The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a wellknown pattern an alert arrives a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity