SOC Workbench - Threat Investigation
Security leaders know that speed matters when responding to threats. This video demo showcases how the eSentire SOC Workbench enables analysts to move from alert to actionable response with unmatched speed and precision. Watch the demo to understand how this SOC could strengthen your defenses, and contact Computer SuperCenter to explore a personalized deployment.
What is the Investigation Workbench?
The Investigation Workbench is a feature within the Insight portal that helps analysts conduct threat investigations. It provides an enrichment tool called the investigation co-pilot, which pulls additional context and information from vendors regarding log activity. This assists analysts in making informed conclusions about potential threats.
How does the system identify compromised users?
The system identifies compromised users by analyzing sign-in patterns and activities. For example, if a user typically signs in from Ireland but suddenly has multiple sign-ins from locations like the United States, Nigeria, and Tanzania within a short time frame, it raises a flag. Additionally, suspicious activities such as the creation of unusual inbox rules and the use of untrusted devices are also indicators of compromise.
What role does telemetry play in investigations?
Telemetry plays a crucial role in the investigation process by providing detailed information about processes running on an endpoint. It helps analysts build a process tree, allowing them to trace back activities to their origins. For instance, if a WScript process is spawned by an application like OneNote, telemetry can reveal the chain of events leading to that execution, which is essential for understanding potential exploitation paths.
SOC Workbench - Threat Investigation
published by Computer SuperCenter
Wouldn't it be relief to know you had your very own IT Department? Well that's why we are here: You can trust us. When you have an emergency, or simply need technology advice, you can trust us. Who do you turn to when your computer is down, your data is at risk, or if you finally want a regular, day-to-day service relationship? We are waiting, ready for you, whenever you need us, or on a subscribed, monthly basis. You can count on us every day, in every way.
Yes, you can trust Computer SuperCenter. We've stood the test of time, since 1984, to be specific! There is no higher rated Microsoft or Apple solution provider. Check out our Google and A+ Better Business Bureau Ratings...Then give us a call today - Doing business with us is the safe choice.
Your business can only thrive if the technology you’ve invested in runs at peak performance, every minute of every day. When you choose Computer SuperCenter as your Managed Services Provider (MSP), you’re choosing a partner with the in-house capability to proactively maintain, upgrade, continuously monitor, and intelligently evolve your systems.
In the face of tightened security, Computer SuperCenter delivers protection, disaster recovery and data privacy services to counter the proliferation of network and data breaches.
You can accomplish more than ever using the right collaboration and productivity platform. We are among the most experienced of Microsoft Solution Providers advising and deploying Microsoft Office 365 and Microsoft Azure Cloud Solutions. As a matter of fact, we won the Microsoft award as Top Cloud Solution Provider in the Metro-New York Area.