{
  "id": 8278586,
  "title": "SOC: conhecendo uma das áreas da Cibersegurança",
  "url": "https://urgent.news/2026/09/18/soc-conhecendo-uma-das-areas-da-ciberseguranca",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T17:34:40.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/alessandra_guimaraes/soc-conhecendo-uma-das-areas-da-ciberseguranca-16om"
  },
  "original_language": "pt",
  "account": "In the rapidly evolving world of technology, businesses face growing challenges related to security for systems, networks, and data. This is where Cybersecurity comes into play, an area I have become increasingly interested in. As a second-semester student of Information Systems Analysis and Development at UNICID, my professional goal is to pursue a career in Cybersecurity, with a focus on SOC (Security Operations Center). In this article, I will discuss some of the concepts I've learned about this field and provide a deeper understanding of how a SOC operates.\n\nA SOC, or Security Operations Center, is a centralized unit that combines people, processes, and technologies to monitor and protect technological environments. It gathers information from various systems and devices in a company that can be used to assess security. The primary responsibility is to monitor these events and identify situations that could indicate a threat.\n\nWithin a SOC team, a SOC Analyst plays a crucial role in examining security-related events and alerts. Key activities include monitoring alerts, analyzing logs, investigating suspicious activities, identifying and classifying potential incidents, recording occurrences, forwarding incidents when necessary, and supporting incident response processes. It's important to remember that not every alert signifies an actual attack, which is why thorough analysis is essential. The analyst must review the available information, seek context, and verify if the behavior truly poses a risk.\n\nOne of the key concepts for those starting to study SOC is logs. Logs are records created by systems, applications, servers, network devices, and other components within a technological environment. They can track information such as date and time, user, IP address, action performed, system accessed, and outcome of the action. For example: \"18/09/2026 09:32 User: user01 IP: 192.168.1.25 Event: failed login Result: failed\". Although a single log entry may seem insignificant, when combined with many other events, patterns may emerge that help identify suspicious activities.\n\nAnother related concept is the Blue Team, which is associated with the defensive perspective in Cybersecurity. This involves activities focused on protecting technological environments. Within this context, there might be activities such as monitoring, threat detection, event analysis, investigation, incident response, and improving defensive mechanisms. The SOC can be part of this defensive structure, depending on the organization and how its security area is structured.\n\nMonitoring is crucial in a company with hundreds of computers, servers, applications, and user accounts. Manually tracking everything within this environment would be extremely difficult. That's why monitoring tools and processes help identify events that require attention, transforming a large amount of data into information that can be analyzed by the team responsible for security.\n\nMy personal connection to this subject began when I started researching the various possibilities within Cybersecurity. As a student of Information Systems Analysis and Development, I am building my foundation in technology while simultaneously directing my studies towards security. Some important knowledge areas for this preparation include programming logic, computer networks, operating systems, Linux, cybersecurity fundamentals, information security, logs, and monitoring. My degree also helps me understand how systems and applications are constructed, while cybersecurity studies allow me to view these environments from a protective perspective.\n\nLooking ahead, I plan to deepen my understanding of various topics such as networks, Linux, logs, monitoring, SIEM, and incident response. Gradually, I aim to build this knowledge base. Additionally, I intend to use Dev.to to record other content related to my studies and projects throughout my graduation.\n\nIn conclusion, the SOC is one of the areas that most sparked my interest within Cybersecurity due to its involvement in monitoring, analysis, and defense of technological environments. For those beginning their journey in this field, concepts such as SOC, logs, SIEM, and the Blue Team help understand how different elements can collaborate in the identification and treatment of security events. Currently, I am in my second semester of Information Systems Analysis and Development at UNICID, and this is one of the first topics I have begun to explore in the context of my future professional career in Cybersecurity. This article marks the beginning of my journey in this area.",
  "summary": "🔐 Introdução A tecnologia está cada vez mais presente nas empresas, e junto com essa evolução também aumentam os desafios relacionados à segurança de sistemas, redes e informações. Foi conhecendo melhor esse cenário que comecei a me interessar por Cibersegurança. Sou estudante do 2º semestre de Análise e Desenvolvimento de Sistemas na UNICID e tenho como objetivo profissional seguir na área de…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}