The alert lifecycle: the loop that is the job

~25 min

(Quick review first: SOCs are tiered, you start at Tier 1 doing triage, and the whole SOC depends on the front line getting the first decision roughly right.)

The loop

Nearly everything a SOC analyst does fits one repeating cycle. Learn it as a mental model and every alert you ever handle has a shape:

Detect → Triage → Investigate → Respond → Recover → Learn → (back to Detect)

Walk it once:

Detect. The SIEM correlates events and raises an alert. This half is automated — it is what you built in the Beginners course. The loop, for you, begins the moment an alert appears in the queue.

Triage. Your first decision, and the highest-volume one. Is this real or a false positive? How serious? Does it need deeper investigation or can it be closed? Most alerts end here, closed as benign — and doing that quickly and correctly is the core Tier 1 skill. Triage is not investigation; it is the rapid sort that decides what deserves investigation.

Investigate. For alerts that survive triage, you dig. What actually happened? What is the scope — one machine or many? What did the attacker touch? This is where the Beginners course's investigation skills go to full depth, and where most of this course lives.

Respond. For confirmed incidents, contain and remediate. Isolate a machine, disable an account, block an address, remove persistence. Stop the bleeding, then clean up.

Recover. Return to normal safely — restore systems, confirm the threat is truly gone (not just the visible part), verify no persistence remains. The Beginners course's warning applies: cleaning the process while leaving the persistence means reinfection.

Learn. The step everyone skips and the one that compounds. What did this incident teach? Can you write a detection so it is caught automatically next time? Was there a gap in coverage? A SOC that does not learn from incidents fights the same attack forever; one that does gets measurably better each time — turning every incident into a permanent detection.

Triage in depth

Because triage is most of your early career, understand what a good one involves. For each alert, in seconds to minutes, you are answering:

  • Is it real? True positive or false positive?
  • What is it? What kind of activity, mapped to something you understand — the attack chain, an ATT&CK technique.
  • How serious? Severity and urgency, which are not the same: a low-severity alert on a critical system can outrank a high-severity one on a test box.
  • What is the scope? One system or many? A hint of something larger?
  • What next? Close it, investigate further, or escalate immediately.

Good triage is fast and accurate, which sounds contradictory and is the actual skill. It comes from knowing normal so well that abnormal is obvious — the refrain of the whole programme, now your daily instrument. You get there by paying attention during the quiet hours, not by memorising a checklist.

Documentation runs through all of it

At every step you record what you saw, what you concluded, and what you did. This is not bureaucracy:

  • The next analyst, or your future self, needs to understand what happened.
  • Incidents can become legal matters, where your notes are evidence held to a real standard.
  • Patterns emerge across incidents only if each was written down.
  • Metrics and improvement depend on records.

An investigation nobody wrote down barely happened. Write as you go — reconstructing your reasoning afterwards is painful and unreliable, and "I remember it was suspicious" is worth nothing in a handover or a courtroom.

Try it now

Take three alert types from the Beginners course:

  1. A single failed SSH login.
  2. A brute-force correlation alert — many failures then a success.
  3. A Windows security log cleared (event 1102).

For each, walk the loop as far as it goes: how would you triage it (real or noise, severity), and for the ones that survive, what would you investigate?

Notice that the three take very different paths. The first usually dies at triage. The third goes almost straight to investigation and probably escalation. Learning which path an alert takes, fast, is the Tier 1 craft — and you start practising it in this week's lab.

Sign in to track your progress.