Use cases / 04 — Give Your SOC Code-Level Answers
Use case · SOC Investigation for Server Applications

Give your SOC code-level answers

A process alert tells you where to look. Raven shows the code behind it: the library, execution path and action inside your server application. Investigate suspicious behavior and give developers evidence they can act on.
THE ALERT YOUR SOC GETS
THE ANSWER RAVEN ADDS
what happened which code did it where to investigate
FROM ALERT TO ANSWER · ILLUSTRATIVE RUNTIME INVESTIGATION
Favor LogoSageSure Logogopuff LogoWindward LogoZesty Logo
Favor LogoSageSure Logogopuff LogoWindward LogoZesty Logo
Favor LogoSageSure Logogopuff LogoWindward LogoZesty Logo
/ 02 — SCENARIOS

Same process.  Very different explanations. 

SCENARIO A

A feature that looks like an attack

A server application launches a child process. Is it an attacker executing a command, or a library converting a document? Trace the action to its code before escalating.
SCENARIO B

A connection that needs an explanation

An application contacts an unexpected destination. Identify the library behind the connection and the path that reached it. Investigate the actual code involved, with the affected workload in view.
/ 03 — MECHANISM

Follow the action back to the code.

INVESTIGATION — EVENT #2211
14:02:11 child process on payments-worker
trace: DOC-CONVERT convert() render() spawn(soffice)
context: workload · action · library · execution chain
HANDOFF READY → application team
ILLUSTRATIVE RUNTIME INVESTIGATION
1

Identify the library

Connect a sensitive process, network or file operation to the library behind it inside the affected server application.
2

Understand the execution path

See the chain of library calls that led to the action. Assess the behavior in its application context.
3

Give developers a clear starting point

Bring the action, workload and library chain into the investigation. Help the application team examine the relevant code and explain its behavior.
/ 04 — EVIDENCE

One event.   The missing explanation. 

See how an action inside a server application traces back to a library and its execution path. Give your analyst the context to investigate, and your application team a concrete starting point.
Raven event: anomalous code execution on log4j-4255-vulnerable workload, blocked via policy 3 2 1
1

What happened

The child-process action, timestamp and recorded event outcome.
2

Which code caused it

The originating library and observed execution chain.
3

Where to investigate

The affected server workload or application identifier.

Make the next step clearer.

Investigate sensitive actions with library and execution-path context.
Check whether the behavior is expected before escalating.
Give SOC and engineering the same code-level evidence.
/ 06 — FAQ

Questions from the SOC

Does this replace our EDR or SIEM?

Raven adds library and execution-path context from inside server applications. Use that evidence alongside your endpoint, network and SIEM data to investigate the event.

Can Raven help explain false positives?

Yes. Code context helps analysts check whether a suspicious action came from an expected library feature. Confirm the behavior with the application team before closing the alert.

What can I give the developer?

The affected workload, observed action, originating library and execution chain. This gives the application team a concrete place to investigate and validate the behavior.

Know which code. Know where to investigate.

See the library behind an application event, follow its execution path and give your SOC a clearer next step.
BOOK A DEMO