<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Incident-Response on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/incident-response/</link><description>Recent content in Incident-Response on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/incident-response/index.xml" rel="self" type="application/rss+xml"/><item><title>Break-Glass User (Emergency Access Account)</title><link>https://lesitedefrancois.be/en/security/break-glass/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/break-glass/</guid><description>&lt;p&gt;A &lt;strong&gt;break-glass user&lt;/strong&gt; (or break-glass account, emergency access account) is a privileged account that exists outside the normal access control workflow — bypassing &lt;strong&gt;PAM&lt;/strong&gt; approval gates, MFA requirements, or SSO dependencies — and is reserved for situations where those normal mechanisms are themselves unavailable or would prevent responding to a critical incident in time. The name is a physical analogy: like the fire alarm panel behind a pane of glass that reads &lt;em&gt;break glass in emergency&lt;/em&gt;, the account is designed so that accessing it requires a deliberate, detectable act. It is not a convenience mechanism; it is an organisational safety net for scenarios such as an identity provider outage locking all administrators out of their own infrastructure, a PAM platform failing during an active incident, or a ransomware attack disabling the tooling needed to contain it.&lt;/p&gt;</description></item><item><title>SOAR (Security Orchestration, Automation and Response)</title><link>https://lesitedefrancois.be/en/security/soar/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/soar/</guid><description>&lt;p&gt;&lt;strong&gt;SOAR (Security Orchestration, Automation and Response)&lt;/strong&gt; is the actuation complement to a &lt;strong&gt;SIEM&lt;/strong&gt;: where the SIEM detects and alerts, SOAR responds and acts. It receives alerts — primarily from the SIEM, but also directly from EDR platforms, vulnerability scanners, cloud security posture tools, and CNI/container security platforms — and executes structured response &lt;strong&gt;playbooks&lt;/strong&gt;: predefined, branching workflows that enrich the alert with additional context from connected systems, make automated or human-gated decisions based on that context, and issue remediation actions across the organisation&amp;rsquo;s security tooling. The three pillars of SOAR are &lt;strong&gt;orchestration&lt;/strong&gt; (connecting disparate security tools into a unified, API-driven workflow so they exchange data and coordinate actions without human clipboard-copying), &lt;strong&gt;automation&lt;/strong&gt; (executing repeatable investigation and containment steps at machine speed, consistently and without analyst fatigue), and &lt;strong&gt;case management&lt;/strong&gt; (tracking the full lifecycle of a security incident — detection, triage, investigation, containment, eradication, recovery, and post-incident review — in a structured, auditable record). Leading platforms include Splunk SOAR (formerly Phantom), IBM QRadar SOAR (formerly Resilient), Palo Alto XSOAR (formerly Demisto), Microsoft Sentinel with Playbooks (Logic Apps), and open-source options such as TheHive with Cortex.&lt;/p&gt;</description></item><item><title>SOC (Security Operations Centre)</title><link>https://lesitedefrancois.be/en/security/soc/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/security/soc/</guid><description>&lt;p&gt;A &lt;strong&gt;SOC (Security Operations Centre)&lt;/strong&gt; is the organisational function responsible for defending an infrastructure against security threats through continuous monitoring, alert triage, incident investigation, and coordinated response. It is not a single product: it is the combination of &lt;strong&gt;people&lt;/strong&gt; (security analysts operating in tiered roles), &lt;strong&gt;processes&lt;/strong&gt; (runbooks, escalation paths, incident classification, post-incident review), and &lt;strong&gt;technology&lt;/strong&gt; (primarily a &lt;strong&gt;SIEM&lt;/strong&gt; for detection and visibility, a &lt;strong&gt;SOAR&lt;/strong&gt; platform for orchestration and actuation, EDR agents, vulnerability scanners, threat intelligence feeds, and ticketing or case management systems). The SOC&amp;rsquo;s purpose is to close the loop between something going wrong in the infrastructure and someone doing something about it — with enough structure that the response is consistent, attributable, and auditable regardless of which analyst is on shift. Operating models range from a fully internal 24×7 team, through a virtual SOC (vSOC) sharing analysts across business units, to an outsourced &lt;strong&gt;MDR (Managed Detection and Response)&lt;/strong&gt; or MSSP engagement where a third party operates the SIEM and initial triage on the organisation&amp;rsquo;s behalf; the technology stack is largely the same across models, but the boundary of who performs each tier of work changes. Analyst tiers are conventionally structured as &lt;strong&gt;L1&lt;/strong&gt; (alert triage, false-positive filtering, initial enrichment, escalation decisions), &lt;strong&gt;L2&lt;/strong&gt; (deeper investigation, correlation across data sources, containment recommendations), and &lt;strong&gt;L3&lt;/strong&gt; (threat hunting, malware reverse engineering, incident lead, playbook authoring, purple-team exercises) — with escalation governed by severity classification (P1–P4 or equivalent), SLA targets for &lt;strong&gt;MTTD (Mean Time to Detect)&lt;/strong&gt; and &lt;strong&gt;MTTR (Mean Time to Respond)&lt;/strong&gt;, and documented runbooks that define what each tier may do autonomously versus what requires approval.&lt;/p&gt;</description></item></channel></rss>