Detection cannot be outSOARced. After integrating so many tools and… | by Alex Teixeira | Detect FYI
After integrating so many tools and data sources into all sorts of security monitoring workflows and processes, let me share a few thoughts in regards to SOAR and how it actually helps (or hinders) the challenge of threat detection based on log telemetry, usually tackled via a SIEM. Before exploring this question, let me share a quick definition I found on a website after picking one of the first search hits: SOAR: technology that enable organizations to take inputs from a variety of sources (mostly from security information and event management [SIEM] systems) and apply workflows aligned to processes and procedures. I believe the first thing to address here is the actual need to acquire and integrate a SOAR into your process. Besides the cost, the energy employed to make SOAR work and generate value is ultimately what defines the true cost. That actually applies to any new product you need to deploy or integrate. Note that I'm not anti-automation but the opposite (more below). I'm afr
Cyber Sec Security Monitoring Siem Soar Data Engineering Detection cannot be outSOARced Alex Teixeira 4 min read · Apr 3, 2023 -- 2 Listen Share After integrating so many tools and data sources into all sorts of security monitoring workflows and processes, let me share a few thoughts in regards to SOAR and how it actually helps (or hinders) the challenge of threat detection based on log telemetry, usually tackled via a SIEM. Why SOAR? Before exploring this question, let me share a quick definition I found on a website after picking one of the first search hits: SOAR: technology that enable org
Explore this link on the map →related reading
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Mediumdetect.fyi
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- A SOCless Detection Team at Netflixlinkedin.com
- Creating Cost-Effective, Scalable Detectionsrippling.com