One thing we usually discuss with customers is the workload. Everyone has too much to do and it can, sometimes be difficult to prioritize investigations.
Especially now, where you might be short on staff, and the Covid-19 virus can strike at the SOC organization or reduce the numbers of available people.
Of course, this does not only apply during the world crisis of Covid-19. Automation is also a help in the normal day to day work.
There are benefits of being able to automate responses and we have these discussions with many customers.
MDATP Automatic self-healing is built-in into Defender ATP and is mimicking these ideal steps a human would take to investigate and remediate organizational assets, impacted by a cyber threat.
This is done using 20 built-in investigation playbooks and 10 remediation actions
Increased Capacity
Cost implications
Get full value of your protection suite and people, quick configuration and you are up and running
Sometimes it will take some time from the alert being triggered until someone has the time to start looking at it. Manual work also requires more resources for review and approval for each action
From a SecOPs perspective, an initial response involves information gathering.
Collecting:
Based on our results, we will decide the remediation steps (if we do not follow a playbook here, the catch will be different result depending on who makes the response).
Remediation:
The remediation will include connecting remotely or manually collect the device and then launch tools for the remediation process.
Fast time to respond which will avoid additional damage and compromise of additional devices, when attackers will start moving lateral in the environment.
It’s our 24/7 buddy who assists the SOC staff to remediate threats so the human staff can focus on other things
Playbook is executed
“suspicious host” playbook is just an example of “catch all” playbook that is applied after detailed AutoIR investigation for evidences raised by alerts / incident to ensure that nothing is missed.
Data Collection
Incrimination
Remediation
As you can see in the options, you can select different AutoIR levels
Go auto approval, save time and protect your business!
Happy Hunting