SOC Workbench - Threat Investigation
Security leaders know that speed matters when responding to threats. This video demo showcases how the eSentire SOC Workbench enables analysts to move from alert to actionable response with unmatched speed and precision. Watch the demo to understand how this SOC could strengthen your defenses, and contact Vaz Global Technology to explore a personalized deployment.
What is the Investigation Workbench?
The Investigation Workbench is a feature within the Insight portal that helps analysts conduct threat investigations. It provides an enrichment tool called the investigation co-pilot, which pulls additional context and information from vendors regarding log activity. This assists analysts in making informed conclusions about potential threats.
How does the system identify compromised users?
The system identifies compromised users by analyzing sign-in patterns and activities. For example, if a user typically signs in from Ireland but suddenly has multiple sign-ins from locations like the United States, Nigeria, and Tanzania within a short time frame, it raises a flag. Additionally, suspicious activities such as the creation of unusual inbox rules and the use of untrusted devices are also indicators of compromise.
What role does telemetry play in investigations?
Telemetry plays a crucial role in the investigation process by providing detailed information about processes running on an endpoint. It helps analysts build a process tree, allowing them to trace back activities to their origins. For instance, if a WScript process is spawned by an application like OneNote, telemetry can reveal the chain of events leading to that execution, which is essential for understanding potential exploitation paths.
SOC Workbench - Threat Investigation
published by Vaz Global Technology
We are a technology solutions provider with expertise in a wide range of areas, including cloud migrations, database integration, data mining, call center and voice integration software, optimization, data lakes, and AI/machine learning. In addition, we specialize in cyber security and have strategic partnerships with Fortinet, Veeam, and CloudCheckr. Our team of experts is highly experienced in helping organizations migrate from on-premises systems to cloud-based environments, ensuring a smooth transition with minimal disruption to operations. We also offer comprehensive database integration and data mining services, enabling our clients to leverage their data for business insights and better decision-making. For call center and voice integration software, we offer Amazon Connect solutions, which enable organizations to streamline their customer service operations and improve customer satisfaction. Our optimization services focus on improving system performance and efficiency, while our data lakes and AI/machine learning services help organizations make the most of their data. We prioritize cyber security and offer comprehensive solutions to help organizations protect their data and systems from threats. Our strategic partnerships with Fortinet, Veeam, and CloudCheckr enable us to offer best-in-class solutions to our clients. In addition, we offer billing as a service to help organizations streamline their billing processes and improve accuracy. We also offer AWS SNS for Amber Alerts and automation for school systems, helping educational institutions stay connected with their students and communities. Finally, we provide event and student services, helping organizations plan and execute successful events while also providing comprehensive support for student needs. With our broad range of capabilities and expertise, we are committed to helping our clients achieve their technology goals and drive business success