Cortex XSOAR for SOC Analysts: Incident Response Automation
Master Cortex XSOAR and revolutionize your SOC workflow with automated incident response, threat intelligence, and seamless security tool integration.
...
Share
Introduction to SOAR and XSOAR
Unit 1: Understanding SOAR Fundamentals
What is SOAR?
SOAR Benefits for the SOC
SOAR Use Cases
SOAR Key Metrics
SOAR Implementation Tips
Unit 2: Introduction to Cortex XSOAR
Meet Cortex XSOAR
XSOAR Key Features
XSOAR Capabilities
XSOAR Marketplace
XSOAR Use Cases
Unit 3: XSOAR Architecture and Components
XSOAR Architecture
XSOAR Components
Deployment Options
Data Flow in XSOAR
XSOAR Scalability
Setting Up Your XSOAR Environment
Unit 1: Deployment Options and System Requirements
XSOAR: Cloud vs. On-Prem
Sizing Up XSOAR
Pre-Install Checklist
Unit 2: Initial Setup and Configuration
Cloud Setup: First Steps
On-Premise Install Guide
Basic Configuration
License Activation
Unit 3: User Roles, Permissions, and Interface Customization
User Roles: The Basics
Custom Roles: Granular Access
Authentication Methods
Dashboard Customization
Layouts: Tailoring Views
Themes: A New Look
Unit 4: Advanced Configuration and Optimization
Integration Marketplace
System Diagnostics
Navigating the XSOAR Interface
Unit 1: XSOAR Interface Overview
Welcome to XSOAR!
Dashboard Deep Dive
Incidents Section
Playbooks Section
Integrations Section
Unit 2: Core XSOAR Functionality
Automation Central
Threat Intel Management
XSOAR Marketplace
Settings and Configuration
Reporting Section
Unit 3: Advanced Navigation and Customization
XSOAR Search Mastery
Customizing the Layout
War Room: Real-Time Intel
Keyboard Shortcuts
Dark Mode
Incident Management Fundamentals
Unit 1: Understanding Incidents in XSOAR
What is an Incident?
Incident Data Model
Incident Lifecycle Stages
Incident Statuses
Unit 2: Manual Incident Creation and Alert Ingestion
Creating Incidents Manually
Alert Ingestion Overview
SIEM Integration
Email Alert Ingestion
Unit 3: Incident Handling and Management
Deduplication
Merging Incidents
Linking Incidents
Incident Assignment
Incident Priority
Incident SLAs
Closing Incidents
Incident Enrichment and Investigation
Unit 1: Understanding Incident Enrichment
Why Enrich Incidents?
Enrichment Data Sources
Manual vs. Automated
Unit 2: Enriching Incidents with Threat Intelligence
Threat Intel Feeds
Enriching IP Addresses
Domain Enrichment
File Hash Enrichment
Unit 3: Gathering Information with XSOAR Commands
XSOAR Command Basics
Network Info Commands
Endpoint Info Commands
External Tool Commands
Unit 4: Analyzing Incident Data and Patterns
Data Correlation
Timeline Analysis
Visualization
Unit 5: Documenting and Collaborating on Incidents
Adding Comments
Incident Tasking
Introduction to Playbooks
Unit 1: Understanding Playbooks
What is a Playbook?
Why Use Playbooks?
Playbook Use Cases
Playbook Building Blocks
Tasks vs. Activities
Unit 2: XSOAR Playbook Editor
Meet the Playbook Editor
Adding Tasks Visually
Configuring Task Inputs
Conditional Branching
Looping Through Data
Unit 3: Building Your First Playbook
Planning the Playbook
Creating a New Playbook
Adding Initial Tasks
Testing the Playbook
Activating the Playbook
Building and Customizing Playbooks
Unit 1: Playbook Editor Essentials
Navigating the Editor
Adding Your First Task
Configuring Task Inputs
Understanding Outputs
Task Properties Deep Dive
Unit 2: Branching and Looping
Conditional Branching 101
Building Complex Branches
Looping for Efficiency
Iterating Like a Pro
Combining Branching/Looping
Unit 3: Customization and Layout
Playbook Layout Basics
Customizing Task Appearance
Using Sub-Playbooks
Dynamic Sections
Playbook Version Control
Integrating with Security Tools
Unit 1: Understanding XSOAR Integrations
What are Integrations?
Integration Types
Integration Hub Overview
Pre-built vs. Custom
Unit 2: Installing and Configuring Integrations
Installing Integrations
Configuring Integrations
Instance Management
Permissions & Integrations
Unit 3: Using Integrations in Playbooks
Integrations in Playbooks
Dynamic Inputs
Error Handling
Polling Integrations
Unit 4: Troubleshooting and Advanced Topics
Troubleshooting Basics
Debugging Commands
Advanced Tips
Automating Threat Intelligence Enrichment
Unit 1: Fundamentals of Threat Intelligence in XSOAR
TI Enrichment Intro
TI Indicators
XSOAR's TI Feeds
Manual TI Enrichment
Unit 2: Integrating with Threat Intelligence Platforms (TIPs)
TIP Integration Intro
Configure a TIP
Querying a TIP
Automated TIP Lookup
Unit 3: Playbooks for Automated Threat Hunting
Threat Hunting Intro
Hunting Playbook
Hunting for Malware
Hunting for Phishing
Hunting for Insider Threats
Unit 4: Managing and Updating Threat Intelligence Feeds
Feed Management
Feed Updates
Custom Feeds
Automating User Lockout and Response
Unit 1: Understanding User Lockout Automation
Lockout Automation Intro
XSOAR for Lockouts
Planning Your Playbook
Unit 2: Integrating with Identity Management Systems
AD Integration Basics
AD Integration Deep Dive
Other IDM Systems
Unit 3: Building the User Lockout Playbook
Playbook Foundation
Decision Points
Lockout Actions
Notification Tasks
Unit 4: Handling False Positives and Unlock Requests
False Positive Handling
Unlock Request Process
Unlock Automation
Unit 5: Documentation, Auditing, and Refinement
Documenting Lockouts
Auditing Lockouts
Playbook Refinement
Basic Troubleshooting
Unit 1: Identifying Common XSOAR Issues
Common XSOAR Issues
Checking XSOAR Health
Resource Monitoring
Connectivity Issues
Version Compatibility
Unit 2: Troubleshooting Integration Failures
Integration Status
API Errors
Authentication Issues
Permissions Problems
Data Mapping Errors
Unit 3: Troubleshooting Playbook Errors
Playbook Debugging
Task Failures
Conditional Logic
Looping Issues
Variable Errors
Unit 4: XSOAR Logs and Escalation
XSOAR Logs
Escalation Paths
Reporting and Metrics
Unit 1: XSOAR Reporting Fundamentals
Reporting Overview
Accessing Reports
Report Types
Report Permissions
Report Scheduling
Unit 2: Generating and Customizing Reports
Generating Reports
Report Parameters
Customizing Reports
Chart Customization
Dashboard Creation
Unit 3: Analyzing and Utilizing Report Data
SOC Metrics
Incident Response
Report Export
Report Automation
Report Best Practices
Collaboration and Communication
Unit 1: XSOAR Collaboration Features
Teamwork in XSOAR
Incident Ownership
Analyst Roles & Permissions
War Room Intro
War Room: Chatting
Unit 2: Communication Platform Integration
Comms Platform Integrations
Slack Integration Setup
Teams Integration Setup
Slack: Incident Updates
Teams: Incident Updates
Unit 3: Task Management
Tasks: The Basics
Task Assignment
Task Status Updates
Task Dependencies
Automated Task Creation
Advanced Playbook Techniques
Unit 1: Sub-Playbooks and Customization
Sub-Playbook Basics
Creating Sub-Playbooks
Calling Sub-Playbooks
Custom Fields: The Basics
Creating Custom Fields
Unit 2: Custom Layouts and Scripting
Custom Layouts: Overview
Building Custom Layouts
Scripting in Playbooks
Basic Scripting
Advanced Scripting
Unit 3: Error Handling and Optimization
Error Handling: Basics
Handling Errors
Playbook Optimization
Optimizing Playbooks
Testing & Validation