@chrissanders88 I've found the function of SOC analysts has a degree of variability. Some teams equip their analysts to triage alerts from start to end (my preference) others usually just initial "oh this doesn't look good I should escalate".
@SecureOwl American stuff is confusing but a federally owned platform that had a page per state so it's not subject to as much manipulation and you can goto one place to see all past updates might be cool