Knowledge Management

Use Case

gmbdrj
Loves-to-Learn Lots
I'm trying to make SOC Use cases clear, concise, and easy to find later. It is possible to make a threat detection use case based on MITRE, but I guess SOC is not the only threat detection. There are many other requirements such as compliance and business use cases. What approach should be more effective and right?
Here are my questions.
Use Case Development:
- Best practices for effective SOC use cases and recommended frameworks?
Documentation and Knowledge Management:
- Strategies/tools for organizing SOC use cases for searchability?
Continuous Improvement:
- Methods for improving and updating SOC use cases over time?
- Can you share examples of how penetration testing results have influenced the development of SOC use cases?
Risk Assessment Integration:
- How do you align SOC use cases with risk levels identified in risk assessments?
- Are there specific metrics or indicators from risk assessments that should be incorporated into SOC use cases?
- What best practices do you suggest for regularly reviewing and updating SOC use cases based on changes in risk assessments?
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gmbdrj ,

it's realli diffi coult to answer to your question in few words.

A>nyway, installi the MItre Att@ck app, you can start from a mapping of your Searches with this framework.

Then you can use the Enterprise Security (if you have) and/or the Splunk Security Essentials App to be guided in Use Cases implementation.

Anyway, remember that the starting poins is always data: you have to analyze the data you have to understand which Use Cases you can enable.

Ciao.

Giuseppe 

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...