How Does Tier 2 SOC Automation Work?
Tier 2 SOC work picks up evidence gathering across consoles, containment decisions, sandbox detonation and verdicting, sweeping new indicators through historical data, and the case documentation and handoff that follow. Tier 1 work is linear enough to enumerate, so a playbook can list the steps. Tier 2 investigations branch, since each answer changes the next question, and no engineer can pre-write every path and that is why SOAR does not do well in Tier 2 even in teams where it works well at tier 1.