
UpdatedAug 31, 2026
awesome-soc — Updated!
A curated knowledge base to build, run and mature a SOC (including CSIRT).
Awesome SOC
An operational handbook and knowledge base to build, run and mature a SOC (including CSIRT). Covering:
- SOC basics
- detection engineering
- threat intelligence
- SOC metrics/KPI
- SOC automation
- AI use cases and best practices
- SOP (SOC playbooks)
Those are my view, based on my own experience as SOC/CSIRT analyst and team manager, as well as well-known papers. Focus is more on SOC than on CERT/CSIRT.
My motto is: without reaction (response), detection is useless.
NB: Generally speaking, SOC here refers to detection activity, and CERT/CSIRT to incident response activity. CERT is a well-known (formerly) US trademark, managed by CERT-CC, but I prefer the term CSIRT as it precisely refers to incident response.
Table of Contents
- Must read
- Fundamental concepts
- Mission-critical means (tools/sensors)
- SOC internals/core
- AI (ML, LLM, GenAI, Agentic AI)
- IT/security Watch
- SOAR
- Detection engineering
- Threat intelligence
- Playbooks/SOP
- SOC metrics (KPI/SLA)
- SOC Management
- HR and training
- IT achitecture
- To go further (next steps)
- Appendix
Must read
For a SOC
- SOC build:
- MITRE, 11 strategies for a world-class SOC (or use local file): part 0 (Fundamentals).
- FIRST, Building a SOC
- NCSC, Building a SOC
- Gartner, SOC model guide
- Splunk, State of Security 2025
- Microsoft, Secure your business with 365
- SOC training for interview:
- LetsDefend SOC analyst interview questions
- SOC management:
- FIRST, ISO 27035 Practical value for CSIRT and SOCs
- SANS, 2025 SOC survey
- SOC CMM, SOC Metrics
- Gartner, Market Guide for Managed Detection and Response
- SOC assessment:
- CMM, SOC-CMM
- Rabobank CDC, DeTTECT
- SANS, Continous purple teaming
For a CERT/CSIRT
- Global overview:
- SANS, Incident Response
- FlexibleIR, IR phases
- CSIRT build:
- FIRST, CERT-in-a-box
- FIRST, CSIRT Services Framework
- Security incident response management:
- ENISA, Good practice for incident management
- EE-ISAC Incident Response whitepaper
- LinkedIn Pulse, Security incident management according to ISO 27035
- Microsoft/EY/Edelman, Incident response reference guide
- Microsoft, IR lessons on cloud ID compromise
- Forensics:
- Incident response playbooks & methodology:
- Kaspersky, Incident Response Playbook: Dark Web Breaches
- CISA, Incident Response playbooks
- CERT-SG, Incident Response Methodology