Quick Dig into SOAR Tools
The previous chapters introduced SOAR as a tool and discussed how it can help in day-to-day SOC operations. It can start with case management, helping to orchestrate incident assignments. Then, it can automate everyday tasks where SOC analysts use many tools/windows, enrich an incident with additional data, or even respond to the incident. Finally, it can assist with reporting for better analysis and incident response planning in the future.
In this chapter, we will focus on a few popular SOAR tools and understand how they are combined with SIEM tools. We also dive deep into their main functionalities and learn how they can be used for incident management, investigation, automation, reporting, TI/TVM, and administration panes.
The tools that will be covered are as follows:
- Microsoft Sentinel SOAR
- Splunk SOAR (Phantom)
- Google Chronicle SOAR (Siemplify)
Some other SOAR tools include Palo Alto Cortex XSOAR, IBM Security SOAR, Swimlane...