Taking Automation Beyond the SOC With Advanced Network Access Control

Security orchestration, automation and response (SOAR) tools are most commonly known for automating manual security operations processes in order to expedite security investigations or cyber response. For instance, Splunk’s SOAR technology, Splunk Phantom, is most commonly used to automate alert triage, phishing investigation and response, threat hunting and application vulnerability management.

But in reality, a robust SOAR technology like Splunk Phantom is not a “SOC-only” technology. It should allow you to automate any process using any tool as long as that third-party tool has an API on the backend of it. Through that API, Splunk Phantom can instruct that tool to perform actions automatically in response to any stimulus. You can bring in any meaningful data from any tool into the platform, whether it’s security-related data, such as “notables” from Splunk Enterprise Security (ES) and newly detected vulnerabilities, or non-security related data, such as ticket status or email content from an inbox. Ultimately, you can leverage Splunk Phantom’s capabilities in a variety of ways to automatically execute processes at machine speed.

Automation for IT, Security and Beyond

Booz Allen Hamilton, a consulting firm, helps U.S. government entities build solutions that adhere to the requirements laid out by the Department of Homeland Security (DHS) and the Continuous Diagnostics and Mitigation (CDM) Program. They help government entities reduce cyber risk and provide security visibility across various federal agencies, including safeguarding sensitive data that is distributed across government networks and restricting access to unauthorized users.

To deliver on this promise, Booz Allen needs to be able to answer four key questions:

  1. What is on the network? Identification of all types of hardware and software operating on the network is crucial.
  2. Who is on the network? They must also be able to identify all users and systems with access authorization and indicate the level of authorization.
  3. What is happening on the network? The capability to analyze events, incidents and cyber risks on an ongoing basis is also critical.
  4. How is data protected on the network? Finally, Booz Allen needed a way to collect security information and activity logs of the users and devices, regardless of location.

Traditional network access control (NAC) solutions like Forescout CounterACT and Cisco Identity Services Engine can certainly help block wired endpoints using standard policies that are native to the NAC solution, but the Department of Homeland Security (DHS) wanted to increase security by using automation to block all endpoints using posture assessment. After analyzing and understanding the relationship between the network, systems and users, Booz Allen Hamilton was ready to supplement traditional NAC solutions with automation and orchestration.

Booz Allen approached the Splunk Phantom team and asked, “Can Splunk Phantom automate processes associated with network access control? Moreover, can we block all endpoints using Comply-2-Connect (C2C) posture assessment with automation and orchestration?” After a moment of head scratching, the Splunk Phantom team said, “Yes, we can do that,” and then got to work creating NAC automation playbooks that had to meet very robust performance requirements, including:

Piece of cake, right? To learn how Splunk Phantom and Booz Allen Hamilton achieved these goals and helped the Department of Homeland Security implement advanced network access control, join us for a webinar, "Taking Automation Beyond the SOC With Advanced Network Access Control."

----------------------------------------------------
Thanks!
Kelly Huang

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.