Cortex XSoar for Cybersecurity Specialists: Incident Response Automation & Workflow Design
Master Cortex XSoar to automate incident response, design efficient workflows, and orchestrate security tools for enhanced cybersecurity.
...
Share
Cortex XSoar Fundamentals and Initial Configuration
Unit 1: Introduction to Cortex XSoar
XSoar: What & Why?
XSoar Core Components
Navigating the UI
XSoar Editions & Licensing
Deployment Options
Unit 2: Initial Setup and Configuration
First Login & Setup
User Roles & Permissions
Configuring API Keys
Configuring SSL Certificates
System Settings Deep Dive
Unit 3: Integrating with Security Tools
Integration Overview
SIEM Integration
EDR Integration
Threat Intel Integration
Email Integration
Designing and Implementing Automated Playbooks
Unit 1: Playbook Design Fundamentals
Intro to Playbook Design
Navigating the Editor
Playbook Inputs & Outputs
Basic Playbook Structure
Testing Your Playbook
Unit 2: Implementing Incident Triage
Triage: The Big Picture
Automated Data Collection
Severity Assessment
Assigning Ownership
Triage Complete!
Unit 3: Enrichment and Containment
Enrichment Overview
Threat Intel Integration
Containment Strategies
Blocking Indicators
Isolating Endpoints
Unit 4: Error Handling and Logging
Error Handling: Why?
Try-Catch Blocks
Logging Best Practices
Custom Error Messages
Escalation Strategies
Enriching Incident Data and Leveraging Threat Intelligence
Unit 1: Threat Intelligence Feeds in XSoar
Intro to Threat Feeds
Configuring Threat Feeds
Working with Indicators
Automated Indicator Ingestion
Testing Threat Feeds
Unit 2: Contextual Enrichment
Contextual Enrichment 101
Enrichment Integrations
Playbooks for Enrichment
Analyzing Enriched Data
Custom Enrichment Scripts
Unit 3: Automating Threat Intel
Automated Intel Gathering
Intel Dissemination
Playbooks for Intel
Sharing Intel
Intel Validation
Customization, Reporting, and Advanced Techniques
Unit 1: Custom Integrations: Laying the Groundwork
Integration Architecture
Setting Up Dev Environment
Integration YAML Structure
Basic Python Scripting
Testing Integrations
Unit 2: Advanced Integration Techniques
Error Handling
Rate Limiting
Data Transformation
Context Management
Secure Coding Practices
Unit 3: Reporting and Dashboards
Report Fundamentals
Creating Basic Reports
Custom Report Design
Dashboard Creation
Sharing Reports
Unit 4: Machine Learning in XSoar
ML Fundamentals
Training ML Models
Automated Tasking
Improving Detection
ML Best Practices