Back to all posts
Day 245Saturday, October 3, 20263 min read

Studying How a SOC Hands Alerts From Tier 1 to Tier 3 and Managers

cybersecuritysocsecurityoperationsalerttriageescalationlearningprocess
View original post

🔄 Topic

I studied how a Security Operations Center divides work between Tier 1, Tier 2, Tier 3, leads, and managers. The useful insight was that the tiers form an escalation and decision system, not a ranking of who is “better” at security.

🎯 Goal

Understand what information should move with an alert as it progresses from initial review to deeper investigation and leadership decision-making.

🛠 What I Learned

Tier 1 analysts monitor, review, prioritize, create, close, and escalate alerts. Their value is disciplined triage: identify what arrived, assess severity and context, document the decision, and move cases that need deeper work.

Tier 2 analysts investigate escalated cases in more depth. They correlate identity, endpoint, network, and application evidence, test hypotheses, and determine whether an alert is a false positive, suspicious activity, or a confirmed incident.

Tier 3 analysts and SOC leads handle advanced investigation, detection improvement, threat hunting, and complex response decisions. Managers provide staffing, priorities, risk communication, and operational accountability. The boundaries vary by organization, but the core lesson remains: every handoff needs evidence, scope, ownership, and a clear next action.

🔗 Key Cybersecurity Connections

  • alert severity is not the same as incident certainty
  • escalation should preserve evidence and reasoning
  • ticket closure is a decision that needs a documented basis
  • metrics should measure useful outcomes, not only ticket volume
  • detection engineering improves when investigators feed lessons back into rules

🔍 Investigation Questions

  • What did the first analyst observe, and what remains unknown?
  • Why was the alert escalated or closed?
  • Which evidence has already been checked?
  • What exact question is the next tier expected to answer?
  • Can a manager understand risk without reading the entire raw alert stream?

🚨 Detection Opportunities

A mature SOC monitors repeated false positives, alerts that remain unowned, escalations without evidence, repeated user or host pivots, and cases closed without a stated disposition. These are workflow signals as well as security signals.

🧭 MITRE ATT&CK Techniques

No direct ATT&CK mapping is claimed. This post concerns SOC operating structure and investigative handoffs rather than an observed adversary technique.

⚠ Challenges

It is easy to describe Tier 1 as “basic” and Tier 3 as “advanced.” That framing misses the security control represented by consistent first-line triage. Poorly documented early decisions create more work and can hide real incidents.

📚 What I Learned

A SOC is a chain of evidence-preserving decisions. The quality of an escalation depends less on the job title of the sender than on whether the next analyst receives a clear question, useful context, and an honest statement of uncertainty.

➡ Next Steps

  • practise writing escalation notes from synthetic alerts
  • compare alert closure reasons with the evidence actually available
  • map a sample case from detection through response and lessons learned