L3 SOC Analyst Splunk Incident Runbook Automation
Master Splunk-based incident runbook automation to streamline security operations, enhance response efficiency, and proactively mitigate threats.
...
Share
Fundamentals of Incident Response Automation with Splunk
Unit 1: Introduction to SOAR and Splunk
What is SOAR?
SOAR Principles
Splunk for SOAR
Splunk's Automation
SOAR Use Cases
Unit 2: Designing Incident Response Workflows
Workflow Design
Runbook Essentials
Runbook Automation
Adaptive Response
Metrics & Measurement
Unit 3: Setting Up a Splunk Environment for Automation
Splunk Setup
Data Ingestion
User Roles
Testing the Setup
Dev and Prod
Building Automated Runbooks for Common Incident Types
Unit 1: Phishing Incident Runbook Automation
Phishing Runbook Overview
Email Header Analysis
URL & Attachment Analysis
User Quarantine Automation
Phishing Runbook Reporting
Unit 2: Malware Incident Runbook Automation
Malware Runbook Overview
Endpoint Isolation
Threat Containment
Malware Signature Updates
Malware Runbook Reporting
Unit 3: Data Exfiltration Incident Runbook Automation
Exfil Runbook Overview
Data Source Analysis
User Activity Monitoring
Adaptive Response Actions
Exfil Runbook Reporting
Integrating Splunk with External Security Tools and Threat Intelligence
Unit 1: Splunk REST API Integration
Intro to Splunk's REST API
API Authentication
Making API Requests
Parsing API Responses
API Rate Limiting
Unit 2: Threat Intelligence Integration
Intro to Threat Intel
Threat Intel Feeds
Enriching Incident Data
Adaptive Response
Threat Intel Frameworks
Unit 3: Orchestration with Security Tools
SOAR Platforms
Integrating SIEM
Orchestrating EDR
Network Security Tools
Cloud Security Tools
Advanced Automation Techniques and Custom App Development
Unit 1: Custom Splunk App Development for Incident Response
Intro to Splunk App Dev
Building a Basic App
Custom Alert Actions
Adding a Custom Dashboard
App Deployment Strategies
Unit 2: Monitoring and Auditing Automated Runbooks
Logging Automation Actions
Creating Audit Trails
Monitoring Runbook Performance
Alerting on Failures
Compliance Reporting
Unit 3: Troubleshooting and Optimizing Workflows
Debugging Techniques
Common Pitfalls
Performance Tuning
Reducing False Positives
Workflow Optimization
Unit 4: Advanced Automation Techniques
Adaptive Response
Machine Learning
Orchestration with APIs
Event Enrichment
Proactive Threat Hunting