{"id":12412,"date":"2023-06-12T05:21:18","date_gmt":"2023-06-12T05:21:18","guid":{"rendered":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/?post_type=session&#038;p=12412"},"modified":"2023-06-12T05:24:50","modified_gmt":"2023-06-12T05:24:50","slug":"hitb-lab-bring-your-own-soar-automated-incident-response","status":"publish","type":"session","link":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/","title":{"rendered":"HITB LAB: Bring Your Own SOAR: Automated Incident Response"},"content":{"rendered":"<p style=\"text-align: justify;\">Incident response involves processes beyond investigations like alert management, tuning detections, communication, tracking incident-related metrics, handoffs, etc, that can be tedious, repetitive, and time consuming, especially considering our all-remote environment at GitLab. For that purpose, our incident response team has developed a set of (mostly) Slack-based tools to standardize the process for incident response management and therefore reducing technical, as well as administrative overhead during incidents, through automation (and even gamification!)<\/p>\n<p style=\"text-align: justify;\">These tools leverage platforms like GitLab, Slack, our SIEM, PagerDuty, and Google Workspace to optimize the workflow of our busy incident response team. Our tools are operated within Slack and connect to our critical cloud-based systems for incident response, as well as our automation platform, Tines. With these tools integrated within our incident response processes, we\u2019ve automated alert deployment through our detection as code CI\/CD pipeline, incident severity and priority scoring, team handoffs, incident life trackers that follow compliance guidelines, labeling and metrics generation, and we\u2019ve significantly reduced investigation time by e.g. automating operational communication feeds.<\/p>\n<p style=\"text-align: justify;\">In this workshop, we share this solution and processes developed in-house and demonstrate how we as global incident response teams can best build our own SOAR solutions that fit our requirements and see firsthand how much our efficiency has increased. A portion of our own automation designs and scripts will be opensourced at the conference.<\/p>\n","protected":false},"template":"","class_list":["post-12412","session","type-session","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>HITB LAB: Bring Your Own SOAR: Automated Incident Response - HITBSecConf2023 - Phuket<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HITB LAB: Bring Your Own SOAR: Automated Incident Response - HITBSecConf2023 - Phuket\" \/>\n<meta property=\"og:description\" content=\"Incident response involves processes beyond investigations like alert management, tuning detections, communication, tracking incident-related metrics, handoffs, etc, that can be tedious, repetitive, and time consuming, especially considering our all-remote environment at GitLab. For that purpose, our incident response team has developed a set of (mostly) Slack-based tools to standardize the process for incident response management [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/\" \/>\n<meta property=\"og:site_name\" content=\"HITBSecConf2023 - Phuket\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-12T05:24:50+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/\",\"name\":\"HITB LAB: Bring Your Own SOAR: Automated Incident Response - HITBSecConf2023 - Phuket\",\"isPartOf\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website\"},\"datePublished\":\"2023-06-12T05:21:18+00:00\",\"dateModified\":\"2023-06-12T05:24:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Session\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"HITB LAB: Bring Your Own SOAR: Automated Incident Response\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/\",\"name\":\"HITBSecConf2023 - Phuket\",\"description\":\"August 22 - 26 @ InterContinental\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HITB LAB: Bring Your Own SOAR: Automated Incident Response - HITBSecConf2023 - Phuket","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/","og_locale":"en_US","og_type":"article","og_title":"HITB LAB: Bring Your Own SOAR: Automated Incident Response - HITBSecConf2023 - Phuket","og_description":"Incident response involves processes beyond investigations like alert management, tuning detections, communication, tracking incident-related metrics, handoffs, etc, that can be tedious, repetitive, and time consuming, especially considering our all-remote environment at GitLab. For that purpose, our incident response team has developed a set of (mostly) Slack-based tools to standardize the process for incident response management [&hellip;]","og_url":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/","og_site_name":"HITBSecConf2023 - Phuket","article_modified_time":"2023-06-12T05:24:50+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/","url":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/","name":"HITB LAB: Bring Your Own SOAR: Automated Incident Response - HITBSecConf2023 - Phuket","isPartOf":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website"},"datePublished":"2023-06-12T05:21:18+00:00","dateModified":"2023-06-12T05:24:50+00:00","breadcrumb":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/hitb-lab-bring-your-own-soar-automated-incident-response\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/"},{"@type":"ListItem","position":2,"name":"Session","item":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/session\/"},{"@type":"ListItem","position":3,"name":"HITB LAB: Bring Your Own SOAR: Automated Incident Response"}]},{"@type":"WebSite","@id":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/#website","url":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/","name":"HITBSecConf2023 - Phuket","description":"August 22 - 26 @ InterContinental","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/session\/12412"}],"collection":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/session"}],"about":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/types\/session"}],"wp:attachment":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2023hkt\/wp-json\/wp\/v2\/media?parent=12412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}