Help Stop SOAR Abuse - by Omer Singer - Omer on Security
Don’t get me wrong—Security Orchestration, Automation, and Response (SOAR) is an increasingly valuable part of security operations. Also, this isn’t a “SOAR is dead” post, although hyperautomation is certainly a cooler name. This is about using the right tool for the job. Read on to learn how SOC teams unintentionally take on long-term risk and complexity by using (or abusing) SOAR for detection engineering use cases. Security automation is a best practice for reducing the burden of manual SOC processes. For example, many SOCs have an automated playbook that sorts through employee-reported phishing emails, checks elements against threat intelligence, and yanks any related emails from company mailboxes. Should the same automation approach be applied to threat detection? The problem starts when detection requirements involve uncollected activity logs, a common situation given SOCs tend to have less than half their data in the SIEM. Visibility gaps become detection gaps. The workaround go
Don’t get me wrong—Security Orchestration, Automation, and Response (SOAR) is an increasingly valuable part of security operations. Also, this isn’t a “SOAR is dead” post, although hyperautomation is certainly a cooler name. This is about using the right tool for the job. Read on to learn how SOC teams unintentionally take on long-term risk and complexity by using (or abusing) SOAR for detection engineering use cases. Security automation is a best practice for reducing the burden of manual SOC processes. For example, many SOCs have an automated playbook that sorts through employee-reported…
related reading
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- Mediumdetect.fyi
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Mediumdetect.fyi
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- A SOCless Detection Team at Netflixlinkedin.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Table stakes for Detection Engineering - by Zack Allendetectionengineering.net