spam · Unsubscribe anytime