flâneur — a map of the web's best reading

Detection Engineering the SOC: Building a SOAR Workflow | by RCXSecurity | Medium

medium.com · saved by 1 readers

Welcome back to the third and final article in the short series: Engineering the SOC. So far, we’ve taken a use case through detection creation, and then the process of creating an Incident Response Playbook. The purpose of this series has been to show the exact thought process of a Security Engineer taking a use case through the Detection Lifecycle. The last phase for our use case is design an automated workflow in order to lower the ticket triage time, and in turn, fight off alert fatigue once and for all! In case you haven’t read the first two articles in the series, you can view the table of contents below. This post marks the finale, so I’d highly recommend checking them out before you continue. Or, if you want to explore other related topics, you can find more on Detection Engineering and Cybersecurity at the Cybersec Cafe. Looking for daily cybersecurity content? Check me out on Twitter/X! We were given a use case for our organization where some privileged users will need to acc

Welcome back to the third and final article in the short series: Engineering the SOC. So far, we’ve taken a use case through detection creation, and then the process of creating an Incident Response Playbook. The purpose of this series has been to show the exact thought process of a Security Engineer taking a use case through the Detection Lifecycle. The last phase for our use case is design an automated workflow in order to lower the ticket triage time, and in turn, fight off alert fatigue once and for all! In case you haven’t read the first two articles in the series, you can view the table

Explore this link on the map →