
Imagine a large office building with hundreds of rooms.
There are security cameras throughout the building, access-control systems on the doors, alarms, security guards and a central security control room.
Now imagine something suspicious happens.
- A door is forced open.
- A camera sees someone entering.
- An employee’s access card is used at an unusual time.
- An alarm is triggered.
The security team needs to bring all of this information together, decide whether something is wrong, investigate it and take action.
Modern cybersecurity uses technologies that perform similar functions.
Three particularly important technologies are:
- SIEM — Security Information and Event Management
- SOAR — Security Orchestration, Automation and Response
- EDR — Endpoint Detection and Response
They perform different jobs, but they work extremely well together.
EDR watches individual devices. SIEM brings security information together. SOAR helps automate the response.
The Three Technologies at a Glance
A simple way of understanding the difference is:
- SIEM – Analyses events – “Something suspicious is happening across the organisation.”
- SOAR – Responds and automates activity – “Let’s automatically do something about it.”
- EDR – Detects endpoint activity – “Something suspicious is happening on this computer.”
What Is EDR?
EDR stands for Endpoint Detection and Response.
An endpoint is a device such as:
- Desktop computer
- Laptop
- Server
- Virtual machine
EDR software runs on these devices and continuously monitors activity.
It looks for suspicious behaviour such as:
- Unusual processes
- Suspicious PowerShell activity
- Malware
- Unexpected network connections
- Changes to important files
- Attempts to disable security controls
- Privilege escalation
- Suspicious persistence mechanisms
The EDR agent watches what is happening on the endpoint and reports suspicious activity.
EDR Doesn’t Just Look for Malware
This is an important distinction – Traditional antivirus often focused heavily on identifying known malicious files, but EDR can look at behaviour.
For example:
Word.exe spawns PowerShell.exe which downloads a file and executes a script which connects to the Internet and also modifies the Windows registry
Individually, some of these actions might be legitimate, but together, they could look very suspicious.
EDR can look for patterns of events rather than simply asking “Is this file on a malware blacklist?”
This makes EDR useful against threats that may not have a known malware signature such as a Zero-day.
EDR Provides Visibility
EDR can provide security teams with detailed information about what happened on a device.
For example:
Computer: SALES-PC-27
09:14 Word.exe started
09:15 PowerShell.exe launched
09:15 Script downloaded
09:16 New process created
09:17 External connection established
09:18 File modified
This creates a useful timeline for analysis.
Suppose an attacker gains access to a workstation – EDR may allow investigators to determine:
- Which process started the attack
- Which files were created
- Which commands were executed
- Which accounts were involved
- Where the system connected
- What happened afterwards
EDR Can Respond Too
The R in EDR stands for Response. EDR isn’t just a monitoring system; Depending on the product and configuration, it may be able to:
- Kill a process
- Quarantine a file
- Isolate a device from the network
- Disable an account
- Block an executable
- Collect forensic information
One particularly useful EDR response is endpoint isolation.
Imagine a compromised laptop communicating with an attacker.
EDR can potentially isolate the machine from the Internet and leave it accessible to security administrators while normal network communication is restricted.
This can prevent an attacker from using the machine to move laterally.
EDR vs Antivirus
EDR doesn’t necessarily replace antivirus in a simple one-for-one sense. Modern endpoint security products often combine multiple capabilities.
Traditional antivirus might primarily ask – “Is this file malicious?”
EDR asks much broader questions, such as – “What is happening on this endpoint?”, and – “Does this sequence of activity look suspicious?”, or – “What happened before and after the suspicious activity?”
What Is a SIEM?
SIEM stands for Security Information and Event Management.
A SIEM collects security-related information from many different sources.
For example – Firewalls, Servers, EDR, VPN concentrators, Cloud services, Applications, DNS servers, etc.
So, instead of investigating every system individually, security analysts can examine events from a central location.
What Does a SIEM Collect?
A SIEM might collect information from:
Identity systems
- Logins
- Failed authentication
- MFA events
- Account changes
Firewalls
- Allowed connections
- Blocked connections
- VPN activity
Endpoints
- EDR events
- Malware detections
- Process activity
Servers
- System events
- Authentication
- Application activity
Cloud
- Administrative actions
- API calls
- Configuration changes
Applications
- Login events
- Transactions
- Security events
SIEM Correlation
One of the most useful features of a SIEM is correlation.
A single event might not be particularly interesting, but multiple events from different services paints a much more interesting picture of what’s happening.
A SIEM can correlate these events and recognise that they may represent a larger security incident.
SIEM Doesn’t Just Store Logs
It’s tempting to think of a SIEM as a big place where logs are stored, but it is much more than that.
Modern SIEM platforms can provide:
- Log collection
- Search
- Correlation
- Detection rules
- Alerting
- Dashboards
- Threat intelligence integration
- Investigation capabilities
- Analytics
The emphasis is on turning large quantities of events into useful security information.
One of the most powerful capabilities of the SIEM can be the use of threat intelligence feeds.
The landscape of cyber security threats and attacks changes at rapid pace – keeping up to date with these changes can be sometimes impossible for an organisation to manage effectively.
Fortunately, there are companies dedicated to doing just this.
These companies research and analyse threats, malware, APT groups, rogue IP ranges, and much more, on a continuous basis and generate intelligence feeds which SIEM systems can subscribe to.
Once the feed is ingested, the SIEM can scan the log data to see if any patterns exist that match the data in the feeds that could indicate a system compromise.
SIEM Detection Rules
A SIEM can be configured with rules such as:
IF:
5 failed logins
+
successful login
+
new country
+
privileged account
THEN:
Generate security alert
The exact detection logic can be much more sophisticated and tailored for specific systems, accounts, and services depending on their risk posture.
SIEM and EDR Together
EDR and SIEM complement each other extremely well.
EDR might identify:
Laptop-27
PowerShell
↓
Suspicious Script
↓
External Connection
↓
EDR ALERT
The EDR can send that alert and information to the SIEM which can then correlate it with:
EDR Alert
+
VPN Login
+
Firewall Connection
+
DNS Request
+
Identity Event
Now the security team has a much broader picture of what is happening.
What Is SOAR?
SOAR stands for Security Orchestration, Automation and Response.
SOAR is primarily concerned with automating security processes and responses. A SOAR platform can receive an alert and then perform a series of actions automatically.
Imagine a security analyst receives an alert. Normally they might have to:
- Look up the IP address.
- Check threat intelligence.
- Find the affected user.
- Find the affected device.
- Check EDR.
- Check the firewall.
- Disable the account.
- Isolate the computer.
- Create an incident ticket.
SOAR can automate some or all of this workflow.
SOAR Playbooks
SOAR systems commonly use pre-created activity plans called playbooks.
A playbook defines what should happen when a particular type of alert occurs.
For example a phishing alert may trigger the following activity:
- Extract URL from phishing email
- Check reputation of domain
- Check affected users
- Search user mailboxes
- Remove malicious emails
- Notify security team
The playbook turns a repeatable procedure into an automated workflow.
SOAR and Account Compromise
Suppose a SIEM identifies a potentially compromised account and a suspicious login
A SOAR playbook could:
- Check user account
- Check location of login
- Check device
- Check recent log activity
- Check threat intel feed
- Use results to score confidence rating
- Disable account Y/N
- Revoke logged-in sessions
- Alert SOC analyists
The exact actions depend on the organisation’s policies.
SOAR and EDR
SOAR can control or interact with EDR to reduce response times dramatically.
SOAR and SIEM
SIEM and SOAR are also closely connected.
The SIEM identifies something suspicious – The SOAR helps determine what to do about it.
SIEM vs SOAR
A useful distinction is:
| Technology | Primary role |
|---|---|
| SIEM | Collect and analyse security events |
| SOAR | Automate security workflows and response |
SIEM:
“These events together look like a compromised account.”
SOAR:
“I’ll gather the evidence, check the account, isolate the device and create an incident.”
EDR vs SIEM
Another useful distinction:
| Technology | Primary focus |
|---|---|
| EDR | Individual endpoints |
| SIEM | Organisation-wide security events |
EDR has detailed visibility into a particular device.
SIEM provides a broader view across many systems.
EDR vs SOAR
These technologies solve very different problems.
EDR:
Detect and respond to threats on endpoints.
SOAR:
Automate security processes across multiple technologies.
How the Three Work Together
The real power comes from combining all three systems.
Imagine an attacker sends a malicious document to an employee.
- Phishing email is recieved
- Employee clicks link
- EDR detects suspicious process activity
- SIEM gathers log & other telemetry data from EDR and other monitoring tools
- SOAR automates response via playbook guidance
Each technology contributes something different, but together provide a capable defence
Detection vs Response
One of the most important distinctions is between detection and response.
Detection asks “Is something wrong?”, whereas response asks “What should we do about it?”
EDR, SIEM and SOAR all contribute to these stages in different ways.
Automation Can Make Security Faster
Attackers operate quickly.
A human analyst might take several minutes to investigate and respond to an alert, but an automated workflow can potentially act within seconds.
This can significantly reduce mean time to respond (MTTR).
But automation isn’t automatically better.
Imagine a system which incorrectly identifies an executive’s laptop as compromised and immediately locks it down to prevent further escalation of the perceived attack.
This could cause significant business disruption as the executive can no longer work until the laptop is restored to working condition.
Automated response therefore needs appropriate safeguards.
Human-in-the-Loop
Some organisations require human approval before certain actions are taken.
Less dangerous actions might be fully automated, but high-impact actions may require human approval.
A useful approach to this is to divide responses into different levels.
Low Risk
Automatically:
- Enrich an alert
- Look up an IP address
- Gather endpoint information
- Create a ticket
Medium Risk
Automatically prepare:
- Account disablement
- Endpoint isolation
- Email removal
but require approval.
High Risk
Require human approval before:
- Disabling critical systems
- Blocking major network ranges
- Removing large quantities of data
The appropriate balance depends on the organisation.
SIEM, SOAR, and EDR are not perfect
SIEM storage can be expensive. Large organisations can generate billions of events per day
Storing, processing and analysing all of that information can be expensive, so organisations need to determine:
- What to collect
- What to retain
- What to index
- What to filter
- What requires real-time analysis
More logs doesn’t mean better security – Collecting everything isn’t automatically useful. The challenge is finding the useful information amongst the noise.
This is why detection engineering and effective correlation rules are important.
EDR coverage matters – EDR is only useful on endpoints it can actually monitor.
For example if you have 1000 endpoints, but can only install the EDR client on 950 of them, the 50 which are not covered by EDR may represent a visibility gap.
Security teams therefore need to monitor EDR coverage.
EDR doesn’t protect everything – EDR focuses primarily on endpoints.
It doesn’t replace:
- Firewalls
- Network monitoring
- Identity security
- Email security
- Cloud security
- Application security
SIEM doesn’t automatically make you secure – Buying a SIEM doesn’t magically create a security operations capability.
You need:
- Appropriate log sources
- Good detection rules
- Skilled analysts
- Alert tuning
- Incident-response procedures
- Adequate storage
- Appropriate retention
- Regular review
SOAR doesn’t replace security analysts – SOAR automates repeatable tasks – It doesn’t eliminate the need for people.
Security analysts still need to:
- Investigate complex incidents
- Make risk decisions
- Tune detections
- Develop playbooks
- Handle unusual attacks
- Determine business impact
SOAR should be thought of as an automation tool for security teams, not an autonomous replacement for them.
SIEM, SOAR and EDR as Security Controls
These technologies support several categories of security control.
EDR is primarily Detective + Corrective. It can detect suspicious activity and take corrective action such as isolating a device.
SIEM is primarily Detective – It collects and analyses events to identify suspicious activity.
SOAR is primarily Corrective – It can automate responses to detected incidents.
Together they provide a powerful detection-and-response capability.
In Summary
EDR — Endpoint Detection and Response
EDR focuses on individual endpoints.
It can:
- Monitor processes
- Monitor files
- Monitor network activity
- Detect suspicious behaviour
- Investigate endpoint activity
- Isolate compromised devices
- Remove or quarantine threats
Think:
“What’s happening on this computer?”
SIEM — Security Information and Event Management
SIEM collects and analyses security information from across the organisation.
It can:
- Collect logs
- Correlate events
- Detect suspicious patterns
- Generate alerts
- Provide dashboards
- Support investigations
- Integrate threat intelligence
Think:
“What’s happening across the organisation?”
SOAR — Security Orchestration, Automation and Response
SOAR automates security workflows.
It can:
- Receive alerts
- Gather additional information
- Query security tools
- Enrich events with threat intelligence
- Create tickets
- Isolate devices
- Disable accounts
- Remove malicious emails
- Notify security teams
Think:
“What should we do about it?”
The goal isn’t simply to collect more security data – It is to turn that data into visibility, detection and action.
EDR sees it. SIEM understands it. SOAR acts on it.