SECOPS 12: SOC WMS and Automation Flashcards
WMS
Tags/ID’s, tracks a security event, and tracks the actions to deal with the event
Tool to orchestrate & automate IR process
WMS
WMS aka
SOAR
SOAR stands for
Security Orchestration Automation and Reporting
System that performs containment and eradication
WMS
Sequential workflow
Flow-chart style. One step to the next
State machine
Progress from state to state
Rules-Driven
Rules dictate process
Guides analysts through the triage and response procedure
Workflow
IR lifecycle (4)
Preparation
Detection and Analysis
Containment, Eradication, Recovery
Post incident activity
Tier 1 Analyst
Monitors alerts, triages security alerts, Collects data to escalate to Tier 2
Tier 2 Analyst
Deep IA by correlating data. Determines affect. Advises on remediation.
IR Handler
Manages incident. Executes containment. Comms.
Forensics specialists
Gather, analyze data for investigation. Maintains data integrity.
Reverse engineering specialist
ID’s TTP’s and IOC’s. Signature writing.