5G Security Operations — SOC for 5G Core Networks · Pro
Mature 5G SOCs structure hunting as a discipline alongside alert triage and detection engineering. Allocation: dedicate 10-25% of analyst hours to hunting. Some SOCs have dedicated hunt analysts; others rotate analysts through hunt time. Without explicit allocation, hunting is starved by alert triage. Hypothesis pipeline: a hypothesis backlog maintained by the threat intel team or SOC management, prioritized by threat likelihood and execution effort. Hypotheses come from threat intel feeds, FiGHT coverage gap analysis, post-incident lessons, and analyst intuition. Execution: weekly or…