A Security Operations Centre (SOC) is the team and tooling that monitors, detects and responds to threats around the clock.
The SOC Detection Workflow
How a Security Operations Centre turns raw logs into action.
Tap or hover a part to learn more.
Collect everything.
Endpoints, servers, firewalls, cloud and identity systems forward logs. Good coverage is the foundation of detection.
Check your understanding
1. What tool centralises and correlates security logs?
2. What does an analyst do first with a new alert?
Keep learning
How it works
- Collect — a SIEM aggregates logs from endpoints, network, cloud and identity into one place.
- Detect — correlation rules and analytics turn raw events into alerts; good detection engineering reduces noise.
- Triage — analysts investigate alerts, separating false positives from real incidents, then escalate.
- Tiers — Tier 1 triages, Tier 2 investigates deeper, Tier 3 hunts and engineers detections.
This is the SOC Analyst role in action and leads straight into Incident Response.
