XSOAR Automation for New SOC Analysts

Empowering new SOC analysts with the essential skills to automate security operations using Cortex XSOAR, SIEM, and EDR integrations.

Introduction to Security Automation and Orchestration

Unit 1: Understanding Security Automation and SOAR

Unit 2: XSOAR Architecture and Benefits

Cortex XSOAR Fundamentals: UI and Navigation

Unit 1: XSOAR UI: Getting Started

Unit 2: Customization and Search

Incident Handling in Cortex XSOAR

Unit 1: Incident Creation and Management

Unit 2: Incident Fields and Layouts

Introduction to Playbooks

Unit 1: Understanding Playbooks

Unit 2: Exploring the Playbook Editor

Building Your First Playbook: Basic Incident Enrichment

Unit 1: Playbook Creation and Configuration

Unit 2: Testing and Debugging

Working with Indicators

Unit 1: Understanding and Fetching Indicators

Unit 2: Managing and Using Indicators

Data Manipulation: Commands and Functions

Unit 1: XSOAR Commands and Functions

Unit 2: Conditional Statements and Enrichment

Integration with SIEM: Alert Handling

Unit 1: SIEM Integration Fundamentals

Unit 2: Automating Alert Handling

SIEM Integration: Alert Correlation

Unit 1: Understanding Alert Correlation in XSOAR

Unit 2: Automating Alert Correlation with Playbooks

Integration with EDR: Endpoint Investigation

Unit 1: EDR Integration Fundamentals

Unit 2: Automating Endpoint Investigation

EDR Integration: Endpoint Response Actions

Unit 1: Automating Endpoint Response

Unit 2: Advanced Response Automation

Playbook Debugging and Troubleshooting

Unit 1: Debugging Playbooks

Unit 2: Error Handling

Integration Troubleshooting

Unit 1: Common Integration Problems

Unit 2: XSOAR Troubleshooting Tools

Advanced Playbook Techniques: Sub-Playbooks

Unit 1: Understanding and Creating Sub-Playbooks

Unit 2: Advanced Sub-Playbook Techniques

Advanced Playbook Techniques: Loops and Iteration

Unit 1: Mastering Loops in Playbooks

Unit 2: Dynamic Playbooks and Optimization

Custom Integrations: Introduction

Unit 1: Why Custom Integrations?

Unit 2: Python and the XSOAR Framework

Reporting and Dashboards

Unit 1: Creating Custom Reports

Unit 2: Building and Scheduling Dashboards

Collaboration and Communication

Unit 1: XSOAR Collaboration Features

Unit 2: Automated Communication

Best Practices for XSOAR Automation

Unit 1: Playbook Design and Security Best Practices

Unit 2: Performance, Scalability, and Maintenance

Real-World Use Cases and Case Studies

Unit 1: Analyzing Real-World XSOAR Use Cases

Unit 2: Case Studies and Opportunities