A walkthrough of building a SOAR automation in Microsoft Sentinel using Azure Logic Apps and automation rules to respond to SSH brute force incidents without manual intervention. Covers the two-component architecture (Logic App playbook + automation rule), a real permissions error involving the Microsoft Sentinel Automation Contributor role, and a BadRequest error encountered during manual testing. Also explains the principle that effective SOAR automation requires prior manual investigation of the attack pattern, and scales the architecture to enterprise use cases like firewall blocking, AD account disabling, and ServiceNow ticket creation.

6m read timeFrom infosecwriteups.com
Post cover image
Table of contents
A Logic App playbook, an automation rule, a real permissions error — and what it taught me about how automated incident response actually works.What SOAR actually isThe two pieces — and how they connectStep 1 — The automation ruleStep 2 — The Logic App playbookGet Ronak Mishra’s stories in your inboxStep 3 — Testing it and what actually happenedThe permissions challenge — what no tutorial mentionsWhat this looks like at scaleThe one thing that makes SOAR actually work
157 Impressions