Security Orchestration, Automation, and Response for Security Analysts: Learn the secrets of SOAR to improve MTTA and MTTR and strengthen your organization’s security posture
- Length: 338 pages
- Edition: 1
- Language: English
- Publisher: Packt Publishing
- Publication Date: 2023-07-21
- ISBN-10: 1803242914
- ISBN-13: 9781803242910
- Sales Rank: #1274387 (See Top 100 Books)
Description
Become a security automation expert and build solutions that save time while making your organization more secure
Purchase of the print or Kindle book includes a free PDF eBook
What’s inside
- An exploration of the SOAR platform’s full features to streamline your security operations
- Lots of automation techniques to improve your investigative ability
- Actionable advice on how to leverage the capabilities of SOAR technologies such as incident management and automation to improve security posture
What your journey will look like
- With the help of this expert-led book, you’ll become well versed with SOAR, acquire new skills, and make your organization’s security posture more robust.
- You’ll start with a refresher on the importance of understanding cyber security, diving into why traditional tools are no longer helpful and how SOAR can help.
- Next, you’ll learn how SOAR works and what its benefits are, including optimized threat intelligence, incident response, and utilizing threat hunting in investigations.
- You’ll also get to grips with advanced automated scenarios and explore useful tools such as Microsoft Sentinel, Splunk SOAR, and Google Chronicle SOAR.
- The final portion of this book will guide you through best practices and case studies that you can implement in real-world scenarios.
- By the end of this book, you will be able to successfully automate security tasks, overcome challenges, and stay ahead of threats.
Some of the things you’ll learn in this book
- How to reap the general benefits of using the SOAR platform
- Transforming manual investigations into automated scenarios
- How to manage known false positives and low-severity incidents for faster resolution
- Tips and tricks using various Microsoft Sentinel playbook actions
- All you need to know about tools such as Google Chronicle SOAR, Microsoft Sentinel, and Splunk SOAR
You’ll get the most out of this book if
- You’re a junior SOC engineer, junior SOC analyst, or anyone working in the security ecosystem who wants to upskill toward automating security tasks
- You often feel overwhelmed with security events and incidents
- You have general knowledge of SIEM and SOC, which is a prerequisite
- You’re a beginner, in which case this book will give you a head start
- You’ve been working in the field for a while, in which case you’ll add new tools to your arsenal
Table of Contents
- The Current State of Cybersecurity and the Role of SOAR
- A Deep Dive into Incident Management and Investigation
- A Deep Dive into Automation and Reporting
- Quick Dig into SOAR Tools
- Introducing Microsoft Sentinel Automation
- Enriching Incidents Using Automation
- Managing Incidents with Automation
- Responding to Incidents Using Automation
- Mastering Microsoft Sentinel Automation: Tips and Tricks
Free ChaptersTry Audible and Get Two Free Audiobooks »
To access the link, solve the captcha.
Recommended BooksMore Similar Books »
Ransomware Analysis: Knowledge Extraction and Classification for Advanced Cyber Threat Intelligence
2024-11-13
Subscribe
Categories
Tags