Analyst Flow - Tutorials - 6.x - Cortex XSOAR - Cortex - Security Operations

Cortex XSOAR 6.x Tutorials

Product
Cortex XSOAR
Version
6.x
Creation date
2022-10-13
Last date published
2023-06-05
Category
Tutorials

Depending on how you design the incident life cycle, many actions are performed automatically before the analyst even sees an incident. For example, incidents may be closed as duplicates or false-positives, data is enriched, and more.

For most incidents, the analyst will:

  1. Pick up an open incident.

  2. View enough data to be able to make decisions including what steps have already been taken (Incident Summary, Work Plan).

  3. Easily collect additional data by running commands on third-party tools.

  4. Collaborate with SOC team members in the War Room; ask questions, post comments, and more.

  5. Make an informed decision on how to handle the incident. A typical flow is to design the incident page to include a set of buttons that the analyst can select from (Escalate, Close, etc.)

  6. Activate one of several possible responses either within Cortex XSOAR or externally (e.g., open a ticket for IT).

  7. Close the incident and specify a close reason.