SOC Workbench - Threat Investigation
Security leaders know that speed matters when responding to threats. This video demo showcases how the eSentire SOC Workbench enables analysts to move from alert to actionable response with unmatched speed and precision. Watch the demo to understand how this SOC could strengthen your defenses, and contact Innovative Technology Solutions to explore a personalized deployment.
What is the Investigation Workbench?
The Investigation Workbench is a feature within the Insight portal that helps analysts conduct threat investigations. It provides an enrichment tool called the investigation co-pilot, which pulls additional context and information from vendors regarding log activity. This assists analysts in making informed conclusions about potential threats.
How does the system identify compromised users?
The system identifies compromised users by analyzing sign-in patterns and activities. For example, if a user typically signs in from Ireland but suddenly has multiple sign-ins from locations like the United States, Nigeria, and Tanzania within a short time frame, it raises a flag. Additionally, suspicious activities such as the creation of unusual inbox rules and the use of untrusted devices are also indicators of compromise.
What role does telemetry play in investigations?
Telemetry plays a crucial role in the investigation process by providing detailed information about processes running on an endpoint. It helps analysts build a process tree, allowing them to trace back activities to their origins. For instance, if a WScript process is spawned by an application like OneNote, telemetry can reveal the chain of events leading to that execution, which is essential for understanding potential exploitation paths.
SOC Workbench - Threat Investigation
published by Innovative Technology Solutions
Could you imagine having someone to call the moment your network went down? How about the ability to recover a document from a previous saved state?
Even worse, you have to recover your entire file system because you have the crypt-o-wall virus. That’s what your MSP is all about. Innovative Technology Solutions, LLC provides Managed IT Services to small businesses in the Flint, MI area.
We are based out of Swartz Creek, MI and provide all of our clients with 24/7 emergency support and service. We also monitor your network 24/7 to prevent your emergency from happening. All of our clients receive full antivirus and back up services included with your contract. You also receive a network router that allows for simple VPN connections and remote monitoring tools.
We offer all potential clients a FREE Network Audit. Call us today or complete the form on this page to schedule your audit!
Innovative Technology Solutions, LLC began in 2007 as a small computer repair shop. It was always the vision of the company to provide high quality, professional services to small businesses at an affordable cost. We have spend the last 10 years learning from other managed service providers in the state. Innovative Technology Solutions has developed the best Managed IT program for your company.
Learn more here: https://www.youtube.com/watch?v=llXgF4GVc8c&feature=emb_err_watch_on_yt