← Back to SOC Analyst - Blue Team Operations

Lesson 9 of 10

SOC Automation & SOAR

SOAR

  • TheHive + Cortex, Shuffle, n8n
  • Playbook: Phishing email → extract URLs → VirusTotal → block → notify
  • Ticketing with Jira/ServiceNow