An in-depth view of automation
One thing that we’ve mentioned a few times already, and that will be mentioned a few more times, is that one of the most critical SOAR tasks is minimizing the MTTA and MTTR. There is no better way to do so than by utilizing automation.
Automation is commonly implemented using playbooks. A playbook contains a list of actions that will be performed once it runs. An action can be, for example, getting more details about an incident, getting more information about specific data from external services, or sending a notification to a service.
Let’s look at the example of an incident investigation with no automation. Once an incident is detected, an analyst has to perform an initial triage to see whether the incident is a true or false positive. Commonly, that will be performed by looking at the entities (IP, account, host, URL, and so on) and activities associated with the incident. For example, say a user is signing in from an unfamiliar...