Security Operations Center (SOC) are composed of Security Specialists, who analyze and evaluate logs to respond to cyber incidents. The Security Information and Event Management (SIEM) system produces alerts, which are useful to investigate incidents.
These alerts can also be forwarded to a Security Orchestration, Automation, and Response (SOAR) platform, which can provide automated responses. In this talk, we will explore how those automated responses can be powered by Artificial Intelligence (AI) and used in community playbooks written in Python.