ML4SOC: A Comprehensive Review on Machine Learning for Security Operations Centres
Felix Waschke, Risto Vaarandi, Alejandro Guerra-Manzanares · ACM Computing Surveys · 2026
This literature review examines the application of Machine Learning (ML) within Security Operations Centres (SOCs), providing a comprehensive analysis of academic research in this domain. SOCs have become a critical component of organisational cybersecurity infrastructure, playing a central role in operational defense. However, existing literature reviews have either overlooked the role of using ML in SOC environments (ML4SOC) or have only addressed a limited subset of the available research. In contrast, this study analyses 171 peer-reviewed publications to offer a broad and systematic overview of the field. Given the increasing complexity of the digital threat landscape, ML presents a promising avenue for enhancing SOC capabilities, particularly in processing large volumes of data with reduced human intervention. This review identifies key SOC functions where ML has been most actively applied, including intrusion detection, alert handling, cyber threat intelligence, and malware detection. Beyond mapping application areas, the study also explores the most commonly employed ML methods, the datasets used, and the prevailing research gaps and challenges. By synthesising these findings, the review highlights underexplored areas and outlines a number of research directions that deserve further investigation. These insights aim to guide future research efforts and foster the development of more effective, scalable, and intelligent SOC solutions.