Uncategorized · November 18, 2022 0

Updates on the Context Triage Framework

Humorously, this is why we cannot have great names – I suck at naming things. The Context Triage Framework or CTF is an attempt to holistically bring automation to SOC analyst triaging as well as compiling a library that is applied for triage from expert knowledge.

From attempting to bring it to several projects, I have a few observations.

Pros

  1. It doesn’t require expert knowledge across everything.
  2. Simple easy to follow instructions work best.
  3. The more people use it, the better the feedback becomes.

Cons

  1. This is another source of tech debt. API calls, log schemas, and of course rotational log sources.
  2. Shadow tech, builders and engineers need to be kept on track and introduce shadow tech when they abandon the assigned task for another – especially when such isn’t reported.
  3. Sometimes that expert knowledge doesn’t translate well.
  4. Tasks need to be crafted for yes/no actionable steps.