From Sore to SOAR: Reinventing Sentinel Automation Without Logic Apps | Henri Hambartsumyan @WildWestHackinFest
From Sore to SOAR: Reinventing Sentinel Automation Without Logic Apps | Henri Hambartsumyan  @WildWestHackinFest
Uploaded April 2025 | Updated September 2026, 2 weeks ago
🔗 Join us in-person and virtually at our Wild West Hackin' Fest: information security conferences — wildwesthackinfest.com

🔗 Register for Infosec Webcasts, Anti-casts & Summits. – poweredbybhis.com

This talk shares our journey building a custom SOAR-like solution for Microsoft Sentinel that 1) combines full-code flexibility with low-code simplicity, and 2) overcomes the limitations of Logic Apps in performance, maintainability, and debugging. Learn about architecture and design decisions, integrations, limitations and other lessons we learned when building our SOAR.

00:00 - Welcome, Intro
00:47 - Automation in Sentinel (Microsoft’s SIEM)
01:21 - Sending Sentinel incidents to SNOW with LogicApps
01:58 - LogicApp pitfalls
02:53 - Difficult to debug
03:03 - Stability issues
04:08 - Variable email times
05:10 - How to do it better
09:59 - Architecture Iteration 1 overview
11:41 - Architecture Iteration 1 issues not fixed
12:44 - New issues introduced
13:27 - Sentinel Automation limitations and workarounds
16:24 - Architecture Iteration 2 overview
16:41 - Architecture Iteration 2 results
18:09 - Architecture Iteration 3 overview
20:11 - Architecture Iteration 3 results
21:16 - Storing enrichment data in Sentinel
23:51 - Entity normalization
28:57 - Caching considerations
32:03 - Architecture Iteration 4 goals and explanations
33:13 - Triggering custom actions from the dashboard
35:27 - Recursive enrichments
36:20 - Playbook support
36:35 - JINT
37:18 - Improve reliability
38:15 - Polly
40:05 - Conclusion
40:54 - Q&A - How much is written in LogicApps?
41:16 - Q&A - Azure spend - LogicApps vs code
41:47 - Q&A - What does Microsoft say about the unreliability of LogicApps?
42:14 - Q&A - How to handle sentinel delaying the addition of entities to an incident or alert?
42:58 - Q&A - What was the transition process? How long did it take?
43:41 - Q&A - Are customers surprised at the amount of Sentinel automation required?

///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe

///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections

///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response

///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com

///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training

///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter

Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
From Sore to SOAR: Reinventing Sentinel Automation Without Logic Apps | Henri HambartsumyanBuild your Sh*tty Add-On With KiCad For Your Electronic Badges! | Adrien Lasalle
Wild West Hackin Fest |

From Sore to SOAR: Reinventing Sentinel Automation Without Logic Apps | Henri Hambartsumyan

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER