SlackAsk

Huge update to XSOAR Slackv3

In August of 2022, after consulting with the SecOps team at Code42, XSOAR released a vital update to the Slack content pack that enables simple block configuration and allows users to select and send data back into XSOAR. 

Release Notes - August 29, 2022 SlackBlockBuilder

This development is driving automated workflows that perform empathetic investigations within Code42, and we hope to release new playbooks as part of the Code42 Incydr/Instructor content pack before the end of FY2022!

Palo Alto Networks Symphony  - May 2022

Laura, Zach, and their colleagues at Code42 are a small security team in a growing company, and we need the ability to scale our incident handling without necessarily growing our team. For this reason, our SOAR platform, Palo Alto XSOAR, is a vital part of the security ecosystem. 

In addition to accelerating detection through indicator identification and enrichment, we've identified an opportunity to use XSOAR to enable Empathetic Investigations in the cyber security space. This concept was pioneered by Insider Risk Management experts within Code42, and the Security Operations team is using their findings and strategies to perform the same kind of investigations with many other security events, not just insider risk events. 

In service of this, we are leveraging the Slack integration to facilitate communication with employees within the company when security boundaries are tread. By sending a friendly robot rather than an analyst, we are:

There is much more to say about "how to train your incident handling robots", but this presentation focused on how XSOAR and the Slack integration have been applied to performing Empathetic Investigations in our SOC.

Link - Note that you have to register for the Palo Alto Networks Symphony portal to view. Sorry for the inevitable vendor spam if you do!


Palo Alto Symphony 2022 - SlackAsk, But With More Buttons