39:51SOC Automation: Faster Decision Making and Response
Download resourcesAbout this session
Andy Skrei, VP of worldwide sales engineering at Exabeam and formerly the engineer who rebuilt eBay's SOC after a breach, argues that security operations teams automate the wrong stage. Opening with lessons from that breach (learn what is normal first, use prevalence to calibrate, build timelines), he cites a study finding teams spend about 74 percent of their time on detection, triage and investigation but almost everyone asks for automation only in response. He walks a single alert, a VPN login from a risky geolocation such as China, through a fully manual lifecycle to show how many separate queries an analyst must run to answer who, what, where, when, why and how. He then lays out five levels of automation, illustrated with a jigsaw metaphor: analytics-driven timelines that stitch logs together and attribute usernames to IP addresses, static and machine-learned enrichment (asset type, ownership, account type, peer groups), automatically answering the expensive questions by modelling normal behaviour, higher-fidelity risk-based alerts that give SOAR the full scope rather than a single event, and only then SOAR for response. A closing case shows a nation-state attack detected an hour in, from three log sources, hours before EDR flagged PowerShell and Mimikatz.
Security analysts spend two-thirds of their time on triage and investigation. Why then do most security operations teams only automate response? In this presentation, Andy Skrei will share his experience automating the end-to-end security workflow while leading security investigations at one of the world’s largest online retailers and through working with many of the world’s leading organizations while at Exabeam. Attendees will learn about:
- The productivity benefits of automating the entire SOC lifecycle
- Ways to reduce the time to answer critical questions
- How automating triage and investigations leads to quick, accurate resolutions
Key takeaways
- Automate upstream, not just at response: teams spend about 74 percent of their time on detection, triage and investigation, so putting SOAR on top of a noisy SIEM only automates the smallest slice.
- Learn what is normal before investigating, and use prevalence across users, departments and other organisations to avoid chasing benign artifacts.
- Let analytics build incident timelines and attribute usernames to IP addresses automatically instead of taping evidence to a war-room wall.
- Enrich alerts with both static context (identity, executive or admin tags, critical assets) and machine-learned context (asset type, ownership, human versus service accounts, peer groups) so analysts get up to speed faster.
- Feed SOAR a correlated, risk-scored incident covering the full scope of an attack rather than a single deterministic alert, and close the loop by banning the hash and blocking the domain, not just re-imaging the machine.
Speakers

Andy Skrei is the VP of worldwide sales engineering at Exabeam, a company that provides next-generation security intelligence and management solutions to help organizations protect their most valuable information. He previously worked as a lead… Read moreRead less
Andy Skrei is the VP of worldwide sales engineering at Exabeam, a company that provides next-generation security intelligence and management solutions to help organizations protect their most valuable information. He previously worked as a lead security engineer at eBay, developing and deploying technologies for its global SOC.
