Fundamentals to Security Alert Automation: SOAR Your Own Way | by RCXSecurity | Medium
Welcome to the first iteration in my “SOAR Your Own Way” series, where I’ll cover everything SOAR related. The SOAR is truly a remarkable and versatile piece of technology that can be as simplistic or complicated as an organization wishes it to be. But first, what is a SOAR? SOAR stands for Security Orchestration Automation and Response, and it is an automation workflow tool that is used by security teams to handle automation around Detections and Incident Response use cases. But what does this mean exactly? Let’s take the following scenario: A user, named John, lives and works out of his home in California for a company called RealTech. As a fully remote company, travel is allowed by the company and employees are encouraged, though not required, to provide a notice. One morning, before business hours, a Suspicious Account Login security alert fires off for John’s account from India. Luckily, the security team at RealTech has been working hard at configuring their SOAR for the last yea
Fundamentals to Security Alert Automation: SOAR Your Own Way Ryan G. Cox 7 min read · Dec 12, 2023 -- 1 Listen Share Press enter or click to view image in full size The Cybersec Café Welcome to the first iteration in my “ SOAR Your Own Way ” series, where I’ll cover everything SOAR related. The SOAR is truly a remarkable and versatile piece of technology that can be as simplistic or complicated as an organization wishes it to be. But first, what is a SOAR? SOAR stands for Security Orchestration Automation and Response, and it is an automation workflow tool that is used by security teams to han
Explore this link on the map →saved by
related reading
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Mediumdetect.fyi
- Automated Incident Response: Streamlining Your SecOps | Prophet Securityprophet.security
- Mediumdetect.fyi
- A SOCless Detection Team at Netflixlinkedin.com
- Mediumblog.palantir.com
- Rebuilding Threat Detection and Incident Response at LinkedInlinkedin.com
- Creating Cost-Effective, Scalable Detectionsrippling.com