Company
Date Published
Author
Alana Kirby
Word count
1037
Language
English
Hacker News points
None

Summary

The text discusses the development of a specialized tool called Hobi, designed to provide additional context for security alerts in a company's Security Information and Event Management (SIEM) system. Hobi is an in-house, Zapier-specific context engine that aggregates data from various services and tools to help investigators understand the big picture fully before manual intervention is required. It automates away what was previously done manually by collecting information in real-time as alerts are generated and can be invoked during investigations if more information is needed. Hobi differs from a Security Orchestration, Automation, and Response (SOAR) tool, which focuses on automating incident response operations after an alert has been triggered. Instead, Hobi provides additional actionable data to complement SOAR by programmatically querying data sources for point-in-time context that can be used in alert processing and response. The tool is modular, with libraries for gathering data from log aggregators, identity providers, cloud environments, and more, and allows users to access it via API endpoints or as a SlackBot for interactive use or gathering user feedback.