# 🔍 Role Profile: SOC L2 (Tier 2 Analyst)

![SOC L2 Avatar](../assets/SOC%20L2%20Avatar.png)

## 📋 Role Overview
The **SOC L2 Analyst** leads technical incident investigations, validates incident legitimacy and scope, conducts forensic analysis and timeline reconstruction, assesses business impact, recommends containment, and executes containment for high-severity incidents per the authority matrix.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- 🧭 **Lead Investigation**: Lead the technical incident investigation upon receiving escalation from L1.
- 🎯 **Legitimacy & Scope Validation**: Validate incident legitimacy, affected assets, identities, data, and infrastructure scope.
- 📊 **Confirm Severity Level**: Formally confirm and adjust the incident severity level (e.g. SEV-1, SEV-2).
- 🧠 **Threat Intelligence Correlation**: Perform threat intelligence correlation against internal and external IOC feeds.
- 🔬 **Forensics & Timeline Reconstruction**: Conduct forensic and log analysis to reconstruct the full attack timeline (from Telegram payload to encryption).
- 💼 **Business Impact Assessment**: Assess technical and business impact in coordination with asset owners.
- 💡 **Recommend & Execute Containment**: Recommend containment actions and coordinate with asset/application owners. Execute containment for high-severity incidents according to the authority matrix.
- 🤝 **Coordinate Stakeholders**: Coordinate directly with asset/application owners during containment.
- 🧹 **Lead Eradication**: Lead eradication activities (malware removal, persistence cleanup).
- 📄 **Draft Technical Reports**: Draft initial and final technical incident reports.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Reconstruct timeline: Telegram zip download -> `Signed_Agreement.pdf` trojan -> C2 connection `185.123.45.6` -> SMB share traversal `\\FS01\LoanShares` -> ransomware lock screen.
- Execute host isolation on `LOAN-LAPTOP-042` via EDR.
- Lead malware eradication and draft technical summary report for SOC Manager & Communicator.

---

## 📝 Action Checklist
- [ ] Receive escalation from L1 and validate incident legitimacy & scope.
- [ ] Confirm severity level (SEV-1 Critical).
- [ ] Correlate IOCs and reconstruct attack timeline.
- [ ] Conduct forensic log analysis (SIEM, EDR, Firewall, File Server).
- [ ] Recommend and execute high-severity containment actions (EDR isolation, account lockout).
- [ ] Coordinate with Asset/Application Owners.
- [ ] Lead eradication and draft technical incident report.
