This playbook enables the SOC team to swiftly respond to incidents where an internal system or service is targeted by external malicious traffic. By integrating with Arbor Networks APS, the playbook automates the process of blocking access to the impacted IP address—after an analyst's validation. It is highly effective for mitigating ongoing attacks such as DDoS, botnet probes, or exploitation attempts in real time.
This playbook supports analyst-assisted decision-making to ensure critical business services are not unintentionally blocked. It is especially useful when integrated into use cases involving threat intelligence alerts or firewall logs detecting incoming threats to sensitive assets.
This playbook enables the SOC team to swiftly respond to incidents where an internal system or service is targeted by external malicious traffic. By integrating with Arbor Networks APS, the playbook automates the process of blocking access to the impacted IP address—after an analyst's validation. It is highly effective for mitigating ongoing attacks such as DDoS, botnet probes, or exploitation attempts in real time.
This playbook supports analyst-assisted decision-making to ensure critical business services are not unintentionally blocked. It is especially useful when integrated into use cases involving threat intelligence alerts or firewall logs detecting incoming threats to sensitive assets.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox