Current approaches for SOC automation are focused on making alerts more consumable and running playbooks, but ultimately defenders run the risk of having their systems compromised by not investigating every single alert. This presentation will discuss how the evolutionary nature of software can enable a zero-trust approach to a large volume of alerts. Through identification examples of trusted Microsoft software, high-risk malware Emotet and Ursnif, and a nation state sponsored threat from APT17, it will demonstrate how the Genetic Malware Analysis approach prioritises files according to risk and severity, and accelerates all stages of the incident response cycle.Learning Outcomes:Understand some of the major challenges incident response and SOC teams face on a daily basis.Apply the biological immune system concepts to cybersecurity, and understand how the Genetic Malware Analysis approach works. All malware is based on previously written software or binary code, and detecting even the smallest fragments of code similarities between files can classify malware to its relevant malware family and make attributions.Learn how the Genetic Malware Analysis approach and identifying code reuse similarities between files (both malicious and trusted software) improves security operations and accelerates all stages of the incident response cycle.Identify and distinguish between trusted software, high-risk malware, and nation state sponsored threats through real-life examples.Learn practical applications of incident response flows using the Genetic Malware Analysis approach.