soc-operations

Guide Security Operations Center design and alert triage with runbooks and KPIs.

345|47|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/briiirussell/cybersecurity-skills --skill soc-operations-briiirussell
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc-operations
Source: https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/soc-operations
Command: npx skills add https://github.com/briiirussell/cybersecurity-skills --skill soc-operations-briiirussell

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SOC operations often fail due to poor alert triage, unclear escalation, weak runbooks, and metrics that don’t drive actionable improvements, leading to alert fatigue and slow detection/response.

Core Features & Use Cases

  • SOC build/run/improve playbooks: design staffing, tiering, escalation criteria, and on-call hygiene for a new SOC or an existing one.
  • Alert prioritization & runbook authoring: standardize how Tier 1 triages alerts and how runbooks are structured for repeatability.
  • Continuous tuning & KPI management: reduce alert fatigue using a tuning loop and operational KPIs (MTTD/MTTR/TP rate/runbook coverage).

Quick Start

Use the soc-operations skill to create a SOC build plan for a 6-analyst team that includes tiering, escalation rules, runbook backlog priorities, and target MTTD/MTTR thresholds.

Frequently Asked Questions about soc-operations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I set up a Security Operations Center for a small analyst team?

Setting up a Security Operations Center for a small team requires defining analyst tiering, escalation criteria, and runbook-driven response workflows to ensure proper alert triage and on-call hygiene from day one.

What are the best SOC KPIs for reducing alert fatigue and improving MTTR?

The best SOC KPIs for reducing alert fatigue and improving MTTR include tracking mean time to detect, mean time to respond, true positive rate, and runbook coverage within a continuous alert tuning loop.

How does alert triage and escalation work in a tiered SOC model?

Alert triage in a tiered SOC model works by having Tier 1 analysts perform initial alert prioritization using standardized runbooks, then applying explicit escalation rules to hand off active incidents to incident-triage teams.

How do I structure runbooks for SOC alert triage?

Structuring runbooks for SOC alert triage involves standardizing repeatable response steps for multiple alert types so analysts can consistently execute escalation procedures and reduce mean time to respond.

When should a SOC hand off active incidents to incident triage?

A SOC should hand off active incidents to incident triage when alert escalation criteria are met, maintaining clear operational boundaries that separate 24/7 alert operations from dedicated active incident management.