Become a security automation expert and build solutions that save time while making your organization more secure
Key Features
- Explore the SOAR platformOCOs full features to streamline your security operations
- Learn how to utilize threat hunting techniques for better investigation
- Leverage the capabilities of SOAR technologies such as threat intelligence to improve security posture
Book Description
Security analysts and engineers are often overwhelmed with security events and incidents, which makes it harder to resolve them in time. The growing need for a better approach to modern threats has prompted an interest in SOAR (System Orchestration, Automation and Response) tools that can help you set up automated security tasks. With the help of this expert-led book, youOCOll become well-versed with SOAR, acquire new skills, and make your organization's security posture more robust.
In this book, you can expect a thorough refresher on the importance of understanding cyber security in the first few chapters, diving into why traditional tools are no longer helpful and how SOAR can help.
After going through these insights, youOCOll learn how SOAR works and what are its benefits, including optimized threat intelligence, incident response, and utilizing threat hunting in investigations. YouOCOll also get to grips with advanced automated scenarios and explore useful tools such as Microsoft Sentinel, Palo Alto XSOAR, and so on. The final portion of this book will guide you through best practices and case studies that you can implement in real-world scenarios.
By the end of this book, you will be able to successfully automate security tasks, overcome challenges and stay ahead of threats using automation best practices.
What you will learn
- Reap the general benefits of using the SOAR platform
- Transform manual investigations into automated scenarios
- Learn how to manage known false positives and low-severity incidents for faster resolution
- Explore tips and tricks using various Microsoft Sentinel playbook actions
- Get an overview of tools such as Palo Alto XSOAR, Microsoft Sentinel, and Splunk SOAR
Who This Book Is For
This book is for SOC engineers, SOC analysts, DevSecOps professionals, or anyone working in the security ecosystem who wants to upskill toward automating security tasks. General knowledge of SIEM, SOC, and SOAR is a prerequisite, but this book is a good fit for beginners and advanced professionals alike.
Table of Contents
- State of Cybersecurity and Understanding SOAR Role
- A Deep Dive into Incident Management
- Techniques for Better Incident Investigation
- Minimize MTTA and MTTR with Automation
- Reporting as a New SOAR Start Point
- Overview of SOAR tools
- Intro to Microsoft Sentinel Automation
- Enrich Incidents using Automation
- Manage Incidents with Automation
- Respond to Incidents Using Automation
- Tips and Tricks Using Microsoft Sentinel automation