1. Alert Monitoring & Initial Triage
- Monitor the security alert queue continuously across shift, ensuring no alerts are missed, delayed, or left without an initial disposition.
- Perform initial triage of incoming alerts: review alert context, classify by type and potential severity, and determine whether the alert warrants escalation or closure as a false positive.
- Apply documented playbooks and runbooks to guide triage decisions; escalate promptly to L2 when an alert exceeds L1 scope or confidence threshold.
- Maintain accurate, timely documentation of all triage actions: alert details, initial findings, disposition rationale, and escalation notes.
- Support shift handoff quality by ensuring all open items are clearly documented and communicated to the incoming analyst.
2. ReliaQuest GreyMatter
- Use GreyMatter as the primary platform for alert review, case management, and initial investigation workflows.
- Navigate GreyMatter case queues, apply filters,
and use built-in enrichment and AI-assisted features to support triage decisions — always validating outputs before acting.
- Document findings, disposition notes, and escalation rationale within GreyMatter case records in accordance with SOC documentation standards.
- Develop proficiency with GreyMatter investigation workflows through structured on-the-job learning and guidance from L2 analysts and the SOC Manager.
3. Microsoft Defender for Endpoint
- Review MDE alerts surfaced through GreyMatter or the MDE portal; understand alert categories, severity levels, and associated device context.
- Perform basic endpoint investigation tasks: review device timelines for obvious indicators, check process trees, and identify key artifacts to include in escalation notes.
- Understand and apply MDE alert triage criteria to support accurate initial severity classification.
4. Microsoft Sentinel
- Review Sentinel incidents and alerts as part of the monitoring queue; understand alert sources and th