17 Soar
17 Soar
11:55AM ET Break
What’s Happening, and When?
Please support this atmosphere with respectful behavior and speech. This
applies to all online interactions including the event Slack channel and in
Zoom.
#01-announcements – Visit this channel to learn about upcoming events and important announcements!
#02-discussion – Converse with fellow attendees, our SANS Chairperson, and invited guest speakers who are also
attending or presenting today!
#04-business-card-swap-meet - Drop your LinkedIn or Twitter handles in this channel to connect with fellow
industry professionals!
#07-Pets – Show off your fur baby for laughs and likes!
Q&A in Zoom
If you’re not joining us on
Slack, please use Zoom’s Q&A
window to submit questions
to our presenters.
• Who is VMRay?
• Demonstration
• Q&A
Who is VMRay?
Company Overview
A cloud and on-premise advanced threat detection and Manual Malware Triage and Phishing Analysis
analysis platform.
12
Analyst Burnout a “Real Issue”
• Make Sure All Alerts Actionable Too Many EDR Manual Malware
• Automation False Positives & Phishing Triage
• Integrated vs. Silo’d Tools
• Alert Coalescing
• Enriched Telemetry Data
14
Alert & Investigation Fatigue By The Numbers
16
Economy of Service, Reducing SOC MTTD & MTTR
SIEM / SOAR
Alerts
Data Analysis Overload No Unnecessary Information Records All Information Including System Records All Information Including System
• Remote working
Agents
• To understand hooking:
• DLL – Dynamic-Link Library: Shared code.
• API – Application Programming Interface: Software with a distinct function.
• IAT – Import Address Table: Records the addresses of functions imported
from DLLs.
26
URL Scanning
Microsoft Sentinel
EDR / XDR
Microsoft Defender
for Endpoints
Q&A
Thank You!
34
Poll Questions – Incident Response
Does your current operations solution Are you struggling to scale your business
automatically correlate related alerts due to challenges like increased customer
into a single threat-centric case demand, talent shortage, etc.?
management system?
Yes No Yes No
On average, how long does it take Does your IR team currently use
to triage and analyze one malware sample? sandbox technology to validate SOAR alerts
and extract IOCs?
March 2023
Proprietary + Confidential
● Identify gaps
● Reallocate resources
2. Track real-time SOC metrics and KPIs to uncover gaps and improve
processes.
Demo
Proprietary + Confidential
Thank you.
Thank you so much for joining this session with
Jane Goh
Principal Lead, Product Marketing
Cortex XSOAR
Are you a good Defining your Practical use cases for Peer Insights
candidate for use cases quick wins
automation?
© 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential.
What Makes for a Successful Candidate?
© 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential.
Defining Your Use Cases
© 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential.
Some Playbooks to Kickstart Your Automation Journey
1 2 3 4
5 6 7
~600
Global XSOAR Customers
56 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Content Packs are Critical Building Blocks to Your Success
6% 1 CommonPlaybooks 6 CortexXDR
of all top level
playbooks are part of a
2 Phishing 7 QRadar
content pack
DefaultPlaybook IntegrationsAnd
3 8
60% IncidentsHealthCheck
57 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Three Phases for Becoming an Automation Leader
58 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Understanding the Customer Journey from POC to 6 Months
59 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Recommendations
60 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Recommendations
61 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Recommendations
62 | © 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Who Are We?
© 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential.
900+
Third-party
tools SIEM Tools People API
Playbook-driven automation
Marketplace
Cortex XSOAR Community
Ecosystem
Threat
Alerts Intel feeds
SIEM Cortex Cortex Xpanse Strata IOT Prisma Mail Other Sources ISAC Open Source Premium Unit42
XDR NGFW
The World’s Most Comprehensive SOAR Ecosystem
This means we’ve probably got your SOC tools covered
Malware Cloud
Analysis Security
Messaging Threat
Intelligence
900+ integrations
Identity
& Access ISTM
Management
Email
Other
Security
Cortex XSOAR: Automate Across Your Operations
Network/IT Ops
SOC Automation Extended Security Automation
Automation
© 2022 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential.
Thank you so much for joining this session with