This playbook is designed to handle alerts related to Discovery techniques (such as reconnaissance or internal scanning), typically observed in the early stages of a cyberattack. The workflow includes contextual enrichment, an analyst decision, and automated responses such as user disablement, email notifications, and case status updates in ArcSight SOAR.
This playbook is designed to handle alerts related to Discovery techniques (such as reconnaissance or internal scanning), typically observed in the early stages of a cyberattack. The workflow includes contextual enrichment, an analyst decision, and automated responses such as user disablement, email notifications, and case status updates in ArcSight SOAR.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox