For the requests coming through SOAR to function properly after approval, the SOAR integration must be correctly implemented into the application. You can access this page for the SOAR integration.
For requests to appear in SOAR Approval, the user or admin must first submit a SOAR request from the reported e-mails section. The SOAR part appears at the very bottom after clicking on the reported email.
From the previous tab you can view & edit the following:
- Domain of the person sending the SOAR Approval is displayed in the Approval section.
- IP address of the person sending the SOAR Approval is displayed in the Approval section.
- Specify until which date the SOAR Approval will be valid.
- Data for the action to be seen in SOAR Approval is sent.
- You can select which Domains from the email will be sent to SOAR Approval.
- You can select which IP addresses from the email will be sent to SOAR Approval.
- You can select which URLs from the email will be sent to SOAR Approval.
- You can select which Hashes from the email will be sent to SOAR Approval.
- You can add external notes within the SOAR Approval.
Afterward, when you click the process button, the SOAR Approval will appear in the SOAR Approval tab for the administrator of the application.
SOAR Approval Page
In this section, you can view incoming SOAR Approvals, approve or reject them if you are an administrator, or learn the details about the approval.
From here you can view the following:
- You can view the status of the incoming approval.
- Approved shows that the request has been approved by the administrator.
- Pending indicates that the request is in a waiting stage.
- Rejected indicates that the request has been rejected.
- From which email the approval was sent.
- Which SOAR resource the approval was sent.
- The date the approval was sent.
- The details of the approval.
From here you can view the following:
- The email address of the person who reported the email.
- The subject of the email.
- The email of the person who sent the SOAR Approval.
- The domains sent for SOAR Approval.
- The IP addresses sent for SOAR Approval.
- The hashes sent for SOAR Approval.
- You can approve or reject the incoming approval.
Process Section
After the SOAR Approval request is approved, if you go to the SOAR section at the bottom of the email, you will find the Processes section where you can view all the SOAR Approvals that have been made for that email so far.
From here you can view the following:
- The request was processed on the SOAR side is displayed.
- The author is displayed.
- The SOAR service is being used is displayed.
- The data being used is displayed (Domains, IP Addresses, Hashes, etc.).
- The status of the request sent to the SOAR service is displayed.
- The action taken by the SOAR service is displayed.