Security Orchestration, Automation, and Response
SOAR is an automated tool that integrates all of your security processes and tools in a central location. As an automated process that is faster that humans searching for evidence of attacks, it helps reduce the mean time to detect (MTTD) and accelerates the time to respond to events.
This will produce faster alert information for the security operations team, where the human entities can take further action to keep the company safe. Let's look at the workflow in the following diagram:
Figure 5.3 – Security integration
As you can see in the preceding diagram, we first of all sort the raw data. The data would then be sent to a syslog server and then arrive at the SIEM server. The SIEM server would then correlate the events with the SOAR tools, which in turn alert the SOC team.
Threat Hunting
Threat hunting is a dynamic process of seeking out cybersecurity threats inside your network from...