- Outbound, over Syslog: verdicts, extracted threat intelligence, and the full analyst and admin audit trail. This is what a SIEM ingests, and what a SOAR uses as a playbook trigger.
- Inbound, over HTTPS: the List API, which lets a playbook or script change list entries without a human in the web interface.
SIEM & SOAR
SIEM & SOAR Overview
The two ways xorlab connects to a SIEM or SOAR: an outbound event stream over Syslog, and an inbound REST API for automation.
Both integrations are optional. xorlab protects email without either of them, and analysts can do everything described here by hand in the web interface.
They rest on two interfaces: