Getting Started with TripleSOC
This guide walks you through the TripleSOC dashboard so you can start monitoring your environment right away.
Accessing the Dashboard
TripleSOC is a web-based platform. Your administrator will provide you with:
- Dashboard URL — typically hosted on your organization's internal network or a dedicated server
- Your credentials — username and password provided by your administrator
- Your role — Admin, Analyst, or Viewer (controls what you can see and do)
Log in at the dashboard URL using your assigned credentials.
The Security Overview
After logging in, you land on the Security Overview dashboard. This is your mission control.
What You See
- Active Agents — how many endpoints are reporting to TripleSOC right now
- Total Alerts — alerts in the current time window, broken down by severity (Critical, High, Medium, Low)
- Trust Zone Distribution — breakdown of agents across Anonymous, Verified, and Secure zones
- Threat Volume Chart — alert trend over the last 7 days
- Top Attack Techniques — MITRE ATT&CK techniques appearing most in recent alerts
Time Window
Use the time selector (top right) to change the view from the last 24 hours to 7 days, 30 days, or a custom range.
Navigating the Platform
The left sidebar is your main navigation. The key sections are:
| Section | What it shows |
|---|---|
| Security Overview | High-level threat posture at a glance |
| Alerts | All alerts with filtering, search, and investigation tools |
| Agents | All monitored endpoints — status, zone, last seen |
| MITRE ATT&CK | Coverage map against the MITRE framework |
| Threat Hunting | Advanced queries for proactive threat search |
| Vulnerabilities | CVEs detected across your environment |
| File Integrity | File change monitoring across critical paths |
| Compliance | Policy compliance status across regulatory frameworks |
| SCA | Security Configuration Assessment results |
| Malware Detection | Identified malware and suspicious executables |
Understanding Alert Severity
TripleSOC classifies alerts into four severity levels:
| Severity | Description |
|---|---|
| Critical | Immediate action required. Active exploitation or confirmed breach indicator. |
| High | Serious threat. Investigate within hours. |
| Medium | Suspicious activity. Review and assess. |
| Low | Informational. Low risk but worth tracking for patterns. |
Your First Actions
- Check Agents — go to the Agents section and confirm all expected endpoints are reporting
- Review Critical Alerts — filter alerts by Critical severity and review any open items
- Check Compliance Status — go to Compliance and review your organization's current posture
- Explore MITRE Coverage — see which attack techniques your detection rules cover
Need Help?
- What is TripleSOC?
- Understanding Trust Zones
- Key Features Overview
- Contact your TripleCyber administrator or email support@triplecyber.com