Cortex XSOAR for SOC Analysts: Building Automated Incident Response Playbooks
Empower your SOC with Cortex XSOAR: Master automated incident response playbooks and elevate your threat management capabilities.
...
Share
Introduction to Security Orchestration, Automation, and Response (SOAR)
Unit 1: Understanding SOAR Fundamentals
What is SOAR?
SOAR Benefits for SOCs
SOAR Core Capabilities
SOAR Use Cases
SOAR Deployment Models
Unit 2: SOAR in the Security Ecosystem
SOAR vs. SIEM
SOAR vs. TIP
SOAR Key Components
SOAR and the MITRE ATT&CK
SOAR Future Trends
Understanding Cortex XSOAR
Unit 1: Cortex XSOAR: An Overview
What is Cortex XSOAR?
Key Features: At a Glance
The Power of Automation
Threat Intel Integration
XSOAR Use Cases
Unit 2: Under the Hood: XSOAR Architecture
Core Components
Data Flow Explained
Integration Architecture
Scalability & High Avail.
Deployment Options
Navigating the Cortex XSOAR Interface
Unit 1: Exploring the XSOAR User Interface
XSOAR UI: First Look
Dashboard Deep Dive
Incidents Overview
Navigating War Room
Accessing Marketplace
Unit 2: Searching, Filtering, and Customization
Global Search Function
Filtering Incidents
Customizing Layouts
User Preferences
Keyboard Shortcuts
Incident Management in Cortex XSOAR
Unit 1: Incident Creation and Lifecycle
Incident Lifecycle Stages
Creating New Incidents
Incident Triage
Incident Investigation
Incident Resolution
Unit 2: Incident Fields and Assignment
Core Incident Fields
Custom Incident Fields
Assigning Incidents
Incident Roles
Service Level Agreements
Introduction to Playbooks
Unit 1: Understanding Playbooks
What is a Playbook?
Playbook-Driven Automation
Playbook Task Types
Playbook Activities
Playbook Use Cases
Unit 2: Creating Your First Playbook
Accessing the Editor
Editor Interface Overview
Adding Your First Task
Connecting the Dots
Running Your Playbook
Building Basic Playbooks
Unit 1: Core Playbook Elements
Playbook Task Types
Working with Inputs
Outputs & Context Data
Conditional Statements
Looping Constructs
Unit 2: Playbook Best Practices
Error Handling
Logging
Playbook Testing
Debugging Techniques
Playbook Documentation
Integrations in Cortex XSOAR
Unit 1: Understanding and Configuring Integrations
What are Integrations?
Integration Types
Navigating the Marketplace
Configuring Integrations
Integration Instances
Unit 2: Working with Integrations and Troubleshooting
Using Integrations
SIEM Integration
EDR Integration
Troubleshooting
Best Practices
Threat Intelligence Management
Unit 1: Integrating and Enriching with Threat Intelligence
TI Feed Integration
TI Feed Connectors
Enriching Incidents
Automated Enrichment
Indicator Scoring
Unit 2: Automating Analysis and Managing Threat Intel
TI Analysis Playbooks
TI Report Generation
TI Curation
Sharing TI
TI Lifecycle Mngmt
Customizing Incident Layouts and Reporting
Unit 1: Customizing Incident Layouts
Layout Customization 101
Adding/Removing Sections
Adding Custom Fields
Rearranging Fields
Conditional Visibility
Unit 2: Reporting and Dashboards
Reporting Overview
Creating Basic Reports
Customizing Reports
Dashboard Design
Dashboard Widgets
Advanced Playbook Development
Unit 1: Advanced Playbook Techniques
Branching Out
Sub-Playbook Power
Scripting Magic
Custom Functions
Dynamic Sections
Unit 2: Playbook Optimization and Collaboration
Version Control
Teamwork Makes...
Performance Tuning
Scaling Up
Playbook Documentation
SOAR Implementation Best Practices
Unit 1: Planning and Implementing SOAR
Defining SOAR Scope
Team Roles & Responsibilities
Integration Strategy
Deployment Considerations
Change Management
Unit 2: Maintaining and Optimizing SOAR
Testing and Validation
Documenting SOAR
Performance Monitoring
Updating Cortex XSOAR
Continuous Improvement
Use Case: Automating Phishing Investigations
Unit 1: Building the Phishing Investigation Playbook
Phishing Playbook: Start
Detonate Those Attachments
Extract Email Indicators
Threat Intel Enrichment
Escalate or Remediate
Unit 2: Advanced Phishing Playbook Techniques
User Interaction Tasks
Dynamic Indicator Scoring
Adaptive Learning
Reporting and Metrics
Evolving the Playbook