SOC 7x24 Monitoring and Managed SOC Service
Monitor firewall, Active Directory, endpoint, network and cloud security events 24/7 with SIEM correlation, threat hunting and incident response.
Cyber attacks do not happen only during business hours. Ransomware, account takeover attempts, malware activity, unauthorized access, lateral movement, data exfiltration attempts and other advanced threats can target an organization's information systems at any hour of the day.
For that reason, buying security products alone is not enough in a modern cyber security approach. Events generated by firewall, EDR/XDR, Active Directory, server, network, cloud and other security systems must be monitored continuously, correlated, analyzed, and real threats detected as quickly as possible.
The SecureSys SOC 7x24 Monitoring Service is a managed cyber security service offered so that security events coming from an organization's information technology and cyber security infrastructure can be monitored 7 days a week and 24 hours a day, analyzed, correlated, prioritized, and incident response processes started where required.
The SecureSys SOC service is not simply alarm watching.
The aim is;
Log → Event → Correlation → Analysis → Threat → Response → Improvement
managing that chain end to end.
The approach targets increased security visibility, earlier detection of real attacks, fewer false positives, and shorter response times for cyber incidents.
What Is a SOC?
SOC stands for Security Operations Center.
A SOC is the central operations structure that continuously monitors an organization's cyber security infrastructure, analyzes security events, investigates threats and manages cyber incident response processes.
Within a SOC;
- SIEM,
- SOAR,
- EDR,
- XDR,
- NDR,
- Threat Intelligence,
- UEBA,
- Vulnerability Management,
- Incident Response
and other security technologies can be used together.
But a SOC is not technology alone.
A successful Security Operations Center requires;
People + Process + Technology
to be managed together.
What Is a SOC Service?
A SOC service is the managed security service that allows an organization's cyber security events to be followed centrally by expert security analysts.
Within the SecureSys SOC Service, security events generated by the organization's;
- firewall,
- Active Directory,
- Windows Server,
- Linux Server,
- EDR/XDR,
- network devices,
- VPN,
- e-mail security,
- web security,
- database,
- cloud systems,
- critical applications
and other sources can be analyzed centrally.
SOC analysts evaluate security events, identify those with genuine attack potential, and ensure action is taken according to the organization's defined escalation processes.
7x24 SOC Monitoring Service
Cyber attacks can happen at any hour of the day.
Ransomware attacks and account takeover operations in particular can be carried out during hours when the organization's security teams are not active.
Monitoring security events only during business hours may therefore not be enough in critical organizations.
With the SecureSys 7x24 SOC Monitoring Service, events from the security infrastructure can be followed 24 hours a day.
This model;
24 Hours × 7 Days × 365 Days
aims to provide continuous security visibility.
SOC as a Service
Building a full-scope Security Operations Center in house can require significant investment in people, technology and operations.
The SOC as a Service model allows organizations to benefit from expert security operations without building a large SOC organization of their own.
Within SecureSys SOC as a Service;
- monitoring of security events,
- alarm analysis,
- event correlation,
- threat analysis,
- escalation,
- reporting,
- incident response support where required
can be provided.
This approach creates a security operations layer that complements the organization's existing IT and cyber security teams.
Managed SOC Service
Managed SOC is the model in which an organization's security operations are run continuously by an expert service provider.
In the SecureSys Managed SOC service the organization's existing security technologies can be retained, or additional technologies can be brought into use according to need.
Within Managed SOC;
- SIEM management,
- tracking of log sources,
- correlation rules,
- use case development,
- alarm analysis,
- threat hunting,
- incident escalation,
- security reporting
and similar processes can be carried out.
The Difference Between SOC and SIEM
The terms SOC and SIEM are often confused with one another.
SIEM is a security technology.
SOC is a security operations process.
SIEM collects logs from different systems, analyzes them and can raise alarms through correlation rules.
SOC analysts then evaluate those alarms and look for answers to questions such as;
- is the event real?
- is it a false positive?
- is it part of an attack chain?
- which systems are affected?
- is a response required?
and similar questions.
Deploying SIEM alone therefore does not amount to a SOC operation.
SIEM Monitoring Service
SIEM infrastructure is one of the core components of the SecureSys SOC operation.
SIEM platforms provide;
- log collection,
- central records,
- correlation,
- alarm generation,
- search,
- reporting
functions.
Within the SecureSys SIEM Monitoring Service, security events can be analyzed centrally.
SIEM Use Case Management
Collecting logs alone is not enough for a SIEM system to produce value.
The right security scenarios must be created.
The SecureSys SOC team can develop SIEM use cases according to the organization's infrastructure.
For example;
- failed logon attacks,
- brute force,
- password spraying,
- creation of unauthorized administrator accounts,
- suspicious PowerShell use,
- critical file changes,
- firewall policy changes,
- abnormal VPN access
correlation rules can be created for these cases.
Integrating Log Sources into the SOC
The success of a SOC operation depends on the right log sources being brought into the system.
Into the SecureSys SOC infrastructure;
- Firewall,
- Active Directory,
- Windows,
- Linux,
- VPN,
- EDR,
- XDR,
- NDR,
- WAF,
- Proxy,
- DNS,
- DHCP,
- Switch,
- Router,
- Database,
- PAM,
- DLP,
- Cloud,
- e-mail security
and many other sources can be integrated.
Monitoring Firewall Logs Through the SOC
The firewall is one of the important sources of security events.
Within the SOC;
- blocked connections,
- IPS alarms,
- VPN logins,
- administrator access,
- policy changes,
- suspicious outbound traffic
can be analyzed.
Active Directory Security Monitoring
Active Directory is the central identity infrastructure of many organizations and one of the important targets for attackers.
Within the SecureSys SOC;
- failed logins,
- administrator account creation,
- group membership changes,
- critical user activity,
- account lockouts,
- abnormal authentication behavior
can be tracked.
Monitoring Windows Security Events
Windows servers and clients generate important security logs.
Through the SOC;
- login activity,
- process creation,
- service changes,
- user operations,
- PowerShell activity,
- security policy changes
can be analyzed.
Linux Security Monitoring
On Linux systems;
- SSH login,
- sudo use,
- user changes,
- service activity,
- authentication logs,
- critical system changes
can be brought into the SOC operation.
EDR and XDR Monitoring
Endpoint Detection and Response and Extended Detection and Response technologies are used to detect attack behavior on endpoints.
The SecureSys SOC team can evaluate the;
- malware,
- ransomware,
- suspicious process,
- credential dumping,
- persistence,
- lateral movement,
- command execution
alarms coming from EDR/XDR systems.
Network Security Monitoring with NDR
NDR – Network Detection and Response solutions help detect abnormal behavior in network traffic.
In the SecureSys SOC operation, NDR data can be analyzed for;
- lateral movement,
- command and control,
- abnormal connections,
- data transfers,
- suspicious network behavior
and similar indicators.
MDR – Managed Detection and Response
MDR is the service model that targets not only monitoring security events but managing detection and response processes more actively.
In the SecureSys MDR approach, the;
Detection + Investigation + Response
processes can be handled together.
Depending on the organization's technology estate and authorization model, active response processes can be applied for specific events.
Threat Detection
Threat Detection is the process of identifying signs of attack in an organization's infrastructure.
The SecureSys SOC team;
- SIEM,
- EDR/XDR,
- NDR,
- Threat Intelligence
evaluates this data together to identify potential threats.
Threat Hunting
Threat Hunting is proactively investigating signs of attack in an organization's infrastructure rather than simply waiting for existing security alarms.
In Threat Hunting work;
- endpoint activity,
- network connections,
- authentication records,
- process behavior,
- DNS queries,
- user activity
can be analyzed.
IOC Scanning
IOC – Indicator of Compromise refers to the technical indicators showing that a system may have been compromised.
IOCs can be;
- IP address,
- domain,
- URL,
- file hash,
- e-mail address
and similar information.
In the SecureSys SOC operation, IOCs obtained from Threat Intelligence sources can be compared against records in the organization's infrastructure.
Threat Intelligence Integration
Cyber Threat Intelligence provides information about current attack infrastructure and threat actors.
Threat Intelligence data can be integrated into SIEM and SOC operations so an organization's existing logs can be compared against current threat indicators.
SOC Operations with MITRE ATT&CK
In SecureSys SOC analyses, the MITRE ATT&CK approach can be used to classify attacker behavior.
Events can be;
- Initial Access,
- Execution,
- Persistence,
- Privilege Escalation,
- Defense Evasion,
- Credential Access,
- Discovery,
- Lateral Movement,
- Collection,
- Command and Control,
- Exfiltration,
- Impact
evaluated within attack tactics such as these.
This approach helps the whole attack chain be seen rather than a single alarm.
Cyber Kill Chain Analysis
Cyber attacks rarely consist of a single event.
An attacker may first gain access to a system, then escalate privileges, move within the network, and in the final stage exfiltrate data or run ransomware.
In SOC operations, events occurring at different times are analyzed to establish whether they are part of the same attack chain.
Detecting Brute Force Attacks
A large number of failed login attempts can be an indicator of a brute force attack.
The SOC can correlate the;
- source IP,
- user,
- target system,
- time window
information to assess the likelihood of an attack.
Password Spraying Detection
In password spraying attacks, instead of trying many passwords against a single user, the attacker may try the same password across many user accounts.
This attack can evade classic brute force alarms.
SecureSys SOC use cases can be developed to detect this kind of behavior.
Credential Theft Detection
The theft of credentials is one of the important stages of modern cyber attacks.
Using EDR/XDR and SIEM data;
- credential dumping,
- suspicious authentication,
- abnormal administrator use
and similar activity can be investigated.
Lateral Movement Detection
After compromising one endpoint, an attacker may try to move to other systems.
This process is called Lateral Movement.
Within the SOC;
- RDP,
- SMB,
- WinRM,
- PowerShell,
- remote service,
- authentication
activity can be analyzed to investigate signs of lateral movement.
Ransomware Detection
Ransomware attacks are one of the most critical cyber security risks for organizations.
In the SecureSys SOC service;
- unusual file activity,
- suspicious process behavior,
- shadow copy deletion attempts,
- lateral movement,
- stopping of security services,
- abnormal network connections
and similar indicators can be evaluated together.
Command and Control Detection
Compromised systems can communicate with attacker infrastructure.
SOC and NDR systems can analyze behavior such as;
- suspicious domain connections,
- known malicious IP addresses,
- abnormal DNS activity,
- periodic beaconing
and similar patterns.
Monitoring Data Exfiltration Attempts
The attacker's aim is not always to encrypt the system.
Some attacks target moving critical data outside the organization.
Within the SOC;
- unusual outbound traffic,
- high-volume data transfers,
- suspicious cloud uploads,
- DLP events
can be analyzed.
DNS Security Monitoring
DNS records can provide important information for detecting attacks.
Through the SOC;
- new or suspicious domain queries,
- known malicious domains,
- unusual DNS volume,
- abnormal query behavior
can be examined.
VPN Security Monitoring
Remote access systems are one of the important entry points attackers target.
The SecureSys SOC can analyze activity such as;
- failed VPN logins,
- logins from different countries,
- access at unusual hours,
- abnormal connections for the same user
and similar events.
Cloud Security Monitoring
Maintaining security visibility in cloud environments is important.
Within the SecureSys SOC, security events such as;
- user activity,
- administrator operations,
- authentication,
- security alerts,
- configuration changes
from supported platforms can be brought into central analysis processes.
Microsoft 365 Security Monitoring
The compromise of user accounts in Microsoft 365 environments can create serious security risk.
From the log and security systems supported within the SOC;
- failed logins,
- suspicious authentication,
- mailbox rule changes,
- administrator activity,
- user security events
can be analyzed.
Database Security Monitoring
Critical database systems are one of the important targets for attackers.
From database logs or DAM systems;
- failed logins,
- administrator activity,
- critical data access,
- privilege changes,
- unusual queries
can be included in SOC analyses.
Monitoring PAM Events Through the SOC
Privileged Access Management systems provide secure management of privileged accounts.
By forwarding PAM logs to SIEM;
- administrator sessions,
- failed access,
- use of highly privileged accounts,
- critical system access
can be tracked by the SOC.
Monitoring DLP Events Through the SOC
DLP solutions can generate security events relating to sensitive data being moved outside the organization.
The SOC can evaluate these events with the;
- user,
- data type,
- transfer channel,
- destination
information to determine the risk level of the event.
WAF Security Monitoring
Web Application Firewall systems provide important data about attacks aimed at web applications.
Within the SOC;
- SQL Injection,
- XSS,
- path traversal,
- exploit attempts,
- bot activity
and similar WAF events can be analyzed.
SOC L1 Analyst
SOC L1 security analysts carry out the first evaluation of incoming alarms.
L1 processes can cover;
- alarm review,
- basic validation,
- false positive analysis,
- event classification,
- escalation
and similar operations.
SOC L2 Analyst
SOC L2 analysts examine events requiring more detailed investigation.
At L2 level;
- log correlation,
- attack chain analysis,
- endpoint analysis,
- IOC research,
- scoping
work can be carried out.
SOC L3 and Advanced Analysis
At L3 level, deeper technical analysis can be carried out on complex security events and advanced attacks.
At this level;
- Threat Hunting,
- malware analysis,
- advanced event analysis,
- detection engineering,
- attack behavior analysis
and similar work can be run.
The SOC Escalation Process
Evaluating every alarm at the same level is not correct.
In the SecureSys SOC operation, events can be classified by severity level.
For example:
Informational → Low → Medium → High → Critical
Critical events are passed to the relevant organizational teams according to the defined communication and escalation procedures.
Incident Response
Where a cyber security incident is confirmed, the incident response process can be started.
Incident Response essentially covers the;
Identification → Containment → Eradication → Recovery → Lessons Learned
stages.
Depending on the scope of the incident and the service model, SecureSys can support the organization's Incident Response processes.
Containment – Limiting the Attack
When an attack is detected, one of the first aims is to prevent it spreading.
Depending on the authorization model, containment actions such as;
- endpoint isolation,
- disabling the user account,
- blocking the malicious IP address,
- creating a firewall rule,
- domain blocking
can be applied or recommended to the organization's team.
Automated Response and SOAR
SOAR – Security Orchestration, Automation and Response technologies can enable automatic action on specific security events.
For example;
IOC Detected → IP Reputation Check → Threat Intelligence Query → Firewall Block → Ticket Creation
playbooks such as these can be prepared.
Automated response actions must be applied with the organization's approval and in line with the defined authorization policies.
SOC Playbook Management
SOC playbooks can be created so cyber incidents can be handled in a standard way.
For example;
- Phishing Playbook,
- Malware Playbook,
- Ransomware Playbook,
- Brute Force Playbook,
- Compromised Account Playbook,
- Data Exfiltration Playbook
can be prepared.
Alarm Enrichment
Evaluating a security alarm on its own may not be enough.
SOC systems can enrich an alarm with;
- Threat Intelligence,
- Asset Criticality,
- user information,
- IP reputation,
- endpoint information,
- vulnerability information
and similar context.
The aim is to help the analyst make a more accurate decision.
Asset Criticality
Not every system carries the same importance for the organization.
An alarm raised on a Domain Controller and the same alarm on a low-importance test system can be evaluated at different risk levels.
Defining asset criticality levels in SOC processes strengthens alarm prioritization.
Vulnerability Intelligence
The presence of a vulnerability on a system can increase the significance of an attack alarm targeting that system.
In SOC operations, correlating vulnerability management data with SIEM and event analysis can provide more accurate risk prioritization.
False Positive Management
One of the important problems in SOC operations is that too many false alarms are generated.
The SecureSys SOC team aims to reduce the false positive rate through;
- improving correlation rules,
- threshold adjustments,
- whitelist management,
- use case tuning
and similar work.
Alert Fatigue Management
Thousands of low-quality alarms can cause security teams to miss critical events.
The SecureSys SOC approach focuses on producing meaningful and actionable security events rather than increasing the number of alarms.
Detection Engineering
Because attacker techniques change constantly, SOC use cases must also be developed.
Within Detection Engineering;
- new detection rules,
- correlation scenarios,
- MITRE ATT&CK mapping,
- log source improvements,
- tuning
work can be carried out.
The SOC Onboarding Process
The transition to the SecureSys SOC service is carried out through a controlled onboarding process.
1. Infrastructure Discovery
The organization's network, system and security infrastructure is analyzed.
2. Identifying Critical Assets
Domain Controllers, critical servers, databases and applications are classified.
3. Identifying Log Sources
The log sources that need to be forwarded to the SOC are determined.
4. SIEM Integration
Log sources are brought into the central SIEM infrastructure.
5. Use Case Creation
Security scenarios are created according to the organization's risk profile.
6. Tuning
Scenarios producing false positives are optimized.
7. Escalation Matrix
The people and processes to be contacted during critical events are defined.
8. 7x24 Operation
The SOC monitoring process is brought into operation.
The First 30 Days of SOC Operation
Understanding the normal behavior of the organization's infrastructure is important in the first period of the SOC service.
During this period the;
- log quality,
- user behavior,
- network activity,
- frequently occurring alarms,
- false positives
are analyzed and the SIEM and SOC rules are optimized.
SOC SLA Management
Different response and notification times can be defined according to the severity of security events.
For example, critical security events can be escalated faster while low-risk events are evaluated within the standard operations process.
SLA values are set according to the organization's risk level and service scope.
SOC Reporting
Operational and management reports can be produced within the SecureSys SOC service.
Reports can include;
- total security events,
- critical alarms,
- event categories,
- the systems generating the most alarms,
- attack types,
- response processes,
- trends,
- improvement recommendations
and similar content.
Executive SOC Report
Senior management should not be expected to review thousands of technical alarms.
Executive reports can therefore summarize the;
- critical risks,
- significant attacks,
- event trends,
- organization's security posture,
- actions to be taken
at a summary level.
SOC KPIs and Metrics
Different metrics can be used to measure SOC performance.
Among the important indicators are;
MTTD – Mean Time to Detect
The average time until an attack is detected.
MTTA – Mean Time to Acknowledge
The time until an alarm is taken up for evaluation by an analyst.
MTTR – Mean Time to Respond
The time taken for the event to enter the response process and actions to be applied.
these measures.
The aim is not simply to generate more alarms but to reduce MTTD and MTTR times.
SOC and ISO/IEC 27001
Logging, management of security events, access control and monitoring processes carry weight within ISO/IEC 27001.
A SOC service can help an organization support these controls operationally.
SOC and KVKK
Detecting unauthorized access and security events on systems that process personal data is important for data security.
A SOC can help suspicious activity on critical systems be monitored centrally.
SOC and PCI DSS
In organizations processing payment card data, monitoring security logs and analyzing events are among the important security controls.
SOC and SIEM infrastructures can support the security monitoring processes within the scope of PCI DSS.
SOC and DORA
Operational resilience and the management of ICT risks carry weight in the finance sector.
A SOC can contribute to an organization's operational resilience approach through continuous monitoring and detection of security events and support for incident response processes.
SOC and NIS2
For organizations within the scope of NIS2, cyber risk management and the management of security events are important topics.
SOC services can help organizations develop continuous security visibility and event detection capabilities.
SOC and Monitoring Isolated Networks
The presence of a Red Network, Green Network or other isolated network architectures should not mean the removal of security visibility.
In suitable architectures, SecureSys can enable the;
- security logs,
- endpoint events,
- firewall records,
- authentication events
of isolated systems to be forwarded to the SOC infrastructure in a controlled way.
In structures requiring high security, architectures such as one-way log transfer can be evaluated.
SOC and Cold Backup Security
In ransomware attacks, backup systems are one of the attackers' targets.
In SOC operations, monitoring critical events on backup systems such as;
- administrator activity,
- backup job changes,
- deletion operations,
- failed backup operations
can be evaluated.
This approach creates a security layer that complements Cold Backup and isolated backup architectures.
SOC Health Check
Evaluating periodically whether an existing SOC or SIEM infrastructure really works effectively is important.
Within the SecureSys SOC Health Check;
- log coverage,
- SIEM use cases,
- false positive rates,
- critical asset coverage,
- MITRE ATT&CK coverage,
- escalation processes,
- SOC KPIs
can be assessed.
SOC Maturity Analysis
SOC operations should be developed over time.
In a maturity assessment;
People + Process + Technology
are analyzed together.
The aim is to evaluate not simply whether the organization owns security products, but how quickly it can genuinely detect and respond to attacks.
The SecureSys SOC 7x24 Service Process
1. Discovery and Asset Analysis
The organization's critical systems and security infrastructure are identified.
2. Integration of Log Sources
Firewall, server, AD, EDR/XDR, network and other systems are integrated into SIEM.
3. Use Case Development
Security scenarios are created according to the organization's risk profile.
4. Tuning
False positives are reduced and detection rules are optimized.
5. 7x24 Monitoring
Security events are followed continuously.
6. L1 Analysis
Alarms are validated and classified.
7. L2/L3 Investigation
Detailed technical analysis is carried out for critical events.
8. Escalation and Response
Confirmed security events are escalated according to the defined procedures.
9. Threat Hunting
Suspicious behavior is investigated proactively.
10. Reporting and Improvement
Operational results are reported and detection capability is developed continuously.
Why the SecureSys SOC 7x24 Monitoring Service?
An effective SOC is not simply keeping a SIEM screen open at all times.
The different traces an attacker leaves across the firewall, endpoint, Active Directory, network, cloud and application layers must be evaluated as parts of the same attack chain.
In the SecureSys SOC approach, the;
SIEM + SOAR + EDR/XDR + NDR + Threat Intelligence + Threat Hunting + Incident Response
capabilities can be handled together.
SOC operations can also be supported by SecureSys;
- Penetration Testing,
- Red Team,
- Active Directory Security,
- Network Security,
- Firewall,
- MDR/XDR,
- NDR,
- SIEM/SOAR,
- Cyber Threat Intelligence,
- Incident Response
capabilities.
This approach aims to build an integrated security operations model that focuses on understanding attack behavior rather than simply watching alarms.
Frequently Asked Questions
What is a SOC service?
A SOC service is the security operations service that allows an organization's cyber security events to be monitored centrally, analyzed, prioritized and, where required, incident response processes to be started.
Does the SOC run 7x24?
Depending on the service model, SOC operations can be run continuously, 7 days a week and 24 hours a day.
Are SOC and SIEM the same thing?
No. SIEM is a log collection and correlation technology. A SOC is the security operations structure made up of security analysts, processes and technologies.
What is SOC as a Service?
SOC as a Service is the model that allows organizations to receive a managed security operations service without building a full-scale SOC in house.
What is Managed SOC?
Managed SOC is the continuous management of an organization's security monitoring and event analysis processes by an expert security service provider.
What is the difference between MDR and SOC?
A SOC can cover broader security monitoring and event management processes. MDR focuses particularly on detecting, investigating and responding to threats. The two services can work together.
Which systems does the SOC monitor?
Firewall, Active Directory, Windows/Linux servers, EDR/XDR, NDR, VPN, WAF, database, PAM, DLP, cloud and other log-generating systems can be brought into SOC scope.
Can the SOC detect ransomware?
Analyzing EDR/XDR, SIEM and network security data together can help detect the different stages of ransomware attacks.
Does the SOC monitor Active Directory attacks?
Yes. Failed logins, privilege changes, suspicious administrator activity and other authentication events can be analyzed.
Does the SOC respond to incidents?
Depending on the service and authorization model, the SOC can escalate events or apply active response actions on defined systems.
Is Threat Hunting carried out within the SOC service?
Depending on the service scope, proactive Threat Hunting work can be carried out.
Are SOC reports provided?
Yes. Periodic security reports can be prepared at both operational and executive level.
Monitor Cyber Threats 7x24 with the SecureSys SOC
Cyber security products are critically important for preventing and detecting attacks. But when the thousands of events those security systems generate are not analyzed correctly, real attacks can be lost in the volume of alarms.
With the SecureSys SOC 7x24 Monitoring Service you can monitor security events from your firewall, Active Directory, servers, endpoints, network, cloud and critical applications centrally; correlate suspicious activity with attack chains; and respond faster to critical events.
Contact SecureSys for detailed information on SOC 7x24 Monitoring, Managed SOC, SOC as a Service or MDR services, and to build a SOC service model specific to your organization.
Do not wait for cyber attacks to happen. Monitor your infrastructure 7x24, detect threats early and shorten your response time.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.