SOC Workbench - Threat Investigation
Security leaders know that speed matters when responding to threats. This video demo showcases how the eSentire SOC Workbench enables analysts to move from alert to actionable response with unmatched speed and precision. Watch the demo to understand how this SOC could strengthen your defenses, and contact Solvix Solutions LLC to explore a personalized deployment.
What is the Investigation Workbench?
The Investigation Workbench is a feature within the Insight portal that helps analysts conduct threat investigations. It provides an enrichment tool called the investigation co-pilot, which pulls additional context and information from vendors regarding log activity. This assists analysts in making informed conclusions about potential threats.
How does the system identify compromised users?
The system identifies compromised users by analyzing sign-in patterns and activities. For example, if a user typically signs in from Ireland but suddenly has multiple sign-ins from locations like the United States, Nigeria, and Tanzania within a short time frame, it raises a flag. Additionally, suspicious activities such as the creation of unusual inbox rules and the use of untrusted devices are also indicators of compromise.
What role does telemetry play in investigations?
Telemetry plays a crucial role in the investigation process by providing detailed information about processes running on an endpoint. It helps analysts build a process tree, allowing them to trace back activities to their origins. For instance, if a WScript process is spawned by an application like OneNote, telemetry can reveal the chain of events leading to that execution, which is essential for understanding potential exploitation paths.
SOC Workbench - Threat Investigation
published by Solvix Solutions LLC
You need technology and office products. You want easy one-stop access and the confidence that you are getting best-in-class offerings at best-bet pricing. You need Solvix Solutions, LLC. Focused on brining the ultimate value to your workplace, Solvix Solutions is a full-service supplier of technology, office, and ergonomic products for the public and private sectors. We procure and repair your infrastructure and desktop technologies—and support you with installation and removal of old equipment, as well as certificates of destruction and recycling.
Founded in 2013 as a woman-owned small business (WOSB), Solvix Solutions provides industry-leading, vendor-agnostic products and services to the government, military, retail, healthcare, legal, media, logistics, automotive, and communications verticals. We’ve established strong relationships with vendor suppliers and customer alike to deliver:
- A wide variety of sources and offerings
- Service and managed support for both projects and products
- Early access to product roadmaps
- Staging services to expedite easy rollouts
- Flexible financing options
- Highly trained staff boasting top product certifications
- Affordable pricing models
- Direct shipping
Solvix Solutions, LLC: Solving today’s problems with tomorrow’s technology.