SIEM is primarily a detection and analysis platform, but modern solutions can be integrated with response mechanisms.

For example :

An alert indicates that a workstation is likely compromised.

The system may potentially trigger a workflow that allows:

  1. to identify the position
  2. to identify the user
  3. to question the EDR
  4. to retrieve more information
  5. to isolate the station
  6. to temporarily disable an account
  7. to create a ticket
  8. to notify the security team.

This automation brings the SIEM closer to the world of:

SOAR — Security Orchestration, Automation and Response.

However, it is important to control the automation.

A faulty automated rule can lead to:

  • the isolation of a critical server
  • blocking a legitimate user
  • the interruption of a service
  • a production incident.

Automation must therefore be proportionate to the level of confidence in the detection.

Categories: