# 🎯 Role Profile: SOC Lead / L3

![SOC L3 Avatar](../assets/SOC%20L3%20Avatar.png)

## 📋 Role Overview
The **SOC Lead / L3** supports complex investigations, guides deep technical and forensic analysis, authorizes major containment actions, assists in scoping and root cause analysis, and shares full authority with the SOC Manager during critical incidents.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- 🔬 **Support Complex Investigations**: Support complex technical investigations when incident complexity exceeds standard L2 playbooks.
- 🧪 **Deep Forensic Guidance**: Guide deep technical and forensic analysis (memory dumps, reverse engineering trojan DLL payloads, protocol analysis).
- 🛡️ **Authorize Major Containment**: Authorize major technical containment actions (e.g. blocking subnets, revoking enterprise Kerberos tickets).
- 🎯 **Scoping & Root Cause Analysis**: Assist in comprehensive incident scoping and deep root cause analysis (RCA).
- 🆘 **Escalation Support**: Provide immediate escalation support when L2 encounters technical uncertainty or operational resistance.
- 👑 **Shared Critical Authority**: Share full operational authority with the SOC Manager during critical (SEV-1) incidents.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Reverse engineer `Signed_Agreement.pdf` trojan payload to identify C2 communication protocols.
- Authorize isolation of affected Loan network segments and credential resets.
- Partner with SOC Manager in directing War Room technical decisions.

---

## 📝 Action Checklist
- [ ] Provide senior technical direction to L2 during active investigation.
- [ ] Guide forensic payload analysis and memory extraction.
- [ ] Authorize major containment actions in alignment with SOC Manager.
- [ ] Assist in enterprise-wide scoping and root cause analysis.
- [ ] Support L2 when technical uncertainties arise.
