security Role playbook · SOC_ANALYST

SOC Analyst

Tier-1 and Tier-2 SOC analysts working an alert queue across one or more aviation customers.

Audience: SOC tier-1 / tier-2Time to first value: end of first shift (≈ day 2)

Why CyViation matters in your role

You already work an alert queue. CyViation gives you the aviation context that turns a generic detection into an operational decision:

wb_sunnyDaily playbook

  1. Triage the queue by severity × asset criticality × customer SLA. Tail-in-flight beats a parked sim.
    [SkyRay → Alert Queue]
  2. Investigate high-confidence detections in the workbench — telemetry, asset, recent CMBs and the related Overwatch campaign in one pane.
    [SkyRay → Incident Workbench]
  3. Close false positives with reason codes — empty closures are the biggest tuning blocker.
  4. Sync with the on-call dispatcher for any alert that could affect a flight in the next 4 hours.
  5. End-of-shift handover — short written note in the workbench thread, not chat.

event_repeatWeekly playbook

  1. Author a weekly threat brief — 1 page, written for pilots and dispatchers.
  2. Tune detection rules; low-precision rules go on a review list with a deadline.
  3. Threat-hunt one campaign hypothesis from the Overwatch feed against your fleets.
    [Overwatch → Campaign View]
  4. Review escalations to CISO — what could have been resolved without escalation? what should have escalated sooner?
  5. Tabletop or live-fire at least once a month, even if short.

checklistFirst 30 days

grid_viewKey screens

Use caseScreen
Triage the queue[SkyRay → Alert Queue]
Investigate an incident[SkyRay → Incident Workbench]
External threat context[Overwatch → Threat Intel Feed]
Campaign / actor view[Overwatch → Campaign View]
Reverse-engineering assistance[Cortex → RE Assistant]
Live operational pictureDispatcher OCC

priority_highWhen to escalate

SituationWhoHow
Alert could affect a flight in the next 4 hoursDispatcher on-callPhone, then workbench note — not chat-only
Credible spoofing / jamming in active corridorDispatcher + Fleet ManagerLive alert in workbench, then call
Suspected avionics supply-chain compromiseCISO + MRO duty managerWorkbench escalation, no public chat
Detection logic looks broken (mass FPs)SOC lead → detection engineeringPause the rule, don't just silence it

menu_bookGlossary

Full list on the Glossary page. Key terms here: tail, phase of flight, CMB, tabletop, risk acceptance.