Automate & respond
SOAR & Incident Response
Run playbooks, take response actions against simulated assets and follow the incident response lifecycle.
Playbooks
5
Automated steps
22
Actions today
14
Analyst time saved
6.4h
Playbooks
| Playbook | Steps | Automated | Last run | Status | |
|---|---|---|---|---|---|
| PB-01Phishing Email Response | 9 | 6 | 12m ago | Enabled | |
| PB-02Compromised Account Containment | 7 | 5 | 1h ago | Enabled | |
| PB-03Ransomware Containment | 12 | 4 | 38m ago | Enabled | |
| PB-04Malicious IP Blocking | 4 | 4 | 6m ago | Enabled | |
| PB-05Endpoint Isolation | 5 | 3 | 2h ago | Testing |
DFIR mini lab & malware triage
Artifact analysis
- prefetch: POWERSHELL.EXE-6D5F1D2A.pf
- amcache: upd.dll first seen 09:26
- shimcache: rundll32.exe executed 09:27
- $MFT: README_RESTORE.txt created 07:47
Static triage — upd.dll
- type: PE32+ DLL, unsigned
- entropy: 7.82 (packed)
- imports: VirtualAlloc, CreateRemoteThread
- strings: cdn-update-sync.net, /beacon
- verdict: likely loader
Response actions
- Isolate endpointWS-FIN-014 · High impact
- Disable user accountr.wijaya · High impact
- Block IP at firewall185.220.101.44 · Medium impact
- Quarantine fileC:\Users\Public\upd.dll · Low impact
- Revoke sessionsEntra ID tenant · Medium impact
- Reset passworda.pratama · Low impact
IR lifecycle
- PreparationClosed
- Detection & AnalysisClosed
- ContainmentInvestigating
- EradicationInvestigating
- RecoveryPending
- Lessons LearnedPending
Learn this capability
Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.
Advanced · Guided Lab · 26 min
Automating response with SOAR playbooks
The same three enrichment and notification steps have been run by hand on every phishing case this month. Codify them into a playbook and decide what stays human.
Advanced · Theory · 18 min
The incident response lifecycle
INC-1041 is confirmed: phishing led to encoded PowerShell and credential access on a finance workstation. The case is now yours as incident responder.
Advanced · Guided Lab · 28 min
Containment decisions under pressure
WS-FIN-014 still has an active C2 channel and the account a.pratama may be in use by the attacker. You must choose containment now, and every option costs something.