Hi everyone. I'm still learning about proper SOAR platforms at work, but in the meantime, my team needed *something* to automate a few basic alert responses.
We couldn't get budget for a real tool, so we built a simple system using PowerShell scripts triggered by Slack. Our SIEM (a basic Splunk setup) sends alerts to a dedicated Slack channel. A bot watches the channel, and if a message contains specific keywords (like "malicious attachment" or "failed logon burst"), it kicks off a corresponding PowerShell script on our Windows server.
The scripts do things like disable a user AD account, isolate a host from the network, or gather basic user login history. It then posts the results back to Slack.
It's definitely not pretty. No fancy GUI, no official playbooks, and we're probably reinventing the wheel. But it has helped cut down our response time for those common alerts by a lot.
I'm curious if others have built similar "homegrown" tools. What were the biggest limitations you ran into? For us, error handling is a constant challenge, and adding new workflows feels clunky.