XSOAR Automation for New SOC Analysts
Empowering new SOC analysts with the essential skills to automate security operations using Cortex XSOAR, SIEM, and EDR integrations.
...
Share
Introduction to Security Automation and Orchestration
Unit 1: Understanding Security Automation and SOAR
What is Automation?
The Power of Orchestration
Why Automate Security?
SOAR to the Rescue!
SOAR Use Cases
Unit 2: XSOAR Architecture and Benefits
Meet Cortex XSOAR
XSOAR's Core
Integrations are Key
Playbooks: Automation Magic
XSOAR Benefits
Cortex XSOAR Fundamentals: UI and Navigation
Unit 1: XSOAR UI: Getting Started
Logging In & Initial View
Dashboard Overview
Navigating the Modules
User Profile & Settings
Help & Documentation
Unit 2: Customization and Search
Dashboard Customization
Creating Custom Widgets
Global Search Function
Advanced Search Techniques
Filtering Data in Modules
Incident Handling in Cortex XSOAR
Unit 1: Incident Creation and Management
Incident Lifecycle Intro
Creating Incidents
Incident Details
Editing Incidents
Closing Incidents
Unit 2: Incident Fields and Layouts
Incident Fields Intro
Key Incident Fields
Custom Fields
Layout Overview
Layout Customization
Introduction to Playbooks
Unit 1: Understanding Playbooks
What is a Playbook?
Playbooks vs. Scripts
Anatomy of a Playbook
Tasks & Integrations
Conditions & Branching
Unit 2: Exploring the Playbook Editor
Navigating the Editor
Task Configuration
Using Pre-built Tasks
Exploring Pre-built PB's
Adapting Playbooks
Building Your First Playbook: Basic Incident Enrichment
Unit 1: Playbook Creation and Configuration
Creating a New Playbook
Adding the First Task
Using the IP Reputation Task
Mapping Data to Incidents
Saving the Playbook
Unit 2: Testing and Debugging
Running the Playbook
Inspecting the War Room
Debugging Basics
Fixing Common Errors
Iterating and Improving
Working with Indicators
Unit 1: Understanding and Fetching Indicators
What are Indicators?
Fetching IOCs: Manual
Fetching IOCs: Integrations
Fetching IOCs: Playbooks
Indicator Context
Unit 2: Managing and Using Indicators
Indicator Types
Indicator Reputation
Indicator Lists
List Management
Using Indicators
Data Manipulation: Commands and Functions
Unit 1: XSOAR Commands and Functions
Intro to XSOAR Commands
Basic Data Retrieval
Data Formatting
Intro to XSOAR Functions
Filtering with Functions
Unit 2: Conditional Statements and Enrichment
Conditional Statements
Data Enrichment Basics
Enrich with Reputation
String Manipulation
Advanced Enrichment
Integration with SIEM: Alert Handling
Unit 1: SIEM Integration Fundamentals
SIEM & XSOAR: Better Togeth
Supported SIEM Integrations
API Keys & Permissions
Test the Connection
SIEM Integration: Gotchas
Unit 2: Automating Alert Handling
Alert Ingestion Methods
Alert to Incident
Alert Handling Playbook
SIEM Alert Enrichment
Alert Auto-Closure
SIEM Integration: Alert Correlation
Unit 1: Understanding Alert Correlation in XSOAR
Alert Correlation Intro
Correlation Rules
XSOAR Correlation Engine
Correlation Configuration
Viewing Correlated Incidents
Unit 2: Automating Alert Correlation with Playbooks
Playbook for Correlation
SIEM Alert Ingestion
Correlation Logic
Incident Prioritization
Testing and Tuning
Integration with EDR: Endpoint Investigation
Unit 1: EDR Integration Fundamentals
EDR & XSOAR: Better Togethr
Choosing Your EDR
Auth & API Keys
Test Your Connection
EDR Data Ingestion
Unit 2: Automating Endpoint Investigation
Get Process Info
File Analysis
Network Connection Intel
Endpoint Isolation
Enriching Incidents
EDR Integration: Endpoint Response Actions
Unit 1: Automating Endpoint Response
Response Action Overview
Isolate Host Playbook
Killing Malicious Process
Blocking Malicious Files
Reversing Isolation
Unit 2: Advanced Response Automation
Approval Processes
User Input for Actions
Response Action Status
Automated Reporting
Rollback Strategies
Playbook Debugging and Troubleshooting
Unit 1: Debugging Playbooks
Common Errors
XSOAR Debugger
Reading Error Messages
Logging is Your Friend
Testing Playbooks
Unit 2: Error Handling
Try-Catch Blocks
Conditional Error Checks
Rollback Mechanisms
Retrying Failed Tasks
Escalation Procedures
Integration Troubleshooting
Unit 1: Common Integration Problems
Integration Issues Intro
Connectivity Problems
Auth Issues
Data Format Errors
Rate Limiting
Unit 2: XSOAR Troubleshooting Tools
XSOAR's Tools
Using Integration Logs
Test Integration
Health Check
External Tools
Advanced Playbook Techniques: Sub-Playbooks
Unit 1: Understanding and Creating Sub-Playbooks
What are Sub-Playbooks?
Creating a Sub-Playbook
Calling Sub-Playbooks
Sub-Playbook Scope
Sub-Playbook Nesting
Unit 2: Advanced Sub-Playbook Techniques
Passing Data to Sub-PB
Dynamic Sub-Playbooks
Sub-PB for Reusability
Sub-PB Version Control
Troubleshooting Sub-PB
Advanced Playbook Techniques: Loops and Iteration
Unit 1: Mastering Loops in Playbooks
Intro to Playbook Loops
For Each Loops
While Loops
Loop Context and Data
Loop Best Practices
Unit 2: Dynamic Playbooks and Optimization
Dynamic Playbook Paths
Automating Repetitive Tasks
Optimizing Performance
Parallel Processing
Real-World Examples
Custom Integrations: Introduction
Unit 1: Why Custom Integrations?
The Need for Custom Int
Identifying Integration Gaps
Custom vs. Marketplace
Intro to APIs
API Authentication Methods
Unit 2: Python and the XSOAR Framework
Python Basics for XSOAR
XSOAR Integration Kit
Anatomy of an Integration
Integration Configuration
Commands and Arguments
Reporting and Dashboards
Unit 1: Creating Custom Reports
Report Basics
Report Data Sources
Filtering Report Data
Report Visualizations
Custom Report Creation
Unit 2: Building and Scheduling Dashboards
Dashboard Basics
Adding Widgets
Dashboard Layouts
Scheduling Reports
Dashboard Creation
Collaboration and Communication
Unit 1: XSOAR Collaboration Features
Incident War Room
Tasks and Assignments
Notes and Annotations
XSOAR User Roles
Audit Trails
Unit 2: Automated Communication
Email Notifications
Slack Integration
MS Teams Integration
Playbook Communication
Custom Communication
Best Practices for XSOAR Automation
Unit 1: Playbook Design and Security Best Practices
Playbook Design Principles
Secure Credentials
Input Validation
Error Handling
Least Privilege Principle
Unit 2: Performance, Scalability, and Maintenance
Optimize Playbook Perf
Scalability Strategies
Integration Updates
Playbook Version Control
Automated Documentation
Real-World Use Cases and Case Studies
Unit 1: Analyzing Real-World XSOAR Use Cases
Phishing Incident Auto
Malware Analysis Auto
Vulnerability Mgmt Auto
Insider Threat Auto
Threat Intel Auto
Unit 2: Case Studies and Opportunities
Case Study: Ransomware
Case Study: Data Breach
Finding Automation Opps
Building a Business Case
Next Steps