Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Skills in the SOC: what they change for analysts


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20026
Topic starter  

TL;DR: SOC performance degrades when investigation know-how lives in individual analysts rather than in repeatable workflows, according to Crogl. Its Skills feature tries to encode that knowledge into structured, on-demand guidance that an agent can apply consistently during triage and threat hunting, and the governance question is not whether automation helps, but whether institutional analyst judgment can be captured without turning the SOC into a stale runbook repository.

NHIMG editorial — based on content published by Crogl: Level the Playing Field in Your SOC with Skills

By the numbers:

Questions worth separating out

Q: How should SOC teams capture analyst expertise without relying on static runbooks?

A: SOC teams should turn the repeatable parts of analyst expertise into governed workflows that trigger in context, rather than burying them in documents that people must remember to find.

Q: Why do investigation workflows break down when knowledge lives only with senior analysts?

A: Workflows break down because the team loses consistency, not just information.

Q: What mistakes do teams make when they try to document SOC procedures?

A: The most common mistake is treating documentation as the control instead of the reference.

Practitioner guidance

  • Codify your highest-value investigation paths Identify the alert types, advisories, and threat hunts that senior analysts handle best, then convert those steps into structured workflows with explicit triggers, outputs, and escalation points.
  • Assign ownership for skill lifecycle management Treat each Skill as governed content with an owner, review cadence, and version history so environment changes do not turn guidance into stale operational risk.
  • Standardise evidence extraction across analysts Require consistent collection of hashes, IPs, domains, filenames, and ATT&CK mappings so every investigation starts from the same evidence baseline.

What's in the full article

Crogl's full blog covers the operational detail this post intentionally leaves for the source:

  • How Skills are structured in a SKILL.md directory and triggered during investigations
  • The threat hunt workflow Crogl uses to extract hashes, IPs, domains, filenames, and ATT&CK mappings
  • How analysts can create, edit, duplicate, export, and manage Skills in the UI
  • The practical difference between a structured Skill, a prompt template, and a static runbook

👉 Read Crogl's blog on Skills for SOC investigations and analyst consistency →

Skills in the SOC: what they change for analysts?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19617
 

Skills are the right abstraction for SOC institutional memory, but only when they are governed as operational control content. A skill library can preserve investigation logic, reduce variance, and improve handoffs, but it must be curated like any other control asset. If Skills drift, the organisation simply automates inconsistency. The practical conclusion is that SOC knowledge capture needs ownership, review, and lifecycle management, not just authoring convenience.

A question worth separating out:

Q: When is a structured investigation skill better than a traditional runbook?

A: A structured investigation skill is better when the task is recurring, time-sensitive, and dependent on local context. In those cases, the workflow needs to load at the moment of use and produce a consistent output, while a runbook still depends on human retrieval and interpretation.

👉 Read our full editorial: Skills as operational memory for SOC investigations



   
ReplyQuote
Share: