JELAJAH SOC
YO

Automate & respond

SOAR & Incident Response

Run playbooks, take response actions against simulated assets and follow the incident response lifecycle.

Playbooks

5

Automated steps

22

Actions today

14

Analyst time saved

6.4h

Playbooks

PlaybookStepsAutomatedLast runStatus
PB-01Phishing Email Response9612m agoEnabled
PB-02Compromised Account Containment751h agoEnabled
PB-03Ransomware Containment12438m agoEnabled
PB-04Malicious IP Blocking446m agoEnabled
PB-05Endpoint Isolation532h agoTesting

DFIR mini lab & malware triage

Artifact analysis

  • prefetch: POWERSHELL.EXE-6D5F1D2A.pf
  • amcache: upd.dll first seen 09:26
  • shimcache: rundll32.exe executed 09:27
  • $MFT: README_RESTORE.txt created 07:47

Static triage — upd.dll

  • type: PE32+ DLL, unsigned
  • entropy: 7.82 (packed)
  • imports: VirtualAlloc, CreateRemoteThread
  • strings: cdn-update-sync.net, /beacon
  • verdict: likely loader

Response actions

  • Isolate endpointWS-FIN-014 · High impact
  • Disable user accountr.wijaya · High impact
  • Block IP at firewall185.220.101.44 · Medium impact
  • Quarantine fileC:\Users\Public\upd.dll · Low impact
  • Revoke sessionsEntra ID tenant · Medium impact
  • Reset passworda.pratama · Low impact

IR lifecycle

  1. PreparationClosed
  2. Detection & AnalysisClosed
  3. ContainmentInvestigating
  4. EradicationInvestigating
  5. RecoveryPending
  6. Lessons LearnedPending

Learn this capability

Hands-on labs that build the technique behind this workspace. Skills transfer to any mainstream SIEM.