Skip to main content
Solved

Emerging Threats - Integrate with SOAR?

  • April 9, 2026
  • 7 replies
  • 104 views

donkos
Forum|alt.badge.img+9

Is there any way we can integrate Emerging Threats with SOAR so that if an IOC match is found it creates a SOAR case?

Best answer by gkush

@donkos  - We’re on a slippery slope now.  The straight answer is “all have to be enabled, and alerting set for both P and B”.  Then there’s a real risk that you turn those on and you observe in horror as a gazillion new alerts flood your system because you’ll get a lot of noise turning the Broad rules on as alerting. At about that point is when I expect to feel sharp pains in my back from the poppet of me you keep on your desk.

What I would do is set all of the Curated Detections to only detections, no alerting.  Next, I’d create a composite detection that aggregates the rule findings.  You can create hourly buckets, and you can match on user or machine, or choose some other match condition (production vs dev, AD group) that makes sense for what you want to track. There’s a fair bit of flexibility and creativity you can use here to suppress or aggregate “noise”, but it also means some work and planning.

7 replies

Forum|alt.badge.img+15

There is current ET to SOAR cases directly, albeit if you do have Applied Threat Intel rules (which use these IOCs) enabled these will surface the same matches as shown in ET in a SOAR Case.


donkos
Forum|alt.badge.img+9
  • Author
  • Bronze 1
  • April 10, 2026

How do I configure the creation of ET matches to SOAR cases directly?


cmorris
Staff
Forum|alt.badge.img+16
  • Staff
  • April 10, 2026

How do I configure the creation of ET matches to SOAR cases directly?

The Applied Threat Intel (ATI) Curated Detections cover these IOCs. If these Curated Detections are enabled and set to alerting, you should receive alerts in the SOAR for them


donkos
Forum|alt.badge.img+9
  • Author
  • Bronze 1
  • April 13, 2026

@cmorris 

I can see 7 ATI Curated Prioritisation and 3 ATI non-prioritised IOC matching curated detections available to us. Which ones would need to be enabled? Does alerting need to be enabled to the P or B level?


gkush
Staff
Forum|alt.badge.img+6
  • Staff
  • April 13, 2026

If a rule detects and IOC, it has to be enabled to see it, and set to alerting to generate a case.

 

 


donkos
Forum|alt.badge.img+9
  • Author
  • Bronze 1
  • April 14, 2026

@gkush There’s 10 different rules - do all have to be enabled? Should alerting be set to P or B?


gkush
Staff
Forum|alt.badge.img+6
  • Staff
  • Answer
  • April 14, 2026

@donkos  - We’re on a slippery slope now.  The straight answer is “all have to be enabled, and alerting set for both P and B”.  Then there’s a real risk that you turn those on and you observe in horror as a gazillion new alerts flood your system because you’ll get a lot of noise turning the Broad rules on as alerting. At about that point is when I expect to feel sharp pains in my back from the poppet of me you keep on your desk.

What I would do is set all of the Curated Detections to only detections, no alerting.  Next, I’d create a composite detection that aggregates the rule findings.  You can create hourly buckets, and you can match on user or machine, or choose some other match condition (production vs dev, AD group) that makes sense for what you want to track. There’s a fair bit of flexibility and creativity you can use here to suppress or aggregate “noise”, but it also means some work and planning.