SOLUTION BRIEF DFLabs IncMan SOAR - The Security Orchestration, Automation and Response Platform for SOCs.

Similar documents
INTEGRATION BRIEF DFLabs and Jira: Streamline Incident Management and Issue Tracking.

The Resilient Incident Response Platform

SIEM Solutions from McAfee

Integrated, Intelligence driven Cyber Threat Hunting

RFP/RFI Questions for Managed Security Services. Sample MSSP RFP Template

DATA SHEET RSA NETWITNESS PLATFORM PROFESSIONAL SERVICES ACCELERATE TIME-TO-VALUE & MAXIMIZE ROI

locuz.com SOC Services

Triage & Collaboration. Improving a major bank s cyber threat security posture

SOLUTION BRIEF RSA NETWITNESS EVOLVED SIEM

Sustainable Security Operations

Orchestrating and Automating Trend Micro TippingPoint and IBM QRadar

FROM SIEM TO SOC: CROSSING THE CYBERSECURITY CHASM

Prescriptive Security Operations Centers. Leveraging big data capabilities to build next generation SOC

Security Monitoring. Managed Vulnerability Services. Managed Endpoint Protection. Platform. Platform Managed Endpoint Detection and Response

BUILDING AND MAINTAINING SOC

CONTENTS. Technology Overview. Workflow Integration. Sample Customers. How It Works

Security. Made Smarter.

USM Anywhere AlienApps Guide

RSA NetWitness Suite Respond in Minutes, Not Months

4-6 Opportunities Significant value in using SPARKL for Security

IBM Resilient Incident Response Platform On Cloud

IBM Resilient Incident Response Platform On Cloud

NetWitness Overview. Copyright 2011 EMC Corporation. All rights reserved.

Security Monitoring Engineer / (NY or NC) Director, Information Security. New York, NY or Winston-Salem, NC. Location:

Traditional Security Solutions Have Reached Their Limit

RSA INCIDENT RESPONSE SERVICES

MATURE YOUR CYBER DEFENSE OPERATIONS with Accenture s SIEM Transformation Services

THE SIX ESSENTIAL CAPABILITIES OF AN ANALYTICS-DRIVEN SIEM

CYBERBIT P r o t e c t i n g a n e w D i m e n s i o n

MITIGATE CYBER ATTACK RISK

ARC VIEW. Critical Industries Need Active Defense and Intelligence-driven Cybersecurity. Keywords. Summary. By Sid Snitkin

Reducing the Cost of Incident Response

SIEMLESS THREAT MANAGEMENT

Compare Security Analytics Solutions

DATA SHEET RISK & CYBERSECURITY PRACTICE EMPOWERING CUSTOMERS TO TAKE COMMAND OF THEIR EVOLVING RISK & CYBERSECURITY POSTURE

SOLUTION BRIEF RSA NETWITNESS SUITE 3X THE IMPACT WITH YOUR EXISTING SECURITY TEAM

Enhancing the Cybersecurity of Federal Information and Assets through CSIP

Automated Response in Cyber Security SOC with Actionable Threat Intelligence

Colin Gibbens Director, Product Management

Cyber Defense Maturity Scorecard DEFINING CYBERSECURITY MATURITY ACROSS KEY DOMAINS

WHITE PAPER. Operationalizing Threat Intelligence Data: The Problems of Relevance and Scale

QuickSpecs. Aruba IntroSpect User and Entity Behavior Analytics. Overview. Aruba IntroSpect User and Entity Behavior Analytics Product overview

Simplifying Security for IBM i and IBM Security QRadar

Threat Containment and Operations. Yong Kwang Kek, Director of Presales SE, APJ

MEETING ISO STANDARDS

GDPR: An Opportunity to Transform Your Security Operations

RSA INCIDENT RESPONSE SERVICES

National Cyber Security Operations Center (N-CSOC) Stakeholders' Conference

McAfee Advanced Threat Defense

Fabrizio Patriarca. Come creare valore dalla GDPR

MISP Training: MISP Deployment and Integration

SOLUTION BRIEF HELPING BREACH RESPONSE FOR GDPR WITH RSA SECURITY ADDRESSING THE TICKING CLOCK OF GDPR COMPLIANCE

One Hospital s Cybersecurity Journey

ARC VIEW. Critical Industries Need Continuous ICS Security Monitoring. Keywords. Summary. By Sid Snitkin

IT Security Training MS-500: Microsoft 365 Security Administration. Upcoming Dates. Course Description. Course Outline $2,

WHITEPAPER. Enterprise Cyber Risk Management Protecting IT Assets that Matter

RSA IT Security Risk Management

ATTIVO NETWORKS THREATDEFEND INTEGRATION WITH MCAFEE SOLUTIONS

SIEM Product Comparison

Cloud is the 'Only' Way Forward in Information Security. Leveraging Scale to Make the Unknown Known, in Dev, Sec & Ops.

PANORAMA. Figure 1: Panorama deployment

OUTSMART ADVANCED CYBER ATTACKS WITH AN INTELLIGENCE-DRIVEN SECURITY OPERATIONS CENTER

IBM Resilient Incident Response Platform On Cloud

the SWIFT Customer Security

THE ACCENTURE CYBER DEFENSE SOLUTION

Six Weeks to Security Operations The AMP Story. Mike Byrne Cyber Security AMP

PANORAMA. Key Security Features

TRUE SECURITY-AS-A-SERVICE

85% 89% 10/5/2018. Do You Have A Firewall Around Your Cloud? Conquering The Big Threats & Challenges

EXABEAM HELPS PROTECT INFORMATION SYSTEMS

SecureVue. SecureVue

Testing for cyber resilience tools & techniques for adversary simulation and improved defense

भ रत य ररज़र व ब क. Setting up and Operationalising Cyber Security Operation Centre (C-SOC)

Deep Instinct v2.1 Extension for QRadar

RSA ADVANCED SOC SERVICES

Infoblox as Part of the Ecosystem

White Paper. How to Write an MSSP RFP

Risk: Security s New Compliance. Torsten George VP Worldwide Marketing and Products, Agiliance Professional Strategies - S23

Incident Response Services to Help You Prepare for and Quickly Respond to Security Incidents

SECURITY SERVICES SECURITY

ALIENVAULT USM FOR AWS SOLUTION GUIDE

in PCI Regulated Environments

Supercharge Your SIEM: How Domain Intelligence Enhances Situational Awareness

Security by Default: Enabling Transformation Through Cyber Resilience

Accelerate Your Enterprise Private Cloud Initiative

Novetta Cyber Analytics

DDoS Managed Security Services Playbook

Building a Threat-Based Cyber Team

Managed Enterprise Phishing Protection. Comprehensive protection delivered 24/7 by anti-phishing experts

Snort: The World s Most Widely Deployed IPS Technology

BHConsulting. Your trusted cybersecurity partner

Managing Microsoft 365 Identity and Access

Mapping BeyondTrust Solutions to

NEXT GENERATION SECURITY OPERATIONS CENTER

White Paper. Essential Eight ASD Security Controls. The Missing Ninth Step. Defence-Grade Security Intelligence

Incident Response Lessons From the Front Lines. Session 276, March 8, 2018 Nolan Garrett, CISO, Children s Hospital Los Angeles

SOC-2 Requirement Solution Brief. EventTracker 8815 Centre Park Drive, Columbia MD SOC-2

PROTECT AND AUDIT SENSITIVE DATA

Visual TruView Unified Network and Application Performance Management Focused on the Experience of the End User

ENTERPRISE-GRADE MANAGEMENT FOR OPENSTACK WITH RED HAT CLOUDFORMS

Transcription:

SOLUTION BRIEF DFLabs IncMan SOAR - The Security Orchestration, Automation and Response Platform for SOCs. This Solution Brief outlines how DFLabs IncMan SOAR is designed to automate, orchestrate and measure security operations and incident response processes and tasks to improve the overall effectiveness and efficiency of your SOC.

DFLabs IncMan SOAR, the award-winning and pioneering Security Orchestration, Automation and Response (SOAR) platform for Security Operations Centers (SOCs) is a purpose built platform designed to manage security operations. This Solution Brief outlines how DFLabs IncMan SOAR enables you to automate, orchestrate and measure security operations and incident response processes and tasks to improve the overall effectiveness and efficiency of your SOC. Minimize Resolution Time By 90% Maximize Analyst Efficiency By 80% Increase Handled Incidents By 300% Executive Summary. DFLabs IncMan SOAR provides a library of customizable playbooks for different threat and incident response scenarios such as malware, data loss or regulatory breach notification. The solution further provides capabilities to support incident responders in assessing, investigating and hunting for threats, and to gather, maintain and transfer knowledge within the secuirty operations center team. DFLabs IncMan SOAR acts as a force multiplier making it possible to manage more incidents in less time with fewer security analysts, and to do so in a repeatable, measurable and enforceable manner. At the heart of IncMan SOAR is our R³ Rapid Response Runbook engine. R³ Runbooks are created using a visual editor and support granular, stateful and conditional workflows to orchestrate and automate incident response activites such as incident triage, stakeholder notification, data context and enrichment and threat containment. R³ Runbooks are enhanced by capabilities to empower incident responders by assessing, investigating and hunting for threats, and to gather, maintain and transfer knowledge between IR and SOC teams. Our patent-pending Automated Responder Knowledge (ARK) module applies machine learning to historical responses to threats and recommends relevant runbooks and paths of action to manage and mitigate them. IncMan SOAR acts as a force multiplier, enabling SOCs to do more with less. Figure 1. R³ Rapid Response Runbook Example.

Features. DFLabs IncMan SOAR provides orchestration and automation features to automate, orchestrate and measure incident response processes. The solution can ingest the data of hundreds of third party security technologies with many certified bidirectionl integrations, including Cisco ThreatGrid and Umbrella, IBM QRadar, Splunk, McAfee, Palo Alto and many others. IncMan SOAR has been designed with industry standards, regulatory frameworks and best practices in mind, suporting ISO, GDPR, NIST and SEC regulations amongst others. Automation. R³ Rapid Response Runbooks Support the creation of customizable automation runbooks Complex stateful and conditional logical decision making to pursue a variety of alternative responses Over 100 out of the box automation actions Graphical visual editor Full Incident Lifecycle Automation Triage and notification Context enrichment Hunting and investigating Dual-Mode Actions Combine manual, semi-automated and automated actions Automate the action without automation the decision Automated Responder Knowledge Learns from historial incidents and your team s responses to them Advise analysts about similar or related incidents and suggest relevant and related playbooks Speeds up response times and facilitates knowledge sharing Threat containment Orchestration. Aggregation and Correlation of Security and Incident Data Support for hundreds of third party security technologies via Syslog, CEF and Email parsing Over 45 bidirectional connectors Database querying Custom script execution Bidirectional SOAR API Customizable, Linear and Conditional Playbooks Over 100 customizable playbooks for individual incident types or threats and regulatory frameworks Automatically correlates and reapplies playbooks across tenants in multi-user and MSSP environments Professional services are available to assist in customization Integrated Knowledgebase Module Share playbooks, threat intelligence, situational awareness and best practices to facilitate knowledge transfer and continuity Library includes GDPR, ISO, NIST and other regulatory frameworks Powerful Case Management Integrated forensics capabilities Forensics, response system analysis and evidence management Collaboration with diverse stakeholders Secure collaborative platform for data sharing and reporting

Analytics and Reporting. Customizable Dashboards and Widgets Support for a huge variety of key performance indicators and metrics Visualize data with charts, graphs, tables and meters Integrated Reporting Engine with Templates for: Operational performance Incidents Threats Regulatory compliance Over 140 customizable KPI and reporting templates Full Incident Phase Management Measure every individual phase of the IR workflow Optimization, benchmarking and SLA calculation Threat and Incident Data Visualization and Analysis Analysis and visualization of indicators of compromise and incident observables Automated threat intelligence fusion Support for STIX, TAXII, OpenIOC, MISP and many open source commercial TI feeds Deployment. IncMan SOAR can be deployed as a virtual machine and/or decidated HW appliance High availability and load balancing Multitenant architecture Scalable platform can be integrated with NAS and SAN Figure 2. IncMan SOAR Deployment Overview.

About Us. DFLabs is an award-winning and recognized global leader in Security Orchestration, Automation and Response (SOAR) technology. Its pioneering purpose-built platform, IncMan SOAR, is designed to manage, measure and orchestrate security operations tasks, including security incident qualification, triage and escalation, threat hunting & investigation and threat containment. lncman SOAR harnesses machine learning and automation capabilities to augment human analysts to maximize the effectiveness and efficiency of security operations teams, reducing the time from breach discovery to resolution and increasing the return on invest ment for existing security technologies. As its flagship product, IncMan SOAR has been adopted by Fortune 500 and Global 2000 organizations worldwide. The company s management team has helped shape the cyber security industry, which includes co-editing several industry standards such as ISO 27043 and ISO 30121. DFLabs has operations in Europe, North America and EMEA. For more information, visit our website www.dflabs.com or connect with us on Twitter @DFLabs. CONTACT US: BOSTON - UNITED STATES 150 State Street Boston, 02109 T +1 201 579 0893 LONDON - UNITED KINGDOM 1 Primrose Street London, EC2A 2EX T +44 203 286 4193 MILAN - ITALY Via Bergognone, 31 20144, Milan T +39 0373 82416 CUSTOMER SUPPORT: T +39 0373 82416 E support@dflabs.com