Alessio Brescia
Design and Implementation of Standardized Incident Response Playbooks for SOC Automation: From Sigma-Based Detection Engineering to AI-Assisted SOAR Orchestration.
Rel. Cataldo Basile, Alberto Briano. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2026
Abstract
Security Operations Centers operate in an increasingly complex landscape characterized by high volumes of heterogeneous security events, evolving attack techniques and stringent requirements for timely and accurate incident response. In this context, the initial phases of incident handling, particularly detection triage and early response, are often affected by fragmentation, manual effort and variability in analyst decision-making, which can reduce both efficiency and consistency across operations. This thesis proposes a structured and reproducible approach to address these challenges by integrating detection engineering, automated orchestration and AI-assisted decision support into a unified operational pipeline. The work is based on the definition of portable detection logic using Sigma rules, subsequently translated into platform-specific queries for SGBox and Splunk in order to enable alert generation in heterogeneous SIEM environments.
These alerts act as triggers for automated playbooks implemented within an orchestration layer based on n8n, where enrichment, contextual analysis and preliminary response actions are performed through the integration of internal telemetry, external threat intelligence services and machine learning-based components
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Informazioni aggiuntive
Corso di laurea
Classe di laurea
Aziende collaboratrici
URI
![]() |
Modifica (riservato agli operatori) |
