Building and maintaining a modern-day SOC can be an overwhelming challenge. What are the right technologies to use? What’s going to have the most impact to your security program? Where should you spend your limited budget in a sea of overlapping solutions? As leads of the Black Hat NOC, we often get asked these questions and more, and we’ve spent the last 23 years learning the answers, sometimes the hard way. There were many successes, there were many failures, and all of it led to an understanding of where to invest time, money, or both if you’re trying to defend a network when it really counts. Let’s explore how organizations can make strategic choices by leveraging open source tools to fill critical gaps, or even replace commercial solutions outright, and where vendors get it wrong, right(*gasp*), or fall somewhere in between.