This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

SOAR beyond the SOC

Download resources

About this session

Mark Allen, systems engineer at Palo Alto Networks in Ottawa, makes the case that security orchestration, automation and response (SOAR) platforms are worth far more than the phishing and malware playbooks most SOCs stop at. He first frames the drivers: alert volume, too few analysts, remote SOCs since the pandemic, cloud teams and tools the SOC has never worked with, and product proliferation. He then walks through use cases outside the SOC: user onboarding and offboarding driven from the HR system, chasing owners of expiring TLS certificates with automatic escalation, routing cloud misconfigurations to the DevOps engineer who pushed the Terraform template, publishing Office 365 feeds as external dynamic lists for firewalls, feeding attack surface discoveries into the vulnerability scanner, enriching vulnerabilities with EDR context and auto-patching in a dev mirror, central log searches across several SIEMs, and mapping incidents to MITRE ATT&CK with course-of-action playbooks. Throughout, he stresses that SOAR removes manual steps rather than analysts, and that wins outside the SOC make the purchase easier to justify internally.

 SOAR has traditionally been the purview of larger enterprises with SOC teams. However, with the recent world disruptions, cybersecurity teams are leveraging automation to ease transition, streamline processes, and ensure their companies and employees are secured. Security automation has risen to the forefront as the “glue” that can orchestrate silos of people, tools and processes and we believe that more security teams can, and should, take advantage of the benefits of automation. In this session, we will cover the drivers for security automation, and show how SOAR can be just as easily applied to many areas outside of the SOC to help security teams of various sizes better cope with the new “normal” of work.  We will explore different areas of security, with real-world automation use cases, as well as share experiences of how our own Palo Alto Networks security teams and our customers have leveraged automation to great effect for their teams.   

Key takeaways

  • Sell SOAR internally with use cases other teams feel, such as onboarding and certificate renewals, so the SOC is not the only budget owner.
  • Drive onboarding and offboarding from the HR record so accounts, laptops, SSO and VPN are provisioned and, more importantly, cleanly removed with an audit trail.
  • Let a playbook chase certificate owners and escalate to their manager as the expiry date approaches instead of an engineer doing it by email.
  • Chain attack surface discovery to the asset inventory and vulnerability scanner so an unknown RDP host with a known CVE is escalated automatically.
  • Automate risky actions such as patching and firewall upgrades in a dev mirror first, then use those results as evidence in production change control.

Speakers

Mark Allen
Mark Allen
Systems Engineer · Palo Alto Networks
SOAR has traditionally been the purview of larger enterprises with SOC teams. However, with the recent world disruptions, cybersecurity teams are leveraging automation to ease transition, streamline processes, and ensure their companies and… Read moreRead less

SOAR has traditionally been the purview of larger enterprises with SOC teams. However, with the recent world disruptions, cybersecurity teams are leveraging automation to ease transition, streamline processes, and ensure their companies and employees are secured. Security automation has risen to the forefront as the “glue” that can orchestrate silos of people, tools and processes and we believe that more security teams can, and should, take advantage of the benefits of automation. In this session, we will cover the drivers for security automation, and show how SOAR can be just as easily applied to many areas outside of the SOC to help security teams of various sizes better cope with the new “normal” of work. We will explore different areas of security, with real-world automation use cases, as well as share experiences of how our own Palo Alto Networks security teams and our customers have leveraged automation to great effect for their teams.

Resources

Tags

More from GoSec 2021

Also from Mark Allen

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.