Posts

Showing posts with the label Security Operations

SOAR Explained: Security Orchestration and Automated Response for CySA+

SOAR — Security Orchestration, Automation, and Response — is the category of tooling that takes the repetitive work out of a security operations centre. It connects the tools an analyst would otherwise click through by hand, runs the routine steps automatically, and hands the human what actually needs judgement. SIEM tells you something happened. SOAR does something about it. The problem SOAR addresses is straightforward and familiar to anyone who has worked a queue: a SOC generates far more alerts than its analysts can investigate, and a large share of those alerts require the same dull sequence every time — look up the IP reputation, check the hash, query the EDR, see who the user is, decide whether it matters. That sequence takes fifteen minutes and requires no creativity. Multiply it by four hundred alerts a day. The Three Words Orchestration is the integration layer. SOAR connects to the SIEM, EDR, firewall, identity provider, ticketing system, threat intelligence feeds...