[DIMVA26] Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study
Conference Moosmann, J., Pekaric, I., Apruzzese, G., Conference on Detection of Intrusions and Malware & Vulnerability Assessment, 2026
Oneliner: Apparently, the operators of our examined SOC mostly rely on 'gut feelings'.
