Skip to content
Notifications
Clear all

Show me your workflow: How your SOC team triages CB alerts daily.

18 Posts
18 Users
0 Reactions
1 Views
(@george7)
Estimable Member
Joined: 2 weeks ago
Posts: 202
 

That approach is exactly what makes a workflow sustainable. I'm glad your SOC lead shared that dashboard, it's often the first step to getting everyone on the same page.

You touched on something important for renewal talks - showing a refined workflow proves you're extracting more value from the tool itself. It's a stronger position than just complaining about volume. I've seen teams combine that with metrics on MTTR for true positives discovered *after* the filtering, which demonstrates the process isn't just hiding things.

Your checklist is solid. The third point about cross-referencing with threat intel is key, but how do you handle the latency? If the feed is a few hours behind, do you still close the alert or does it get a pending flag?


Keep it constructive.


   
ReplyQuote
(@henryw)
Trusted Member
Joined: 2 weeks ago
Posts: 32
 

I like the point about showing MTTR for true positives after the filter. That feels like concrete proof the workflow is working, not just hiding things.

On the latency question, we actually got stuck on that too. Our lead said we shouldn't leave things pending for an intel check, because it creates a backlog that never gets cleared. His rule was to close it if the checklist was otherwise clean, but make a note to revisit if a high-fidelity IOC came in later. It felt risky at first.



   
ReplyQuote
(@clarak2)
Eminent Member
Joined: 2 weeks ago
Posts: 37
 

Love the structured checklist approach. That escalation threshold of 3+ items is interesting. We found 2 specific high-fidelity signals were enough for escalation, like an unsigned binary spawning weird children on a critical server. Setting it at 3 might be keeping some real threats in the review queue longer than needed.

Also, your point about renewal talks is spot on. Quantifying that 40% time reduction is good, but we found mapping it directly to "alerts per analyst hour" with a trendline was the clincher for finance. It showed we were getting more efficient, not just ignoring alerts.


Docs save time


   
ReplyQuote
Page 2 / 2