Skip to main content
S
SOCSimulatorDocumentation
Core Concepts

Core Concepts

Understand the fundamental concepts of SOC operations and alert handling.

Core Concepts

Master these fundamental concepts to become an effective SOC analyst.

Key Topics

The SOC Workflow

Alert Generated → Triage → Investigation → Response → Resolution
      ↑                         ↓
      └──── Correlation ────────┘
  1. Alert Generated - Security tools detect suspicious activity
  2. Triage - Quick assessment to prioritize response
  3. Investigation - Deep dive into the alert context
  4. Response - Take action to contain or remediate
  5. Resolution - Document and close the incident

MITRE ATT&CK Framework

SOC Simulator maps all scenarios to the MITRE ATT&CK framework:

TacticDescription
ReconnaissanceGathering information
Initial AccessGetting into the network
ExecutionRunning malicious code
PersistenceMaintaining access
Privilege EscalationGetting higher permissions
Defense EvasionAvoiding detection
Credential AccessStealing credentials
DiscoveryLearning the environment
Lateral MovementMoving through the network
CollectionGathering target data
ExfiltrationStealing data out
ImpactDisruption or destruction

Your progress across these techniques is tracked on your profile.

On this page

We use cookies to improve your experience and measure usage. Learn more