The SOC Technology Stack: XDR, SIEM, WAF, and More

Source: Pixabay

What is a Security Operations Center (SOC)?

A SOC is responsible for maintaining, monitoring, and protecting information security in an organization. It is considered a hub of intelligence that gathers real-time information as it streams across the assets of the organization, including servers, networks, and endpoints, and uses it to identify security events and respond to them in an effective and timely manner.

Don’t Make a Hash of Analysis, Go Fuzzy

Security Operations Center (SOC) analysts spend a lot of their time and effort trying to identify if a document has changed, possibly signifying it has been compromised. The leading method of doing so involves using a hashing algorithm.

Using hash we can tell if there has been even the slightest change to a document. But what happens when the change is insignificant or our purpose is to locate similar files that don’t have the exact same hash?