SOC workflow, monitoring, telemetry, network/host evidence, IR logic & automation practice for CBRCOR 350-201