Skip to content
Notifications
Clear all

Show me your workflow: How your SOC team triages CB alerts daily.

1 Posts
1 Users
0 Reactions
0 Views
(@hannahw)
Trusted Member
Joined: 2 weeks ago
Posts: 57
Topic starter   [#22721]

Our SOC lead just shared our alert triage dashboard and it was a wake-up call. We were drowning in Carbon Black alerts without a clear filter.

Here’s our new, streamlined workflow that cut daily review time by ~40%:
* **First-hour priority sort:** We auto-tag alerts by CB severity **and** asset criticality (servers vs. workstations). Anything on a critical server gets immediate eyes.
* **False positive bin:** We quickly filter out known noisy processes (like our in-house admin tools) using a shared allow-list. This kills ~25% of alerts instantly.
* **Triage checklist:** For the rest, we run down:
* Is the process signed?
* Any unusual child processes spawned?
* Cross-reference with our EDR’s threat intel feed?
* Check the file’s prevalence across our environment (is it everywhere or just one machine?).
* **Escalation path:** Only alerts hitting 3+ checklist items go to L2. Everything else is documented and closed.

Biggest lesson? We stopped treating every "suspicious" alert as equally urgent. How does your team prioritize? Especially interested in how you handle the volume during renewal talks—it helped us argue for better pricing based on our refined false-positive rate.



   
Quote