SOC Workbench - Threat Investigation
Security leaders know that speed matters when responding to threats. This video demo showcases how the eSentire SOC Workbench enables analysts to move from alert to actionable response with unmatched speed and precision. Watch the demo to understand how this SOC could strengthen your defenses, and contact Net Core Technologies to explore a personalized deployment.
What is the Investigation Workbench?
The Investigation Workbench is a feature within the Insight portal that helps analysts conduct threat investigations. It provides an enrichment tool called the investigation co-pilot, which pulls additional context and information from vendors regarding log activity. This assists analysts in making informed conclusions about potential threats.
How does the system identify compromised users?
The system identifies compromised users by analyzing sign-in patterns and activities. For example, if a user typically signs in from Ireland but suddenly has multiple sign-ins from locations like the United States, Nigeria, and Tanzania within a short time frame, it raises a flag. Additionally, suspicious activities such as the creation of unusual inbox rules and the use of untrusted devices are also indicators of compromise.
What role does telemetry play in investigations?
Telemetry plays a crucial role in the investigation process by providing detailed information about processes running on an endpoint. It helps analysts build a process tree, allowing them to trace back activities to their origins. For instance, if a WScript process is spawned by an application like OneNote, telemetry can reveal the chain of events leading to that execution, which is essential for understanding potential exploitation paths.
SOC Workbench - Threat Investigation
published by Net Core Technologies
All companies need a solid IT framework, regardless of their size.
We deliver technology solutions built for success.
Professional IT Services
Net Core Technologies is a Managed Services Provider specializing in networking, wireless, information security, and custom IT solutions from technology leaders Cisco, Fortinet, HP/Aruba, Dell, Lenovo, and Microsoft products and services. Our engineers have a broad history ofdesigning an implementing networking solutions for clients in the healthcare, finance, gaming, retail, and government sectors.
Our engineers have extensive field experience in their relative fields and will invest the time needed to familiarize themselves with your business's technology needs. The major advantage to our corporate IT support is that instead of just having a single ‘in-house’ IT person, you will have the support of an entire team of IT professionals, with full access to our resources. Net Core Technologies will provide a virtual IT department to your business, reducing your TCO and providing a larger ROI than traditional staffing.
We perform an initial network evaluation for new clients to make sure you have a business continuity plan, and then sit down with you to determine your needs. We have an extremely fast response time and use a combination of our remote, phone-based and on-site services to provide you with a highly cost-effective support plan. In addition to our support, we offer a good deal of productivity boosting services designed to optimize the way you do business.
We have taken IT outsourcing to the next level and can provide your company with the support and tools you need for your business. Let us take care of your computer infrastructure, so you can concentrate on the most important thing: running your business!