MITRE ATT&CK Framework: Arsitektur Deteksi dan Cara Mengukur Cakupan SOC yang Sebenarnya
Panduan arsitektur deteksi MITRE ATT&CK framework, distribusi 15 taktik, logika korelasi SIEM, dan cara mengukur efektivitas cakupan SOC yan...
By Cisometric Marketing Team, Published on September 7, 2026
A Security Operations Center (SOC) can process thousands of security signals and alerts across an organization's environment, but generating an alert is only the beginning.
A detection rule identifies activity that matches a defined condition within available telemetry. It does not, by itself, determine whether that activity represents malicious behaviour, legitimate activity, or a false positive. The investigation that follows requires analysts to validate the signal, correlate evidence, assess severity, determine scope, and decide what response is appropriate.
This is where the structure of the SOC team becomes important.
Also read: Behind the Screens: The People Powering Your SOC
A tiered analyst model provides a framework for distributing investigative responsibilities according to the complexity of the activity, scope of the investigation, and technical expertise required. The objective is not simply to move an alert from L1 to L2 to L3, it is to ensure that the right level of analysis is applied at the right stage of an investigation.
A detection rule operates against defined conditions in security telemetry, and when those conditions are met, an alert is generated. However, the alert itself is not the conclusion. The first question for the SOC is whether the observed activity represents a genuine security event.

SOC analysts may need to establish:
Is this a true positive, benign activity, or false positive?
Which asset, identity, application, or environment is involved?
Is there supporting evidence in other telemetry?
What is the potential scope of the activity?
How critical is the affected asset or identity?
Does the available evidence indicate a broader attack?
Does the investigation require additional technical expertise?
This requires analysts to move beyond the original detection and build context from multiple sources.
Relevant evidence may include:
Endpoint, identity, network, application, and cloud telemetry
Process trees and command-line activity
Authentication history and privilege information
Source and destination relationships
Historical behaviour of the affected user or asset
Indicators of compromise (IOCs)
Tactics, techniques, and procedures (TTPs)
Asset criticality and exposure
[Visual Direction]
The objective is not simply to determine whether an alert is suspicious, but to establish what happened, how significant it is, and what should happen next.
Once an alert enters the SOC, the investigation can be distributed across different analyst tiers. The tiered model is not a hierarchy of seniority. Each level provides a different degree of investigative depth and operates within a different scope of responsibility.
Tier | Primary Investigation Focus |
L1 | Initial validation, enrichment, triage |
L2 | Deeper investigation, correlation, scoping, response |
L3 | Advanced analysis, threat hunting, complex investigations |
The exact operating model can vary between organizations, but the underlying principle remains consistent, that the investigation should be escalated when the complexity or technical requirements exceed the current investigation scope, while maintaining continuity of context across the tiers.
The objective is to determine whether the alert can be resolved through established procedures or whether additional investigation is required.

This involves:
Validating the detection against available telemetry
Reviewing affected assets and identities
Performing initial enrichment
Checking known benign patterns and documented exclusions
Applying established investigation procedures and playbooks
Determining initial severity and priority
Documenting findings and investigation context
Escalating activity that falls outside the defined investigation scope
L1 is not simply responsible for checking alerts. The analyst must establish enough evidence and context to make an informed decision about what happens next.
For well-understood scenarios, L1 may be able to complete the investigation and execute the appropriate response without escalation. When the evidence indicates greater complexity or requires investigation beyond established procedures, the case can move to L2.
The role of L1 is therefore to establish sufficient context for an accurate initial decision: resolve, respond, or investigate further.
When an alert cannot be adequately resolved through initial triage, the investigation requires broader analysis. L2 focuses on understanding what happened, how the activity developed, and how far it extends across the environment.

This can involve:
Correlating telemetry across multiple sources
Examining endpoint and authentication activity
Connecting related events across systems and identities
Identifying affected assets and accounts
Reconstructing potential attack paths
Determining the scope of suspected compromise
Applying threat intelligence and additional context
Determining appropriate containment or remediation actions
The investigation therefore moves from individual alert validation toward incident reconstruction.
For example, an authentication anomaly may initially appear isolated. Correlation with endpoint activity, network connections, privilege changes, or additional authentication events may reveal that the activity forms part of a larger attack sequence.
The investigation therefore becomes a process of correlation, scoping, and reconstruction.
Some investigations require capabilities beyond conventional alert triage and incident analysis.
L3 provides the technical depth required for advanced investigations, including cases involving sophisticated attack behaviour, incomplete evidence, or activity that has not been captured effectively by existing detection mechanisms.

Activities can include:
Advanced threat investigation
Threat hunting
Forensic analysis
Complex attack-path reconstruction
Analysis of sophisticated or previously unseen attack patterns
Advanced malware or packet analysis
Detection improvement based on investigation findings
L3 activity can also be proactive.
A key distinction is that L3 activity does not have to begin with an existing alert. Threat hunting, for example, is a proactive activity in which analysts search for indicators of adversary activity that may have bypassed existing detection logic.
This creates two complementary investigation paths:
Reactive investigation begins with a detected event and works toward understanding and responding to the activity.
Proactive investigation searches for evidence of adversary activity that may not have generated a conventional alert.
L3 therefore serves as an advanced technical capability within the broader investigation process, rather than simply functioning as the final escalation point for every unresolved alert.
Escalation between SOC tiers should not be treated as a measure of how important an alert becomes. The requirement for escalation is determined by the investigation characteristics and technical capabilities required to resolve the case.
Relevant factors can include:
Complexity of the observed activity
Scope of suspected compromise
Criticality of affected assets
Privilege level of affected identities
Confidence in the detection
Availability of supporting evidence
Required technical expertise
Potential business impact
Containment and remediation requirements
For example, consider two alerts generated by the same detection rule:
One may involve a standard user endpoint and activity that corresponds to a known benign pattern. The investigation may therefore be resolved through established L1 procedures.
Another alert may involve a privileged identity, multiple endpoints, and activity that cannot be explained through the available evidence. The investigation may require broader correlation and scoping at L2, followed by advanced technical analysis at L3.
The detection is similar. The investigation requirements are not.
This is why escalation criteria should be based on investigation complexity, evidence, scope, and required expertise rather than simply progressing every alert through L1, L2, and L3 sequentially.
The differences in the SOC tier scope do not mean that one tier is more valuable than another. Each tier contributes findings and context that can support the investigation at other levels.
The tiers therefore function as a connected investigation chain, where findings from one level can inform contexts and decisions at another rather than being treated as separate or isolated activities, and will be carried forward as an incident develops.

An L1 analyst's initial validation and enrichment can provide important context for an L2 investigation, while L2 findings can help L3 analysts understand the broader attack activity. The flow also works in reverse, with findings from deeper investigation or threat hunting improving detection logic, enrichment, and investigation procedures used at earlier stages.
A tiered analyst structure is ultimately about matching the right level of technical capability to the investigation at hand. That means building a SOC requires more than enough people to monitor alerts. Therefore, the team needs:
Clearly defined escalation criteria
Analysts need to understand when an incident can be resolved within their current scope and when additional expertise is required.
Differentiated technical capabilities
Each tier should have the knowledge and technical exposure needed to perform its responsibilities effectively.
Consistent investigation procedures
Documented processes help analysts handle known scenarios consistently while providing clear points for escalation when those procedures are no longer sufficient.
Relevant telemetry and security tooling
Investigation quality depends on the evidence available to the analyst. Endpoint, identity, network, application, and cloud telemetry can provide different pieces of the same incident.
Context transfer between tiers
Escalation should preserve the evidence, reasoning, and findings already established rather than forcing the next analyst to restart the investigation.
Continuous improvement
Investigation findings should feed back into detection logic, enrichment, automation, procedures, and other parts of the security operation.
This reflects a broader SOC principle: people, process, and technology need to work together, to ensure that security events receive the appropriate level of analysis, technical expertise, and response based on their characteristics and potential impact.
A SOC's effectiveness is ultimately determined by how well it can turn security signals into informed investigation and response decisions.

This requires more than generating alerts or maintaining coverage. An effective SOC needs to be able to:
Validate whether detected activity represents a genuine security event
Correlate evidence across relevant telemetry and security sources
Prioritize incidents based on severity, scope, asset criticality, and potential impact
Respond according to the investigation findings and technical requirements
Improve detection, investigation procedures, and response capabilities based on lessons from previous incidents
A tiered analyst model supports this process by distributing investigation responsibilities according to complexity, scope, and required technical expertise. L1, L2, and L3 should therefore operate as a connected investigation chain, where findings and context are carried across tiers rather than treating each level as an isolated function.
For organizations evaluating or building a SOC, the key consideration is not simply whether these tiers exist. It is whether the people, processes, and technology behind them can work together to maintain investigation depth and continuity from initial detection through response.
At Cisometric, our Security Operations Center applies this principle through a structured approach to security monitoring, investigation, and incident response.

To learn more about how the Cisometric SOC supports security operations, explore our Security Operations Center.
Stay connected with Cisometric for more insights on SOC, AI-powered threats, cyber resilience, and digital trust.
LinkedIn: Cisometric
Instagram: @cisometric
Youtube: @Cisometric
L1, L2, and L3 are analyst tiers used to distribute security investigation responsibilities based on investigation complexity, scope, and required technical expertise. L1 typically handles initial validation, enrichment, and triage; L2 expands the investigation through correlation, scoping, and response; while L3 handles advanced analysis, threat hunting, and complex investigations.
The tiers should not be interpreted as a simple hierarchy of analyst quality. In an effective SOC, each tier contributes different investigative capabilities and shares context across the investigation chain. Cisometric applies this tiered approach as part of its Security Operations Center operations.
SOC alert escalation should be driven by the requirements of the investigation, rather than automatically moving every alert from L1 to L2 and then L3. Factors such as suspected compromise scope, affected asset criticality, privilege level, available evidence, attack complexity, and required technical expertise can determine whether deeper investigation is necessary. A well-understood alert may be resolved at L1, while a multi-stage attack involving multiple systems or identities may require L2 or L3 analysis.
For Cisometric, this principle supports a structured investigation process where escalation is based on what the incident requires, while preserving investigation context between analyst tiers.
The primary difference is investigation scope and technical depth, rather than simply seniority.
L1 establishes whether an alert requires further investigation through validation, enrichment, and triage.
L2 expands the investigation through evidence correlation, scoping, attack-path reconstruction, and response.
L3 applies advanced technical analysis, threat hunting, forensic investigation, and complex attack analysis.
These capabilities are complementary. Findings from L1 can provide critical context for L2, while deeper L2 or L3 findings can improve detection logic and investigation procedures used earlier in the process. This connected approach is also central to how Cisometric structures SOC investigations.
A detection rule only identifies activity that matches a defined condition. Determining whether it represents a real threat requires analysts to correlate the alert with additional context.
This can include endpoint and identity telemetry, authentication history, process activity, network connections, historical behaviour, threat intelligence, IOCs, TTPs, and asset criticality. Analysts then assess whether the activity is a true positive, benign activity, or false positive, as well as its potential scope and impact.
This evidence-driven approach is important in Cisometric's SOC because effective investigation requires moving beyond the original alert to understand what happened, how far the activity extends, and what response is appropriate.
An effective SOC combines people, process, and technology rather than relying on alert volume or security tooling alone.
From an operational perspective, this means having differentiated analyst capabilities, clearly defined escalation criteria, consistent investigation procedures, sufficient telemetry, appropriate security tooling, and mechanisms for transferring investigation context between tiers. Just as importantly, findings from investigations should feed back into detection, enrichment, automation, and response processes.
Cisometric's SOC follows this broader operating principle, connecting security monitoring, investigation, escalation, and response rather than treating alert handling as an isolated activity.
Panduan arsitektur deteksi MITRE ATT&CK framework, distribusi 15 taktik, logika korelasi SIEM, dan cara mengukur efektivitas cakupan SOC yan...
A phishing email can now be written with near-perfect grammar, a fake executive voice can sound familiar enough to trigger trust,
Linux is widely used across modern business infrastructure. It runs on cloud servers, workstations, network appliances, security tools, cont...
Search Article by Category
We use cookies to enhance your browsing experience, analyse site traffic, and deliver relevant content. Choose which cookies you allow. Privacy Policy