In this talk we would like to take you through a practical sequence of SOC improvements, bringing an example organization from a fully manual set of partially or completely undocumented workflows to a semi-automated and consistently executable process. We will demonstrate that the introduction of automation can both save analysts' time and increase the sophistication of problems they can tackle. We will show two practical examples of automated approaches to common intelligence and correlation tasks.With the emergence of SOAR technologies and enterprise-class threat intelligence exchanges at around the same time, analysts can now spend less time performing manual data collection work and can be more involved with increasingly sophisticated tasks. Due to the infinitely flexible nature of SOAR technology and the rich data provided by threat intelligence providers, practically any security workflow can be automated with some analysis, time, and effort. In this talk we will share some of the lessons learned when first starting a SOAR practice and growing it to a fully mature and operationalized state. We will demonstrate the resolution of four security incidents using increasing levels of case management and automation, from fully manual to mostly automated.First, we will operate in a purely manual mode, tracking our process with chat, email, and a wiki. At this stage our security posture is highly dependent on the quality and knowledge of the particular analyst handling the incident on that particular day. This level of maturity often lacks attribution, audit, and a consistent process to follow. It is also not uncommon to either have an action plan that is unused and out of date, an action plan that is indefinitely 'under development' and unpublished, or no action plan whatsoever.From there we will extract the processes of the team and represent them in a structured, repeatable way. In this second phase we are able to track the state of investigations, maintain an audit trail, and execute simple automated actions to expedite the enrichment of indicators and the notification of stakeholders.Moving to a third phase, we will show a playbook that starts to demonstrate the types of proactive security tasks that are incredibly inefficient without automation. We will use the popular service called "Have I Been Pwned" to check publicly exposed password breaches for the private email addresses belonging to our employees (providing during on-boarding). If there are matches we will automatically generate an email to the user with the details along with recommendations to protect both themselves and the company. We will also query internally for other systems for which those passwords may be in place, and reset them accordingly.Transitioning to a full-fledged SOAR and threat intelligence use case, we will show proactive threat hunting leveraging indicators of various types from an enterprise threat intelligence provider, and correlating those internally with any systems to which they have connected. Based on the threat score from the threat intelligence provider and a threshold that is defined in the playbook, the analyst will be able to make an informed decision on how to respond to each piece of reported data. From there the playbook will block network connections and processes related to the threat intelligence and report on the actions that were taken to other IT teams that manage the systems being controlled.By the end of our talk we hope to have educated our audience about a pathway to SOAR adoption, demonstrated the power and flexibility of incorporating automation into their security workflow, and to have inspired a few ideas for new SOAR and threat intelligence use cases.Key take-aways:We will show the thought process and practical implications to consider when designing and implementing an automated playbook for using SOAR to ingest threat intelligence, compare it against internal data, and respond when a detection is generated. We hope to inspire participants to come up with new SOAR use cases and improve their SOC maturity.