I'm about 2 years into SOC work and I'm curious about other analysts workflow friction.
What's the part of your day that you find yourself thinking "this is dumb, why am i still doing this manually" Examples i'm curious about:
- IOC enrichment (jumping between VT, AbuseIPDB, Shodan etc. for one investigation)
- Pivoting between tools when chasing an alert
- Translating findings into reports
- Query writing/tuning
- Triaging false positives
- Documenting cases
- Dealing with phishing analyses
Which of these or others is actual daily pain vs. which has been solved well enough by your current stack?
For me i would love to have a tool where i got my utility tools and do all IOC lookups, enrichments in one. Or am i just missing something?