flâneur — a map of the web's best reading

Detection cannot be outSOARced. After integrating so many tools and… | by Alex Teixeira | Detect FYI

detect.fyi · 927 words · saved by 1 readers

After integrating so many tools and data sources into all sorts of security monitoring workflows and processes, let me share a few thoughts in regards to SOAR and how it actually helps (or hinders) the challenge of threat detection based on log telemetry, usually tackled via a SIEM. Before exploring this question, let me share a quick definition I found on a website after picking one of the first search hits: SOAR: technology that enable organizations to take inputs from a variety of sources (mostly from security information and event management [SIEM] systems) and apply workflows aligned to processes and procedures. I believe the first thing to address here is the actual need to acquire and integrate a SOAR into your process. Besides the cost, the energy employed to make SOAR work and generate value is ultimately what defines the true cost. That actually applies to any new product you need to deploy or integrate. Note that I'm not anti-automation but the opposite (more below). I'm afr

Cyber Sec Security Monitoring Siem Soar Data Engineering Detection cannot be outSOARced Alex Teixeira 4 min read · Apr 3, 2023 -- 2 Listen Share After integrating so many tools and data sources into all sorts of security monitoring workflows and processes, let me share a few thoughts in regards to SOAR and how it actually helps (or hinders) the challenge of threat detection based on log telemetry, usually tackled via a SIEM. Why SOAR? Before exploring this question, let me share a quick definition I found on a website after picking one of the first search hits: SOAR: technology that enable org

Explore this link on the map →

related reading