Back to updates
UpdatedAug 31, 2026

awesome-soc — Updated!

A curated knowledge base to build, run and mature a SOC (including CSIRT).

Share

GitHub stars Awesome Last Update License Contributions welcome Lychee

Awesome SOC

An operational handbook and knowledge base to build, run and mature a SOC (including CSIRT). Covering:

  • SOC basics
  • detection engineering
  • threat intelligence
  • SOC metrics/KPI
  • SOC automation
  • AI use cases and best practices
  • SOP (SOC playbooks)

Those are my view, based on my own experience as SOC/CSIRT analyst and team manager, as well as well-known papers. Focus is more on SOC than on CERT/CSIRT.

My motto is: without reaction (response), detection is useless.

NB: Generally speaking, SOC here refers to detection activity, and CERT/CSIRT to incident response activity. CERT is a well-known (formerly) US trademark, managed by CERT-CC, but I prefer the term CSIRT as it precisely refers to incident response.

Table of Contents

Must read

For a SOC

For a CERT/CSIRT

Categories