- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
This blog was written by Tomer Haimof
Understanding and visualizing your cloud risks can be difficult to do. And, even if you have overcome those issues, the more data you collect often means more alerts and more work for your security team. It's time consuming to manually prioritize large volumes of cloud security alerts based on criteria such as whether the impacted resource had a public IP, host vulnerability, or attached identity and access management (IAM) permissions.
Your security team gets a lot of rich data regarding your cloud network and servers from Prisma Cloud. This includes alerts on issues such build misconfigurations or untrusted network traffic. But, extracting and correlating all the data from Prisma Cloud to determine severity and prioritize each alert doesn’t need to be a time consuming task that requires browsing between several screens when performed manually.
With the Prisma Cloud and Cortex XSOAR integration, enrichment, correlation and severity scoring can be fully automated with a playbook using API custom queries based on each alert data.
In addition, most organizations have separate teams (and even sub-teams) involved in the remediation of such alerts, spanning security, network, infrastructure, etc.
Cortex XSOAR provides a central location for case management and cross-team collaboration. Cortex XSOAR can automate the process of communications and ticketing, for example, creating a Jira issue or sending a Slack message with all of the enriched data to the relevant stakeholders.
Cortex XSOAR provides detailed incident layout views to aid analysts further their investigation. There are two main tabs: Case Info and Investigation.
The Case Info tab presents high level data, such as enrichment, notifications, and communications results:
The Investigation tab presents more detailed information, including policy data, violating resources, and indicators:
Combining Prisma Cloud with Cortex XSOAR facilitates the process of handling cloud security incidents and alerts, which can save multiple teams precious time and also prevent human errors while remediating threats.
This playbook is part of the Prisma Cloud content pack which can be located in the Cortex Marketplace. For more information about the Prisma Cloud and XSOAR integration, please read this blog.
Don’t have Cortex XSOAR? Download our free Community Edition today to test out this playbook and hundreds more automations for common use cases you deal with daily in your security operations or SOC.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Subject | Likes |
---|---|
4 Likes | |
3 Likes | |
3 Likes | |
2 Likes | |
2 Likes |
User | Likes Count |
---|---|
11 | |
4 | |
3 | |
2 | |
2 |