Security Think Tank: Integration between SIEM/SOAR is critical
Summary
SOAR can automate this, taking autonomous decisions that support the investigation, drawing in threat intelligence and presenting the results to the analyst with recommendations for further action. Throughout the process, ticketing and collaboration tools would keep the team and relevant stakeholders informed and generate reports as required. Typically, a SOAR solution will also provide case management, analysis and reporting and support communication and collaboration. Default configurations may provide a start, but playbook and defined workflows must be tuned to automate them in a SOAR solution as it will not generate these for you. Also in order to respond, the SOAR solution must know how to reconfigure firewalls, DNS servers and proxies for example, as well as isolating hosts in your specific environment.