# 🛡️ Role Profile: SOC L1 (Tier 1 / Shift Duty)

![SOC L1 Avatar](../assets/SOC%20L1%20Avatar.png)

## 📋 Role Overview
The **SOC L1 Analyst** works shift duty to continuously monitor security alerts, perform initial triage, determine False Positives vs True Positives, enrich alert context, create ITSM tickets, and escalate credible incidents to L2 within strict SLAs.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- 👁️ **Continuous Monitoring**: Monitor alerts continuously across EDR (CrowdStrike/Defender), SIEM (Splunk/QRadar), firewall, and user reports.
- 🔍 **Triage & Validation**: Perform initial alert validation and triage to determine False Positive (FP) vs True Positive (TP).
- 🏷️ **Context Enrichment**: Enrich alert context (asset details, user profile, source/destination IP, potential impact).
- 📝 **ITSM Ticket Creation**: Open an ITSM incident ticket for all potential incidents with evidence attached.
- ⏱️ **15-Minute Escalation**: Escalate credible incidents to L2 within **15 minutes** of validation.
- ⚡ **Predefined Containment**: Execute predefined containment actions for low/medium severity incidents according to approved playbooks.
- 🚨 **Direct Manager Escalation**: Escalate directly to the **SOC Manager** if L2 is unavailable.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Monitor EDR alert for `LOAN-LAPTOP-042` and user report of Adobe PDF error `0x80070005`.
- Validate true positive indicators (process tree `explorer.exe` -> Trojan DLL -> SMB write burst).
- Create SEV-1 ITSM Ticket and phone/chat escalate to SOC L2 within 15 minutes.

---

## 📝 Action Checklist
- [ ] Continuously monitor SIEM & EDR consoles.
- [ ] Validate alert context (User: `j.smith`, Host: `LOAN-LAPTOP-042`, IP: `10.15.34.120`).
- [ ] Determine FP vs TP state.
- [ ] Create ITSM incident ticket.
- [ ] Escalate to SOC L2 within 15 minutes (or SOC Manager if L2 unavailable).
- [ ] Execute playbook predefined containment for low/medium alerts where applicable.
