Skip to content
SOC Alert Triage Automation
Projects / Proyek

SOC Alert Triage Automation

Minimalist dark-themed portfolio

Overview / Ringkasan

A SOC-focused workflow to reduce alert fatigue through enrichment, risk scoring, and suppression logic.
Workflow SOC untuk menekan alert fatigue melalui enrichment, risk scoring, dan suppression yang terkontrol.

Challenge / Tantangan

High false-positive volume delayed response to critical incidents and overloaded analyst queues.
Volume false positive yang tinggi menunda respons insiden kritis dan membebani antrean analis.

Solution / Pendekatan

Implemented IOC enrichment, severity scoring, and low-value alert suppression integrated with playbook automation.
Menerapkan enrichment IOC, scoring tingkat risiko, dan suppression alert bernilai rendah yang terintegrasi playbook otomatis.

Results / Dampak Terukur

Alert noise reduced by 57% and median response time improved from 2h20m to 58m within one quarter.
Noise alert turun 57% dan median response time meningkat dari 2 jam 20 menit menjadi 58 menit dalam satu kuartal.
Now Playing Loading...