09/22/2026

How a Managed SOC works: What happens when a cyberattack begins?

How a Managed SOC works: What happens when a cyberattack begins? Business

(This text was translated from English into German with the help of AI.)

Let’s imagine the following scenario: An employee in the HR department of a medium-sized company receives an email containing what appears to be a job application. The message and the attachment look legitimate, so she opens the file. She is curious. The vacancy in the accounts department has been unfilled for some time. In the background, the document is now attempting to launch other programs, such as PowerShell or other system commands. This process remains invisible to the employee. For G DATA CyberDefense’s Managed Security Operations Centre, however, it is precisely this behaviour that serves as a key indication that something is amiss.

Suspicious activity detected

As soon as the sensors detect unusual behaviour, an incident is automatically logged in the system. This appears immediately on the analyst team’s screens in the SOC, where it is taken over and assessed.

The initial focus is not on assuming that a successful attack has taken place straight away. Rather, the analysts ask themselves questions such as:

  • Has any known malware been detected?
  • Has it already been stopped?
  • Have any further processes been launched?
  • Is there any evidence that the attack is already spreading?

This initial assessment – known as triage – determines whether the incident is a minor one or a genuine security incident.

Not every alert is an attack

Particularly at the start of a collaboration with a company, a Managed SOC familiarises itself with the specific IT environment of its client organisation. Many particular features have already been discussed during the onboarding process. Analysts become familiar with other specific details as they carry out their work.

For example, many administrators use tools for network inventory or system administration. Some of these behave in a similar way to attackers, as they scan networks or access numerous systems simultaneously. For the G DATA team, this means they carefully review every alert and cross-check it against the actual IT landscape. If necessary, they check with the client or document known management tools for future assessments. This continuously reduces the number of unnecessary queries and makes the analysis increasingly efficient.

The analysis goes much deeper

If an incident proves to be suspicious, the actual investigation begins. The team of analysts examines not only the detected file, but the entire sequence of related activities. They analyse process chains, check which programmes have been launched and look for signs that the attacker may have left further traces. For example, was the malware stopped, but had it managed to install a backdoor on the network beforehand? Have user rights been altered? Are there any other anomalies? Depending on the service level, the specialists can access the affected endpoint directly, examine files, terminate processes or isolate systems. The aim is always to contain the attack as early as possible and prevent it from spreading across the network.

Particularly critical: Stolen login credentials

Not every attack begins with malware. Increasingly, groups of attackers first steal usernames and passwords via fake login pages. Alternatively, they may have purchased this information beforehand on the dark web. They then log into the corporate network using genuine login credentials.

These attacks are particularly dangerous because they initially appear to be perfectly normal user activity. However, a managed SOC also detects unusual behaviour from legitimate user accounts. If an employee’s account suddenly moves across several servers, scans the network or attempts to access systems that are normally never used, corresponding alerts are triggered.

The team of analysts then checks, for example:

  • Is this behaviour consistent with the user account?
  • Has the account recently been granted new permissions?
  • Has a new administrator account perhaps even been created?
  • Is this a legitimate change or an attack?

If in doubt, compromised accounts are immediately deactivated before any major damage occurs.

People and technology work hand in hand

A modern managed SOC does not operate solely on an automated basis. Artificial intelligence and detection mechanisms identify suspicious activities and prioritise them. However, the actual assessment is carried out by experienced security analysts. They analyse technical information, evaluate the context and decide on appropriate countermeasures. It is precisely this combination that ensures attacks are not only detected quickly but also assessed correctly.

When is the customer involved?

Many incidents are analysed and resolved entirely by the Security Operations Centre without the customer having to take any active action. Only when decisions need to be made or further action is required is there consultation with the relevant contacts within the organisation. This includes, for example:

  • Confirmation of unusual administrator activity
  • Recommendations to install important security updates
  • Notifications of misconfigurations
  • Possibly a recommendation to reinstall a system as a precautionary measure

This keeps the operational burden on the customer’s IT department to a minimum.

Where does Managed Extended Detection and Response end?

Not every incident escalates into a major incident. If the SOC can fully trace the attack and contain it securely, Managed Extended Detection and Response is sufficient in many cases. The situation is different if an attacker has been active on the network undetected for some time or may have established a permanent foothold. In such cases, mere threat mitigation is no longer enough. The G DATA Security Operations Centre recommends an Incident Response or a Compromise Assessment – a thorough investigation of the IT systems (to detect ongoing and hidden cyber-attacks). The aim is to trace the entire attack without omission, identify any remaining points of access and completely clean up the corporate network.Not every incident escalates into a major incident. If the SOC can fully trace the attack and contain it securely, Managed Extended Detection and Response is sufficient in many cases. The situation is different if an attacker has been active on the network undetected for some time or may have established a permanent foothold. In such cases, mere threat mitigation is no longer enough. The G DATA Security Operations Centre recommends an Incident Response or a Compromise Assessment – a thorough investigation of the IT systems (to detect ongoing and hidden cyber-attacks). The aim is to trace the entire attack without omission, identify any remaining points of access and completely clean up the corporate network.

Successful cyber defence begins long before encryption

Many companies only associate cyber attacks with encrypted servers or system failures. In fact, there is often a considerable time lag between the initial intrusion and any visible damage. It is precisely during this phase that a Managed SOC delivers its greatest benefit: it detects suspicious activity at an early stage, assesses it in the correct context and initiates countermeasures before a single click turns into a corporate crisis. Modern cyber defence today means not only detecting attacks, but also, where possible, stopping them before they cause any damage at all.



Kathrin Beckert-Plewka

Kathrin Beckert-Plewka

Public Relations Manager


Share Article