homepage
Menu
Open menu
  • Training
    Go one level top Back

    Training

    • Courses

      Build cyber prowess with training from renowned experts

    • Hands-On Simulations

      Hands-on learning exercises keep you at the top of your cyber game

    • Certifications

      Demonstrate cybersecurity expertise with GIAC certifications

    • Ways to Train

      Multiple training options to best fit your schedule and preferred learning style

    • Training Events & Summits

      Expert-led training at locations around the world

    • Free Training Events

      Upcoming workshops, webinars and local events

    • Security Awareness

      Harden enterprise security with end-user and role-based training

    Featured

    Get a Free Hour of SANS Training

    Free Course Demos

    Can't find what you are looking for?

    Let us help.
    Contact us
  • Learning Paths
    Go one level top Back

    Learning Paths

    • By Focus Area

      Chart your path to job-specific training courses

    • By NICE Framework

      Navigate cybersecurity training through NICE framework roles

    • DoDD 8140 Work Roles

      US DoD 8140 Directive Frameworks

    • By European Skills Framework

      Align your enterprise cyber skills with ECSF profiles

    • By Skills Roadmap

      Find the right training path based on critical skills

    • New to Cyber

      Give your cybersecurity career the right foundation for success

    • Leadership

      Training designed to help security leaders reduce organizational risk

    • Degree and Certificate Programs

      Gain the skills, certifications, and confidence to launch or advance your cybersecurity career.

    Featured: Solutions for Emerging Risks

    New to Cyber resources

    Start your career
  • Community Resources
    Go one level top Back

    Community Resources

    Watch & Listen

    • Webinars
    • Live Streams
    • Podcasts

    Read

    • Blog
    • Newsletters
    • White Papers
    • Internet Storm Center

    Download

    • Open Source Tools
    • Posters & Cheat Sheets
    • Policy Templates
    • Summit Presentations
    • SANS Community Benefits

      Connect, learn, and share with other cybersecurity professionals

    • CISO Network

      Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders

  • For Organizations
    Go one level top Back

    For Organizations

    Team Development

    • Why Partner with SANS
    • Group Purchasing
    • Skills & Talent Assessments
    • Private & Custom Training

    Leadership Development

    • Leadership Courses & Accreditation
    • Executive Cybersecurity Exercises
    • CISO Network

    Security Awareness

    • End-User Training
    • Phishing Simulation
    • Specialized Role-Based Training
    • Risk Assessments
    • Public Sector Partnerships

      Explore industry-specific programming and customized training solutions

    • Sponsorship Opportunities

      Sponsor a SANS event or research paper

    Interested in developing a training plan to fit your organization’s needs?

    We're here to help.
    Contact us
  • Talk with an expert
  • Log In
  • Join - it's free
  • Account
    • Account Dashboard
    • Log Out
  1. Home >
  2. Blog >
  3. How SOAR Transforms Security Operations: A Real-World Case Study
Shawn_Chakravarty_340x340.png
Shawn Chakravarty

How SOAR Transforms Security Operations: A Real-World Case Study

Security Orchestration Automation and Response (SOAR) can be a culture shift for your operations team and possibly your entire organization.

July 17, 2024

Security Orchestration Automation and Response (SOAR) can be a culture shift for your operations team and possibly your entire organization.

There are many approaches to SOAR in an operations team. Given new out of the box capabilities, some tools can shift how a security operations team function. For a long time, geeks around the world threatened, “Go away or I will replace you with a very small shell script.”  I think of this attempt at humor any time an analyst on my team says the words, “Oh, I will just go automate that quickly.”  And my team says it a lot. The team was told a long time ago, if you do something more than three times, it is time to automate.

In early April of 2024, security researchers announced a vulnerability in the XZ project, assigned CVE-2024-3094. That morning, my threat intelligence team greeted me with multiple text messages and reports from public intelligence sources. It was a long day. The XZ utility is commonly used, and this vulnerability had a known exploit in the wild. Luckily, a Microsoft software engineer, Andres Freund, noticed a system running oddly. His discovery cascaded through my Cyber Threat Intelligence (CTI) team to my Operations (Ops) team, Vulnerability Management (VM), IT, and on down line.

Not surprisingly, the teams jumped into action, but remediation would take time. While VM, IT, and other teams tested the patch and prepared to roll it out, Ops needed to hold the line. In the world of block and tackle defensive operations, there would be a lot of noise. In my role, it is important to step back and let the smart people do the work. I patiently waited for an update that seemed to never arrive. When it did, I was pleased to see that not only had signatures been built but alert validation had been automated. In the SOAR, the alerts had been validated through the vulnerability scan results. Once the SOAR determined a system vulnerability, it sent an alert and created a rule to block the traffic. It documented this rule in a ticket, elevated the ticket’s priority, and sent a Slack message to the Ops team so they could copy the new rule and apply it.

This was all done in an hour. Of course, there are many ways for an Ops team to correlate the data within a security information and event management (SIEM) or a VM platform. But this was how my team decided to handle it.

My team also recognized that automation was not needed for every step in the workflow. There can be both manual and automated tasks throughout the workflow. An example of this is the “report phishing” workflow. Most of the major SOAR vendors have their salespeople swoop in with this solution first. It is low hanging fruit because analysts find responding to phishing reports tedious. It is a quick win that can result in many people hours saved immediately.

The workflow is simple. Every user in the company has a button they can click to report phishing. Some of the less sophisticated phishing report buttons report the suspicious email to the Ops team. Sometimes this is done without a button. Your organization might just have a distribution list that users are told to forward the email to.

Ops will review the headers, detonate links and attachments, make a determination, and respond to the user. The last step is more important than you think. But we will come back to that. If the email is determined to be malicious, a search for other such emails needs to be performed. Proxy logs need to be reviewed to see if any other workstations communicated with links or IP addresses in the email. Blocks need to be put in place. Of course, all this needs to be logged in the case management system. In a large organization, this can be tens or hundreds of emails reported daily. And each report can take upwards of an hour to fully analyze and respond.

It would be easy to just say “automate the entire thing.” But in reality, it is better to approach this in smaller chunks. First, automate the receipt of the report and ticket creation. Simple enough. Now when the user clicks on “report phishing,” a ticket is created, headers are extracted, artifacts are attached to the ticket (attachments, hash, URLs etc.), and an analyst is notified of the new ticket. Now the analyst has all the data to determine whether the email is malicious.

Second, automate the analysis of the artifacts. Before the ticket is created, your SOAR sends the attachments and URLs to your sandbox. The items are detonated, and the ticket is populated with the analysis. The ticket can be upgraded to a higher priority if the email is malicious. All blocks and mitigations put in place are done manually at this point. This allows the analysts to decide the efficacy of the determination and adjust.

This is also when automation can be used to look for other instances of the email or communications to the known bad URLs/IP addresses. Emails can be removed from inboxes before they are ever seen by the user.

Third, send the reporting user a Slack message with the determination. The importance of this step cannot be overstated. Over my many years in security the best way to ensure the “see something say something” mantra is followed is with reinforcement. Users want to know if it is a valid email. Sometimes they want to know if they CAN click on the link. When they report phishing and never hear back, they never know if it was really a malicious email. And don’t get me started on the people that use the report phishing button instead of the delete button.

In our situation, a message is sent to the user that says one of three things:

“This email appears to be malicious. An analyst is reviewing it and will reach out with more information. Excellent work identifying a phishing email and protecting the company.”  A similar message is sent to the user’s manager to inform them of the accomplishment.

“This email has been reviewed by our automated system and appears to be benign. If you still believe it to be malicious, type yes and an analyst will review the email manually. You will receive a response from the analyst with their determination.”

“Our automated systems were not able to determine if this email is malicious or benign. An analyst will manually review the email and report back to you.”

This is a clear example of improving the corporate culture through continuous education and communication. You should do quarterly training with phishing assessments and communicate the results. But a simple compliment during a routine report goes a long way to reinforcing training.

The last iteration of this SOAR workflow is to implement the mitigations. This is the most sensitive and can be impacting. Doing it last is critical to ensure a low false positive rate. There can still be human intervention prior to rolling out blocks or deleting emails from the mail server.

There are many other low hanging fruits to grab using SOAR. Working for large enterprises, I have found that data loss prevention (DLP) alerts are a good start also. Using new Generative AI (GenAI) technologies allows us to take automation to another level when responding to DLP alerts. That’s for a future post.

Ready to dive deeper into Security Orchestration Automation and Response (SOAR) and other cutting-edge security operations strategies? Enroll in or register for a demo of our LDR512 course today and gain the knowledge and skills to transform your organization's security posture. Don't miss this opportunity to become a leader in cybersecurity! Check out the LDR512 course here.

Share:
TwitterLinkedInFacebook
Copy url Url was copied to clipboard
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote D'ivoire
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania, United Republic Of
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City State
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Tags:
  • Cybersecurity Leadership

Related Content

Blog
LDR - Blog - It’s Dangerous to Go Alone- A Consensus-Driven Approach to SOC Metrics_340 x 340.jpg
Cybersecurity Leadership
April 25, 2025
It’s Dangerous to Go Alone: A Consensus-Driven Approach to SOC Metrics
Metrics play a crucial role in understanding the performance of Security Operations Center (SOC) functions.
Mark-Orlando-370x370.jpg
Mark Orlando
read more
Blog
Cybersecurity Leadership
April 24, 2025
Visual Summary of SANS Cybersecurity Leadership Summit 2025
Check out these graphic recordings created in real-time throughout the event for SANS Cybersecurity Leadership Summit 2025
No Headshot Available
Emily Blades
read more
Blog
LDR - Blog - Building and Leading Security Operations_340 x 340.jpg
Cybersecurity Leadership
April 22, 2025
Building and Leading Security Operations: The Infinite Quest
Security operations are not a finite project but an ongoing process to be sustained for as long as possible.
Mark-Orlando-370x370.jpg
Mark Orlando
read more
  • Company
  • Mission
  • Instructors
  • About
  • FAQ
  • Press
  • Contact Us
  • Careers
  • Policies
  • Training Programs
  • Work Study
  • Academies & Scholarships
  • Public Sector Partnerships
  • Law Enforcement
  • SkillsFuture Singapore
  • Degree Programs
  • Get Involved
  • Join the Community
  • Become an Instructor
  • Become a Sponsor
  • Speak at a Summit
  • Join the CISO Network
  • Award Programs
  • Partner Portal
Subscribe to SANS Newsletters
Receive curated news, vulnerabilities, & security awareness tips
United States
Canada
United Kingdom
Spain
Belgium
Denmark
Norway
Netherlands
Australia
India
Japan
Singapore
Afghanistan
Aland Islands
Albania
Algeria
American Samoa
Andorra
Angola
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius, and Saba
Bosnia And Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
Brunei Darussalam
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos (Keeling) Islands
Colombia
Comoros
Cook Islands
Costa Rica
Cote D'ivoire
Croatia (Local Name: Hrvatska)
Curacao
Cyprus
Czech Republic
Democratic Republic of the Congo
Djibouti
Dominica
Dominican Republic
East Timor
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
Falkland Islands (Malvinas)
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard And McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
Indonesia
Iraq
Ireland
Isle of Man
Israel
Italy
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Korea, Republic Of
Kosovo
Kuwait
Kyrgyzstan
Lao People's Democratic Republic
Latvia
Lebanon
Lesotho
Liberia
Liechtenstein
Lithuania
Luxembourg
Macau
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia, Federated States Of
Moldova, Republic Of
Monaco
Mongolia
Montenegro
Montserrat
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
North Macedonia
Northern Mariana Islands
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn
Poland
Portugal
Puerto Rico
Qatar
Reunion
Romania
Russian Federation
Rwanda
Saint Bartholemy
Saint Kitts And Nevis
Saint Lucia
Saint Martin
Saint Vincent And The Grenadines
Samoa
San Marino
Sao Tome And Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Sint Maarten
Slovakia
Slovenia
Solomon Islands
South Africa
South Georgia and the South Sandwich Islands
South Sudan
Sri Lanka
St. Helena
St. Pierre And Miquelon
Suriname
Svalbard And Jan Mayen Islands
Sweden
Switzerland
Taiwan
Tajikistan
Tanzania, United Republic Of
Thailand
Togo
Tokelau
Tonga
Trinidad And Tobago
Tunisia
Turkey
Turkmenistan
Turks And Caicos Islands
Tuvalu
Uganda
Ukraine
United Arab Emirates
United States Minor Outlying Islands
Uruguay
Uzbekistan
Vanuatu
Vatican City State
Venezuela
Vietnam
Virgin Islands (British)
Virgin Islands (U.S.)
Wallis And Futuna Islands
Western Sahara
Yemen
Zambia
Zimbabwe

By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
  • Privacy Policy
  • Terms and Conditions
  • Do Not Sell/Share My Personal Information
  • Contact
  • Careers
© 2025 The Escal Institute of Advanced Technologies, Inc. d/b/a SANS Institute. Our Terms and Conditions detail our trademark and copyright rights. Any unauthorized use is expressly prohibited.
  • Twitter
  • Facebook
  • Youtube
  • LinkedIn