Security Orchestration, Automation, and Response for Security Analysts: Learn the secrets of SOAR to improve MTTA and MTTR and strengthen your organization's security posture


Security Orchestration, Automation, and Response for Security Analysts: Learn the secrets of SOAR to improve MTTA and MTTR and strengthen your organization’s security posture
Author: Benjamin Kovacevic (Author), Nicholas DiCola (Foreword)
Publisher finelybook 出版社:‏ Packt Publishing
Publication Date 出版日期:‏ 2023-07-20
Language 语言: English
Print Length 页数: 338
ISBN-10: 1803242914
ISBN-13: 9781803242910

Book Description

Become a security automation expert and build solutions that save time while making your organization more secure

Purchase of the print or Kindle book includes a free PDF eBook

What’s inside

  • An exploration of the SOAR platform’s full features to streamline your security operations
  • Lots of automation techniques to improve your investigative ability
  • Actionable advice on how to leverage the capabilities of SOAR technologies such as incident management and automation to improve security posture

What your journey will look like

  • With the help of this expert-led book, you’ll become well versed with SOAR, acquire new skills, and make your organization’s security posture more robust.
  • You’ll start with a refresher on the importance of understanding cyber security, diving into why traditional tools are no longer helpful and how SOAR can help.
  • Next, you’ll learn how SOAR works and what its benefits are, including optimized threat intelligence, incident response, and utilizing threat hunting in investigations.
  • You’ll also get to grips with advanced automated scenarios and explore useful tools such as Microsoft Sentinel, Splunk SOAR, and google Chronicle SOAR.
  • The final portion of this book will guide you through best practices and case studies that you can implement in real-world scenarios.
  • By the end of this book, you will be able to successfully automate security tasks, overcome challenges, and stay ahead of threats.

Some of the things you’ll learn in this book

  • How to reap the general benefits of using the SOAR platform
  • Transforming manual investigations into automated scenarios
  • How to manage known false positives and low-severity incidents for faster resolution
  • Tips and tricks using various Microsoft Sentinel playbook actions
  • All you need to know about tools such as google Chronicle SOAR, Microsoft Sentinel, and Splunk SOAR

You’ll get the most out of this book if

  • You’re a junior SOC engineer, junior SOC analyst, or anyone working in the security ecosystem who wants to upskill toward automating security tasks
  • You often feel overwhelmed with security events and incidents
  • You have general knowledge of SIEM and SOC, which is a prerequisite
  • You’re a beginner, in which case this book will give you a head start
  • You’ve been working in the field for a while, in which case you’ll add new tools to your arsenal

Table of Contents

  1. The Current State of Cybersecurity and the Role of SOAR
  2. A Deep Dive into Incident Management and Investigation
  3. A Deep Dive into Automation and Reporting
  4. Quick Dig into SOAR Tools
  5. Introducing Microsoft Sentinel Automation
  6. Enriching Incidents Using Automation
  7. Managing Incidents with Automation
  8. Responding to Incidents Using Automation
  9. Mastering Microsoft Sentinel Automation: Tips and Tricks

“An organization’s Security Operations Center (SOC) can become overwhelmed if too many alerts are generated and there are not enough SOC analysts to triage them, or skilled cybersecurity workers to fill the positions needed to respond. This is why an automated response to security incidents is a must. SOAR is the answer to an organization’s SOC overcoming these challenges. SOAR can be used to reduce the number of alerts that need investigation and triage, to automate parts of normal investigations and save SOC analysts’ time, and more importantly, to automate remediation, leading to quick actions to resolve security incidents. In this book, you will learn about security orchestration, automation, and response in depth, both in theory and principle, using real playbook examples to automate a response. You will learn about the tools available and the various methods to implement them as a partial or complete security incident response. Benjamin is a skilled professional and expert in SOAR, helping customers implement it and creating samples, shared through open source to help organizations enable their security automation.”

Nicholas DiCola,

Vice President of Customers

Zero Networks

Amazon page

打赏
未经允许不得转载:finelybook » Security Orchestration, Automation, and Response for Security Analysts: Learn the secrets of SOAR to improve MTTA and MTTR and strengthen your organization's security posture

评论 抢沙发

觉得文章有用就打赏一下

您的打赏,我们将继续给力更多优质内容

支付宝扫一扫

微信扫一扫