Is there any way we can integrate Emerging Threats with SOAR so that if an IOC match is found it creates a SOAR case?
Emerging Threats - Integrate with SOAR?
Best answer by gkush
What I would do is set all of the Curated Detections to only detections, no alerting. Next, I’d create a composite detection that aggregates the rule findings. You can create hourly buckets, and you can match on user or machine, or choose some other match condition (production vs dev, AD group) that makes sense for what you want to track. There’s a fair bit of flexibility and creativity you can use here to suppress or aggregate “noise”, but it also means some work and planning.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.

