Use case · SOC Investigation for Server Applications
Give your SOC code-level answers
A process alert tells you where to look. Raven shows the code behind it: the library, execution path and action inside your server application. Investigate suspicious behavior and give developers evidence they can act on.
what happened
✓
which code did it
✓
where to investigate
✓
FROM ALERT TO ANSWER · ILLUSTRATIVE RUNTIME INVESTIGATION
/ 02 — SCENARIOS
Same process. Very different explanations.
SCENARIO A
A feature that looks like an attack
A server application launches a child process. Is it an attacker executing a command, or a library converting a document? Trace the action to its code before escalating.
SCENARIO B
A connection that needs an explanation
An application contacts an unexpected destination. Identify the library behind the connection and the path that reached it. Investigate the actual code involved, with the affected workload in view.
Connect a sensitive process, network or file operation to the library behind it inside the affected server application.
2
Understand the execution path
See the chain of library calls that led to the action. Assess the behavior in its application context.
3
Give developers a clear starting point
Bring the action, workload and library chain into the investigation. Help the application team examine the relevant code and explain its behavior.
/ 04 — EVIDENCE
One event. The missing explanation.
See how an action inside a server application traces back to a library and its execution path. Give your analyst the context to investigate, and your application team a concrete starting point.
3
2
1
1
What happened
The child-process action, timestamp and recorded event outcome.
2
Which code caused it
The originating library and observed execution chain.
3
Where to investigate
The affected server workload or application identifier.
Make the next step clearer.
Investigate sensitive actions with library and execution-path context.
Check whether the behavior is expected before escalating.
Give SOC and engineering the same code-level evidence.
/ 06 — FAQ
Questions from the SOC
Does this replace our EDR or SIEM?
Raven adds library and execution-path context from inside server applications. Use that evidence alongside your endpoint, network and SIEM data to investigate the event.
Can Raven help explain false positives?
Yes. Code context helps analysts check whether a suspicious action came from an expected library feature. Confirm the behavior with the application team before closing the alert.
What can I give the developer?
The affected workload, observed action, originating library and execution chain. This gives the application team a concrete place to investigate and validate the behavior.
Know which code. Know where to investigate.
See the library behind an application event, follow its execution path and give your SOC a clearer next step.