flâneur — a map of the web's best reading

Help Stop SOAR Abuse - by Omer Singer - Omer on Security

omeronsecurity.com · saved by 1 readers

Don’t get me wrong—Security Orchestration, Automation, and Response (SOAR) is an increasingly valuable part of security operations. Also, this isn’t a “SOAR is dead” post, although hyperautomation is certainly a cooler name. This is about using the right tool for the job. Read on to learn how SOC teams unintentionally take on long-term risk and complexity by using (or abusing) SOAR for detection engineering use cases. Security automation is a best practice for reducing the burden of manual SOC processes. For example, many SOCs have an automated playbook that sorts through employee-reported phishing emails, checks elements against threat intelligence, and yanks any related emails from company mailboxes. Should the same automation approach be applied to threat detection? The problem starts when detection requirements involve uncollected activity logs, a common situation given SOCs tend to have less than half their data in the SIEM. Visibility gaps become detection gaps. The workaround go

Don’t get me wrong—Security Orchestration, Automation, and Response (SOAR) is an increasingly valuable part of security operations. Also, this isn’t a “SOAR is dead” post, although hyperautomation is certainly a cooler name. This is about using the right tool for the job. Read on to learn how SOC teams unintentionally take on long-term risk and complexity by using (or abusing) SOAR for detection engineering use cases. Security automation is a best practice for reducing the burden of manual SOC processes. For example, many SOCs have an automated playbook that sorts through employee-reported phi

Explore this link on the map →