Knowledge Management

Use Case

gmbdrj
Loves-to-Learn Lots
I'm trying to make SOC Use cases clear, concise, and easy to find later. It is possible to make a threat detection use case based on MITRE, but I guess SOC is not the only threat detection. There are many other requirements such as compliance and business use cases. What approach should be more effective and right?
Here are my questions.
Use Case Development:
- Best practices for effective SOC use cases and recommended frameworks?
Documentation and Knowledge Management:
- Strategies/tools for organizing SOC use cases for searchability?
Continuous Improvement:
- Methods for improving and updating SOC use cases over time?
- Can you share examples of how penetration testing results have influenced the development of SOC use cases?
Risk Assessment Integration:
- How do you align SOC use cases with risk levels identified in risk assessments?
- Are there specific metrics or indicators from risk assessments that should be incorporated into SOC use cases?
- What best practices do you suggest for regularly reviewing and updating SOC use cases based on changes in risk assessments?
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gmbdrj ,

it's realli diffi coult to answer to your question in few words.

A>nyway, installi the MItre Att@ck app, you can start from a mapping of your Searches with this framework.

Then you can use the Enterprise Security (if you have) and/or the Splunk Security Essentials App to be guided in Use Cases implementation.

Anyway, remember that the starting poins is always data: you have to analyze the data you have to understand which Use Cases you can enable.

Ciao.

Giuseppe 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...