Monitoring of a SIEM solution to respond to and contain security event/incidents withing the specified SLA.
Monitor user activity, network events and signals from security tools to identify incidents.
Perform event correlation and carrying out Threat hunting operation using information gathered from a variety of sources to detect, confirm, contain, remediate, and recover from attacks.
Carrying out Triage of identified security incidents.
Notify SOC managers and cyber incident responders of suspected cyber incidents and articulate the event's history, status, and potential impact for further action in accordance with the cyber incident response plan and procedures.
Maintain chronology and documentation related to an incident.