Back to glossary

SOC

2 min read

In security operations, a SOC is a security operations centre: the team and tooling that monitor for and respond to threats, often around the clock. It is defined by an operating model rather than by a room, and its quality is measured by what it detects and how fast it acts, not by how many alerts it processes.

July 24, 2026
Compartir:

How it works

Telemetry from endpoints, identity, network and cloud is collected into a SIEM or equivalent platform, where detection content turns raw events into alerts. Analysts triage those alerts, escalate what survives triage, and drive containment through agreed procedures. Around that sit the functions that decide whether the model works: content development, which is detection engineering; proactive investigation, which is threat hunting; and case management, increasingly automated through SOAR.

The model can be internal, outsourced as MDR, or a hybrid where a provider watches out of hours. The choice changes who is on the keyboard at three in the morning, not what has to be true for detection to work.

What goes wrong

Coverage is assumed rather than measured. A centre with excellent endpoint telemetry and no identity telemetry will not see an attacker who never drops a file and simply signs in with credentials bought from an access broker. Cloud control plane logs, mail platform audit events and directory changes are the usual gaps.

The second issue is what happens after the alert. We repeatedly find engagements where the detection fired correctly, an analyst triaged it, and nothing followed, because containment needed an authority nobody had at that hour. A detection that produces no action is a log entry with better formatting.

Third, outsourcing tends to transfer monitoring without transferring context. A provider who does not know which server is the payroll system cannot prioritise, and the escalation arrives as a technical description rather than as a business event.

Where this shows up in an audit

The honest measurement is an adversary who does not announce themselves. In a purple team exercise we execute known techniques with the defenders present and record, for each one, whether telemetry existed, whether a rule fired, whether an analyst saw it and whether anything was done. That produces a coverage map by technique instead of an opinion. In a full red team we do not tell them, and the finding is the point at which the operation was noticed, if it was. This is part of how we test detection and response with a real adversary.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.