XSOAR for SOC Analysts: Core Architecture, UI Navigation, Playbooks, Incident Investigation, and Dashboard Customization
Empower your SOC analysts with essential XSOAR skills: architecture, UI, playbooks, incident handling, and dashboard customization.
...
Share
XSOAR Core Architecture Fundamentals
Unit 1: Introduction to SOAR and XSOAR
What is SOAR?
Why XSOAR?
XSOAR Use Cases
Unit 2: XSOAR Architecture Deep Dive
Core Components
Demisto Server Explained
Database Details
Integration Architecture
Unit 3: XSOAR Deployment and Data Flow
On-Premise Deployment
Cloud Deployment
Hybrid Deployment
Data Ingestion
Analysis & Response
Data Flow Security
Unit 4: Component Interaction and Scalability
Component Interactions
Navigating the XSOAR User Interface
Unit 1: XSOAR UI: Core Navigation
Welcome to the UI!
The Incidents Page
Dashboard Overview
Playbooks Section
War Room Explained
Unit 2: Advanced UI Features
Global Search Mastery
Filter Like a Pro
Sorting Columns
Customizing Columns
UI Personalization
Unit 3: Incident Layouts and War Room Deep Dive
Anatomy of an Incident
Context Data is King
War Room Collaboration
War Room Commands
Playbook Essentials: Automation and Orchestration
Unit 1: Understanding XSOAR Playbooks
What are Playbooks?
Playbook Key Elements
Playbook Structure
Inputs & Outputs
Conditional Branching
Unit 2: Common Playbook Tasks
Data Enrichment Tasks
Threat Intel Lookups
Remediation Actions
User Interaction Tasks
Notification Tasks
Unit 3: Playbook Execution and Analysis
Manual Playbook Trigger
Automatic Playbook Trigger
Analyzing Playbooks
Playbook Best Practices
Incident Investigation and Response
Unit 1: Incident Investigation Fundamentals
Incident Triage in XSOAR
Alert Analysis in XSOAR
Root Cause Analysis
Unit 2: Data Enrichment and Threat Hunting
Enrichment Overview
IP Enrichment
Domain & URL Enrichment
File Hash Enrichment
Threat Hunting Basics
Unit 3: Remediation and Documentation
Containment Actions
Eradication Actions
Recovery Actions
Closing the Incident
Reporting on Incidents
Lessons Learned
Customizing Layouts and Visualizing Data
Unit 1: Layout Customization Fundamentals
Layouts: The Big Picture
Accessing the Layout Editor
Adding Fields to Layouts
Arranging Layout Elements
Layout Best Practices
Unit 2: Dashboard Creation and Configuration
Dashboards: The Overview
Creating a New Dashboard
Adding Widgets to Dashboards
Configuring Widget Settings
Dashboard Best Practices
Unit 3: Advanced Dashboard Techniques
Custom Widget Creation
Sharing Dashboards
Dashboard Drill-Downs
Data Interpretation
Advanced XSOAR Features and Integrations
Unit 1: XSOAR Integrations: The Powerhouse
Intro to Integrations
Integration Architecture
Configuring Integrations
Managing Integrations
Common Integration Types
Unit 2: Reporting and Threat Intelligence
XSOAR Reporting
Report Configuration
Threat Intel Overview
TI Integration
TI in Playbooks
Unit 3: XSOAR API and Advanced Automation
Intro to the XSOAR API
API Authentication
API Use Cases
Custom Integrations