SIEM, SOAR and EDR: The Technologies That Help Security Teams Detect and Respond to Attacks

Imagine a large office building with hundreds of rooms.

There are security cameras throughout the building, access-control systems on the doors, alarms, security guards and a central security control room.

Now imagine something suspicious happens.

  • A door is forced open.
  • A camera sees someone entering.
  • An employee’s access card is used at an unusual time.
  • An alarm is triggered.

The security team needs to bring all of this information together, decide whether something is wrong, investigate it and take action.

Modern cybersecurity uses technologies that perform similar functions.

Three particularly important technologies are:

  • SIEM — Security Information and Event Management
  • SOAR — Security Orchestration, Automation and Response
  • EDR — Endpoint Detection and Response

They perform different jobs, but they work extremely well together.

EDR watches individual devices. SIEM brings security information together. SOAR helps automate the response.

The Three Technologies at a Glance

A simple way of understanding the difference is:

  • SIEM – Analyses events – “Something suspicious is happening across the organisation.”
  • SOAR – Responds and automates activity – “Let’s automatically do something about it.”
  • EDR – Detects endpoint activity – “Something suspicious is happening on this computer.”

What Is EDR?

EDR stands for Endpoint Detection and Response.

An endpoint is a device such as:

  • Desktop computer
  • Laptop
  • Server
  • Virtual machine

EDR software runs on these devices and continuously monitors activity.

It looks for suspicious behaviour such as:

  • Unusual processes
  • Suspicious PowerShell activity
  • Malware
  • Unexpected network connections
  • Changes to important files
  • Attempts to disable security controls
  • Privilege escalation
  • Suspicious persistence mechanisms

The EDR agent watches what is happening on the endpoint and reports suspicious activity.

EDR Doesn’t Just Look for Malware

This is an important distinction – Traditional antivirus often focused heavily on identifying known malicious files, but EDR can look at behaviour.

For example:

Word.exe spawns PowerShell.exe which downloads a file and executes a script which connects to the Internet and also modifies the Windows registry

Individually, some of these actions might be legitimate, but together, they could look very suspicious.

EDR can look for patterns of events rather than simply asking “Is this file on a malware blacklist?”

This makes EDR useful against threats that may not have a known malware signature such as a Zero-day.

EDR Provides Visibility

EDR can provide security teams with detailed information about what happened on a device.

For example:

Computer: SALES-PC-27

09:14  Word.exe started
09:15  PowerShell.exe launched
09:15  Script downloaded
09:16  New process created
09:17  External connection established
09:18  File modified

This creates a useful timeline for analysis.

Suppose an attacker gains access to a workstation – EDR may allow investigators to determine:

  • Which process started the attack
  • Which files were created
  • Which commands were executed
  • Which accounts were involved
  • Where the system connected
  • What happened afterwards

EDR Can Respond Too

The R in EDR stands for Response. EDR isn’t just a monitoring system; Depending on the product and configuration, it may be able to:

  • Kill a process
  • Quarantine a file
  • Isolate a device from the network
  • Disable an account
  • Block an executable
  • Collect forensic information

One particularly useful EDR response is endpoint isolation.

Imagine a compromised laptop communicating with an attacker.

EDR can potentially isolate the machine from the Internet and leave it accessible to security administrators while normal network communication is restricted.

This can prevent an attacker from using the machine to move laterally.

EDR vs Antivirus

EDR doesn’t necessarily replace antivirus in a simple one-for-one sense. Modern endpoint security products often combine multiple capabilities.

Traditional antivirus might primarily ask – “Is this file malicious?”

EDR asks much broader questions, such as – “What is happening on this endpoint?”, and – “Does this sequence of activity look suspicious?”, or – “What happened before and after the suspicious activity?”

What Is a SIEM?

SIEM stands for Security Information and Event Management.

A SIEM collects security-related information from many different sources.

For example – Firewalls, Servers, EDR, VPN concentrators, Cloud services, Applications, DNS servers, etc.

So, instead of investigating every system individually, security analysts can examine events from a central location.

What Does a SIEM Collect?

A SIEM might collect information from:

Identity systems

  • Logins
  • Failed authentication
  • MFA events
  • Account changes

Firewalls

  • Allowed connections
  • Blocked connections
  • VPN activity

Endpoints

  • EDR events
  • Malware detections
  • Process activity

Servers

  • System events
  • Authentication
  • Application activity

Cloud

  • Administrative actions
  • API calls
  • Configuration changes

Applications

  • Login events
  • Transactions
  • Security events

SIEM Correlation

One of the most useful features of a SIEM is correlation.

A single event might not be particularly interesting, but multiple events from different services paints a much more interesting picture of what’s happening.

A SIEM can correlate these events and recognise that they may represent a larger security incident.

SIEM Doesn’t Just Store Logs

It’s tempting to think of a SIEM as a big place where logs are stored, but it is much more than that.

Modern SIEM platforms can provide:

  • Log collection
  • Search
  • Correlation
  • Detection rules
  • Alerting
  • Dashboards
  • Threat intelligence integration
  • Investigation capabilities
  • Analytics

The emphasis is on turning large quantities of events into useful security information.

One of the most powerful capabilities of the SIEM can be the use of threat intelligence feeds.

The landscape of cyber security threats and attacks changes at rapid pace – keeping up to date with these changes can be sometimes impossible for an organisation to manage effectively.

Fortunately, there are companies dedicated to doing just this.

These companies research and analyse threats, malware, APT groups, rogue IP ranges, and much more, on a continuous basis and generate intelligence feeds which SIEM systems can subscribe to.

Once the feed is ingested, the SIEM can scan the log data to see if any patterns exist that match the data in the feeds that could indicate a system compromise.

SIEM Detection Rules

A SIEM can be configured with rules such as:

IF:

5 failed logins
+
successful login
+
new country
+
privileged account

THEN:

Generate security alert

The exact detection logic can be much more sophisticated and tailored for specific systems, accounts, and services depending on their risk posture.

SIEM and EDR Together

EDR and SIEM complement each other extremely well.

EDR might identify:

Laptop-27

PowerShell
   ↓
Suspicious Script
   ↓
External Connection
   ↓
EDR ALERT

The EDR can send that alert and information to the SIEM which can then correlate it with:

EDR Alert
   +
VPN Login
   +
Firewall Connection
   +
DNS Request
   +
Identity Event

Now the security team has a much broader picture of what is happening.

What Is SOAR?

SOAR stands for Security Orchestration, Automation and Response.

SOAR is primarily concerned with automating security processes and responses. A SOAR platform can receive an alert and then perform a series of actions automatically.

Imagine a security analyst receives an alert. Normally they might have to:

  1. Look up the IP address.
  2. Check threat intelligence.
  3. Find the affected user.
  4. Find the affected device.
  5. Check EDR.
  6. Check the firewall.
  7. Disable the account.
  8. Isolate the computer.
  9. Create an incident ticket.

SOAR can automate some or all of this workflow.

SOAR Playbooks

SOAR systems commonly use pre-created activity plans called playbooks.

A playbook defines what should happen when a particular type of alert occurs.

For example a phishing alert may trigger the following activity:

  • Extract URL from phishing email
  • Check reputation of domain
  • Check affected users
  • Search user mailboxes
  • Remove malicious emails
  • Notify security team

The playbook turns a repeatable procedure into an automated workflow.

SOAR and Account Compromise

Suppose a SIEM identifies a potentially compromised account and a suspicious login

A SOAR playbook could:

  • Check user account
  • Check location of login
  • Check device
  • Check recent log activity
  • Check threat intel feed
  • Use results to score confidence rating
  • Disable account Y/N
  • Revoke logged-in sessions
  • Alert SOC analyists

The exact actions depend on the organisation’s policies.

SOAR and EDR

SOAR can control or interact with EDR to reduce response times dramatically.

SOAR and SIEM

SIEM and SOAR are also closely connected.

The SIEM identifies something suspicious – The SOAR helps determine what to do about it.

SIEM vs SOAR

A useful distinction is:

TechnologyPrimary role
SIEMCollect and analyse security events
SOARAutomate security workflows and response

SIEM:

“These events together look like a compromised account.”

SOAR:

“I’ll gather the evidence, check the account, isolate the device and create an incident.”

EDR vs SIEM

Another useful distinction:

TechnologyPrimary focus
EDRIndividual endpoints
SIEMOrganisation-wide security events

EDR has detailed visibility into a particular device.

SIEM provides a broader view across many systems.

EDR vs SOAR

These technologies solve very different problems.

EDR:

Detect and respond to threats on endpoints.

SOAR:

Automate security processes across multiple technologies.

How the Three Work Together

The real power comes from combining all three systems.

Imagine an attacker sends a malicious document to an employee.

  • Phishing email is recieved
  • Employee clicks link
  • EDR detects suspicious process activity
  • SIEM gathers log & other telemetry data from EDR and other monitoring tools
  • SOAR automates response via playbook guidance

Each technology contributes something different, but together provide a capable defence

Detection vs Response

One of the most important distinctions is between detection and response.

Detection asks “Is something wrong?”, whereas response asks “What should we do about it?”

EDR, SIEM and SOAR all contribute to these stages in different ways.

Automation Can Make Security Faster

Attackers operate quickly.

A human analyst might take several minutes to investigate and respond to an alert, but an automated workflow can potentially act within seconds.

This can significantly reduce mean time to respond (MTTR).

But automation isn’t automatically better.

Imagine a system which incorrectly identifies an executive’s laptop as compromised and immediately locks it down to prevent further escalation of the perceived attack.

This could cause significant business disruption as the executive can no longer work until the laptop is restored to working condition.

Automated response therefore needs appropriate safeguards.

Human-in-the-Loop

Some organisations require human approval before certain actions are taken.

Less dangerous actions might be fully automated, but high-impact actions may require human approval.

A useful approach to this is to divide responses into different levels.

Low Risk

Automatically:

  • Enrich an alert
  • Look up an IP address
  • Gather endpoint information
  • Create a ticket

Medium Risk

Automatically prepare:

  • Account disablement
  • Endpoint isolation
  • Email removal

but require approval.

High Risk

Require human approval before:

  • Disabling critical systems
  • Blocking major network ranges
  • Removing large quantities of data

The appropriate balance depends on the organisation.

SIEM, SOAR, and EDR are not perfect

SIEM storage can be expensive. Large organisations can generate billions of events per day

Storing, processing and analysing all of that information can be expensive, so organisations need to determine:

  • What to collect
  • What to retain
  • What to index
  • What to filter
  • What requires real-time analysis

More logs doesn’t mean better security – Collecting everything isn’t automatically useful. The challenge is finding the useful information amongst the noise.

This is why detection engineering and effective correlation rules are important.

EDR coverage matters – EDR is only useful on endpoints it can actually monitor.

For example if you have 1000 endpoints, but can only install the EDR client on 950 of them, the 50 which are not covered by EDR may represent a visibility gap.

Security teams therefore need to monitor EDR coverage.

EDR doesn’t protect everything – EDR focuses primarily on endpoints.

It doesn’t replace:

  • Firewalls
  • Network monitoring
  • Identity security
  • Email security
  • Cloud security
  • Application security

SIEM doesn’t automatically make you secure – Buying a SIEM doesn’t magically create a security operations capability.

You need:

  • Appropriate log sources
  • Good detection rules
  • Skilled analysts
  • Alert tuning
  • Incident-response procedures
  • Adequate storage
  • Appropriate retention
  • Regular review

SOAR doesn’t replace security analysts – SOAR automates repeatable tasks – It doesn’t eliminate the need for people.

Security analysts still need to:

  • Investigate complex incidents
  • Make risk decisions
  • Tune detections
  • Develop playbooks
  • Handle unusual attacks
  • Determine business impact

SOAR should be thought of as an automation tool for security teams, not an autonomous replacement for them.

SIEM, SOAR and EDR as Security Controls

These technologies support several categories of security control.

EDR is primarily Detective + Corrective. It can detect suspicious activity and take corrective action such as isolating a device.

SIEM is primarily Detective – It collects and analyses events to identify suspicious activity.

SOAR is primarily Corrective – It can automate responses to detected incidents.

Together they provide a powerful detection-and-response capability.

In Summary

EDR — Endpoint Detection and Response

EDR focuses on individual endpoints.

It can:

  • Monitor processes
  • Monitor files
  • Monitor network activity
  • Detect suspicious behaviour
  • Investigate endpoint activity
  • Isolate compromised devices
  • Remove or quarantine threats

Think:

“What’s happening on this computer?”

SIEM — Security Information and Event Management

SIEM collects and analyses security information from across the organisation.

It can:

  • Collect logs
  • Correlate events
  • Detect suspicious patterns
  • Generate alerts
  • Provide dashboards
  • Support investigations
  • Integrate threat intelligence

Think:

“What’s happening across the organisation?”

SOAR — Security Orchestration, Automation and Response

SOAR automates security workflows.

It can:

  • Receive alerts
  • Gather additional information
  • Query security tools
  • Enrich events with threat intelligence
  • Create tickets
  • Isolate devices
  • Disable accounts
  • Remove malicious emails
  • Notify security teams

Think:

“What should we do about it?”

The goal isn’t simply to collect more security data – It is to turn that data into visibility, detection and action.

EDR sees it. SIEM understands it. SOAR acts on it.