<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Cortex XSOAR Esri Case Study in Cortex XSOAR Articles</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/cortex-xsoar-esri-case-study/ta-p/329087</link>
    <description>&lt;H2&gt;&lt;STRONG&gt;Navigating Rough Seas&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;How Esri Reduced Its Alert Barrage with Cortex XSOAR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="524px"&gt;
&lt;P&gt;&lt;FONT color="#00CC66"&gt;&lt;STRONG&gt;Industry&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Software/Geographic Information Systems&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#00CC66"&gt;&lt;STRONG&gt;Integrations&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Cortex XSOAR on-premises platform&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;SIEM&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Network monitoring&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#00CC66"&gt;&lt;STRONG&gt;Challenges&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Alert fatigue (more than 10,000 per week)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Shortage of skilled SOC analysts (only five)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Detection of duplicates and related incidents&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Complex and distributed threat indicator management&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;TD width="524px"&gt;
&lt;P&gt;&lt;FONT color="#00CC66"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Esri used Cortex XSOAR to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Get faster closure and false positive detection with auto- mated playbooks&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Leverage historical cross-correlation for duplicate detection&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Combine analyst knowledge with a collaboration window for joint investigations&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;FONT color="#00CC66"&gt;&lt;STRONG&gt;Results&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Cortex XSOAR enabled Esri to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Cut weekly alert volume by 95%&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Increase analyst productivity&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Reduce organizational risk&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="lia-message-template-content-zone"&gt;&lt;STRONG&gt;The Customer&lt;/STRONG&gt;&lt;/H3&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;Esri is a global organization that helps more than 350,000 customers around the world solve tough problems through advanced geospatial technology. With more than 75% of Fortune 500 companies deploying its solutions to meet business goals, it was critical for Esri to maintain a security posture that would protect its diverse digital assets and those of its customers.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="lia-message-template-content-zone"&gt;&lt;STRONG&gt;The Situation&lt;/STRONG&gt;&lt;/H3&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;Esri’s vast customer base and digital nature led to multiple security challenges. Alerts in excess of 10,000 each week caused significant fatigue among the team of five security operations analysts. Detecting false positives and duplicate incidents amid a countless host of attacks was a specific concern that wasn’t being addressed. &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;Esri was also looking to streamline threat indicator management processes, which were distributed, complex, and not conducive to lean threat hunting exercises. Suboptimal responses to these issues were increasing Esri’s business risk, wasting resources, and making the security operations center (SOC) more difficult to manage.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H3 class="lia-message-template-content-zone"&gt;&lt;STRONG&gt;The Solution&lt;/STRONG&gt;&lt;/H3&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;To meet its challenges head on, Esri deployed Cortex™ XSOAR for security orchestration, automation, and response in addition to its existing security information and event management (SIEM) and network monitoring solutions. To speed up incident triage and response, the team took advantage of custom playbooks that interweaved automated and manual tasks.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;BR /&gt;&lt;SPAN&gt;These playbooks also codified analyst knowledge, ­facilitating a standardized response to specific attacks. For false positive and duplicate detection, Esri used historical cross-correlation capabilities in Cortex XSOAR. By quickly highlighting common artifacts and indicators across incidents, Esri analysts could spot and close duplicate attacks without spending too much time on redundant investigations.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;To enhance analyst productivity and learning, Esri used the Cortex XSOAR War Room to conduct joint investigations and help cross-pollinate its analysts’ skill sets. Now able to work on complex incidents together, pull in security actions from other tools, and document results in the same window, Esri’s analysts could restructure their task loads to focus on the cerebral over the trivial.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Outcomes with Cortex XSOAR" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25751i6CE77F6E913A9A8E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Cortex XSOAR Problem Solution Result Workflow.png" alt="Outcomes with Cortex XSOAR" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Outcomes with Cortex XSOAR&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;H3 class="lia-message-template-content-zone"&gt;&lt;STRONG&gt;The Results&lt;/STRONG&gt;&lt;/H3&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;Esri’s application of orchestration, automation, and collaboration led to both objective and subjective improvements. Alerts went from 10,000 per week to roughly 500—a staggering 95% reduction stemming largely from swift resolution of false positives and duplicate incidents, thanks to automated playbooks and historical cross-correlation.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;Moreover, Esri used Cortex XSOAR as the central hub to ingest all alerts, obviating the need for analysts to visit multiple systems to find relevant information. Including ticket management in the team’s incident response platform alongside automation and orchestration meant no alert could slip through the cracks at Esri to cause potential business risk.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Automation freed up the analysts’ time, letting them focus on strategic tasks and continuous process improvements rather than being mired in day-to-day firefighting. Playbooks allowed them to scale their efforts effectively, enabling Esri to more effectively leverage the toughest resource to find and retain: skilled analysts.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;SPAN&gt;The Cortex XSOAR War Room led to increased analyst satisfaction. By automatically documenting all analyst actions, allowing them to improve each other’s skill sets, and giving machine learning-powered insights, the War Room lets analysts do more of what they do best—solve difficult problems—without drowning in documentation and menial tasks.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;&lt;SPAN&gt;The automation infused into our security infrastructure by Cortex XSOAR complements our existing SIEM, allowing our SOC team to realize greater efficiencies. Automating these mundane tasks allows our analysts to focus on decision-making.&lt;BR /&gt;– Sean Kohlmeier, Security Operations Manager, Esri&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;</description>
    <pubDate>Thu, 10 Apr 2025 17:23:07 GMT</pubDate>
    <dc:creator>ELaufer</dc:creator>
    <dc:date>2025-04-10T17:23:07Z</dc:date>
    <item>
      <title>Cortex XSOAR Esri Case Study</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/cortex-xsoar-esri-case-study/ta-p/329087</link>
      <description>&lt;P&gt;&lt;SPAN&gt;How Esri Reduced Its Alert Barrage with Cortex XSOAR&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 17:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-articles/cortex-xsoar-esri-case-study/ta-p/329087</guid>
      <dc:creator>ELaufer</dc:creator>
      <dc:date>2025-04-10T17:23:07Z</dc:date>
    </item>
  </channel>
</rss>

