SOC Workbench - Threat Investigation
Security leaders know that speed matters when responding to threats. This video demo showcases how the eSentire SOC Workbench enables analysts to move from alert to actionable response with unmatched speed and precision. Watch the demo to understand how this SOC could strengthen your defenses, and contact Synnex Corp. to explore a personalized deployment.
What is the Investigation Workbench?
The Investigation Workbench is a feature within the Insight portal that helps analysts conduct threat investigations. It provides an enrichment tool called the investigation co-pilot, which pulls additional context and information from vendors regarding log activity. This assists analysts in making informed conclusions about potential threats.
How does the system identify compromised users?
The system identifies compromised users by analyzing sign-in patterns and activities. For example, if a user typically signs in from Ireland but suddenly has multiple sign-ins from locations like the United States, Nigeria, and Tanzania within a short time frame, it raises a flag. Additionally, suspicious activities such as the creation of unusual inbox rules and the use of untrusted devices are also indicators of compromise.
What role does telemetry play in investigations?
Telemetry plays a crucial role in the investigation process by providing detailed information about processes running on an endpoint. It helps analysts build a process tree, allowing them to trace back activities to their origins. For instance, if a WScript process is spawned by an application like OneNote, telemetry can reveal the chain of events leading to that execution, which is essential for understanding potential exploitation paths.
SOC Workbench - Threat Investigation
published by Synnex Corp.
SYNNEX brings the most relevant technology solutions to the IT and consumer electronics markets to help our partners sustainably grow their business. We distribute more than 30,000 technology products from more than 400 of the world’s leading and emerging manufacturers, and provide complete solutions to more than 20,000 resellers and retail customers in the U.S., Canada, and Japan. As part of our value-added services, SYNNEX provides a variety of professional and marketing services, including demand generation; education and training; pre- and post-sales support; end-user enablement; server assessment; design and integration; product lifecycle support; contract design and assembly; and IT resource planning. In addition, SYNNEX provides a wide range of financial options to ensure that our partners always have the means to close deals.
Our Westcon-Comstor Americas business operates in North and Latin America and focuses in security, collaboration, networking, and data center. Our expert technical knowledge and industry-leading partner programs are designed to keep our partners at the forefront of their markets to drive business and growth. Westcon-Comstor Americas goes to market under the Westcon and Comstor brands.