CyTech AQUILA - Security Orchestration, Automation, and Response (SOAR)

Overview:

The SOAR module helps streamline and enhance security operations by automating responses to security alerts and orchestrating workflows across various tools and systems. It allows for faster incident detection, response, and resolution, ensuring your security team can effectively handle a wide range of incidents without manual intervention.

Key Features:

Pre-requisites

  1. Access to CyTech - AQUILA
    • Only users assigned the "Owner" or "Admin" role can access the Control Panel page within this module.

To navigate to SOAR Module please follow the instructions below:

Step 1: Log in to CyTech - AQUILA. click here --> usdc.cytechint.io
Step 2: Click on SOC Optimization

HEHE-2 (8).png

Step 3: Choose Security Orchestration, Automation and Response (SOAR).

HEHE (22).png

Step 4: Hover into leftmost panel to view all the SOAR sections. This Process is applicable in all navigating into a Module.

Hello (11).png

Dashboard

The SOAR Dashboard allows you to monitor and manage security incidents in real time. It provides key metrics like Incident Status, Automated Playbooks, Response Actions, and Case Prioritization, helping you quickly assess and respond to security events while streamlining workflows.

HEHE (15).png

Incident Type by Status: This widget breaks down the incidents by their current status: "Open," "In Progress," "Pending," and "Closed." In the provided data, there are no incidents listed, with "Total Incidents" showing as 0, meaning there are no incidents requiring immediate action at the moment.

HEHE (19).png

Open Alerts Table: The Open Alerts Table lists all the currently open alerts, showing detailed information for each one. The table includes the alert ID, timestamp, rule name, risk score, and severity of the incident. For example, it shows multiple entries related to External User File Access with a risk score of 47 and a severity level marked as "Medium." These entries help the security team assess the potential threats and prioritize actions.

HEHE (20).png

Severity Breakdown of Alerts: This widget displays a breakdown of the severity levels of the ongoing incidents. The severity levels are categorized by color codes, such as Severe, High, Elevated, Guarded, and Low. The widget helps track the urgency of incidents and prioritize response efforts accordingly.

image.png

Control Panel

The Control Panel is the hub for managing alerts, rules, and tools. It lets users configure settings for Alert Tagging, Alert Rules, and External Tools, offering an organized way to control how security alerts and responses are handled.

HEHE (21).png

Alert Tagging

The Alert Tagging section in the Control Panel allows you to organize and prioritize your alerts using custom tags. This feature helps users manage their alerts more effectively. Currently, there are no tags set, and the section shows an empty state.

HEHE (22).png

Alert Rules

The Alert Rules section in the Control Panel provides a comprehensive list of active detection rules. Each rule is associated with a specific alert or action that the system monitors. The table lists key details, such as the rule name, risk score, severity, and the status of the rule’s last response. This section also indicates whether the rule is currently enabled or disabled, with the option to toggle its status.

HEHE (24).png

  1. Search Rule
    • At the top of the table, there is a search bar that allows users to filter and search for specific alert rules. This feature helps users quickly locate a particular rule based on its name or other criteria.
  2. Enabled/Disabled Rules
    • There are two buttons above the list: Enabled Rules and Disabled Rules. These buttons allow users to toggle between viewing only enabled or disabled rules, providing a more streamlined way to manage and review the status of detection rules.

      HEHE (26).png

  1. Rule Overview

    • Each row in the table presents details of an individual alert rule, such as:

      • Rule: The name of the rule and associated system or operation.

      • Risk Score: The assigned risk score for the rule, which helps indicate the potential severity of the detected activity.

      • Severity: A color-coded indicator representing the severity level of the rule, ranging from low to high.

      • Last Run: The most recent execution time of the rule.

      • Last Response: The outcome of the rule's most recent execution, which can be "Succeeded," "Failed," or "Partial Failure."

      • Last Updated: When the rule was last updated.

      • Enabled: Indicates whether the rule is currently active or disabled.

      image.png

This section helps system administrators monitor and manage active detection rules and respond to threats effectively.

Tools

The Tools section in the Control Panel allows users to manage and enhance their IP security using custom tools. This section displays a list of available tools, including their current state and the actions that can be taken with them. At the moment, no tools are displayed, indicating that there are no custom tools configured or available in the system.

HEHE (27).png

Conclusion

Security Orchestration, Automation, and Response (SOAR) is a powerful module designed to enhance the efficiency of security operations and enable faster responses to cyber threats. It streamlines monitoring processes and supports security teams by automating workflows and incident handling. Additionally, users can manage alert tagging, configure alert rules, and control integrated tools through a centralized control panel, making threat management more organized and user-friendly.

If you need further assistance, kindly contact support@cytechint.com for prompt assistance and guidance. 


Revision #9
Created 23 September 2025 07:50:49 by Richmond Abella
Updated 17 April 2026 03:30:24