logo

NJP

Security Incident Response Workspace Demo

Import · Feb 02, 2023 · video

hello everyone welcome to the all-new security incident response workspace demo before we begin this release caters to all the use cases of Tier 1 and tier 2 security analysts we have reimagined the user experience across different touch points of an analyst user Journey this is the landing page that the analyst would land on to by navigating from the workspaces menu over here the landing page presents information about security incidents and response tasks under my work my team's work and an assigned work the landing page presents disposition of work by surfacing up key security incidents and response tasks that need immediate attention for security incidents we have different widgets just by priority by state by category and SLA all of these widgets are interactable for example if I would like to filter the critical incidence I can do so by clicking on the widget directly the bottom half presence a filtered list view we also have a corresponding card view that helps analysts go through the information quickly the right hand side has the upcoming section that presents information about security incidents and response tasks that are due SLA either today or tomorrow the analyst can access them by clicking on this link it will navigate them to a list view where the analysts can go through the information and focus on those that need immediate attention now let us get back the quick link section over here acts like a bookmark you can access third-party sites and systems without having to exit the workspace we also have the traditional list view where we present security incidents response tasks and user reported fish emails and so on we have pre-applied filters such as assigned to me assigned to team and quick filters that help triaging in a much faster and efficient way we have a quick filter open incidence with priority equal to critical already applied so this would filter down critical incidents with much ease than having to go ahead and apply these filters against the list View these quick filters are completely configurable and can be further personalized according to the user now let us understand how the user experience has been made delightful while handling a security incident the overview page presents information or key statistics that are associated with the security incident we have description business impact containing configuration items and Associated users information these are further filtered based on asset type and criticality the threat until section has observables by finding and by type we also have response tasks in related security incidence information on child security incident and similar security incident similar to The Landing Page all of these widgets are interactable now I see there are three militia's observables and if I'd like to know more about these observers I can click on the widget directly it will navigate me to the investigation canvas with a filter pre-applied in the classic UI investigation is done primarily on related lists and we have been hearing from customers that the experience is completely disjointed there are too many related lists the analyst has to navigate from one related list to another from multiple flicks and sometimes the analyst doesn't even know where to look look for information after performing an action all of these are reimagined to a great extent in this investigation canvas investigation generally happen on these artifacts such as Observer bills configuration items users and so on so we have presented them as entry point lists out of the box you can go ahead and configure them as desired Learners understand how all the information associated with observables are presented in one logical section so that the analyst doesn't have to navigate across different places or perform multiple clicks to get the information required let me select these observables and click view Associated info now I have all the information such as threat lookup results observable enrichment and sandbox right in one place by default we present the latest results you also have an option to go ahead and fetch all the results there's so much of information but so less real estate that we have tried maximizing the space by introducing different filters and navigation so you can filter down what information you're exactly looking for you can also collapse all expand all get the exact section to find more information about what you're looking for you can also perform all the orchestration right from here now let's switch gears and get back to the details tab the details tab has all the information such as the security incident related form fields in this step we have short description assignment you know the priority information and everything related to it here while analyst performs edits to these information the analyst can quickly post work notes from here in the classic UI the activity stream that holds the work notes is extremely noisy there is infinite scrolling and it is very difficult to get to exact information what you're looking for this is again been greatly reimagined with the help of the platform provided activity stream you have pre-applied filter sets that helps narrow down exactly what you're looking for you have a search option further to get to what you're looking for the scrolling is limited because we have side by side context while performing the edits now let us move on into the investigation Journey one important Aid or tool that comes handy while performing investigation is the Playbook in the classic UI playbooks are built using flow designer flows and are rendered with the help of response tasks these response tasks are again another uh these response tasks are nothing but another related list and it is hidden amongst those multiple related lists one activity is presented to the user the analyst has to perform that activity complete the response task for the next set of steps to start appearing for the analyst they experiences cumbersome and it is not ideal now we have reimagined this again to a great extent with the help of platform provided Playbook all of these steps are rendered as interactive activity cards the analyst can perform inline orchestration for example submitting to sandbox right from here without having to go to a different place perform the action and come back to see the results analyst can also view results in line right in this place in addition the analyst can go ahead skip cancel the Playbook or you know filter the uh cards based on the status of the Playbook and cancel the entire Playbook itself not just these activity cards one great Advantage as compared to the classic UI is the ability to manually add Playbook for example if you're investigating a phishing incident and it turned out to be a malware incident too you may want to invoke A malwa playbook you can do so by quickly adding the malware playback from here and both of the playbooks would work in parallel while you're performing The Playbook activity you can pull on the activity stream right from the right contextual Pane and add a quick note we have the analyst assist that helps figure out the different KB articles that can come handy while performing investigation actions similarly we have run books that are pre-configured based on a rule we have access to templates over here that comes handy while creating a new security incident or you would want to populate certain fields in a predetermined fashion so you can apply these templates and all of the fields that are applied are shown and you can also go ahead and undo the changes if required the attachment section over here helps access to all the attachments associated with the security incident you can search the attachments you can also download them remove and rename them so this right contextual pane gives access to all the key utilities that are required throughout the investigation Journey you know they are just at a click away moving on we have surfaced up the response tasks uh at the security incident level for any response tasks related activities further moving on with regards to related records we are presenting all the security incident related lists in the related records tab while the investigation experience has been improved with the help of the investigation canvas there would still be need to access these related lists now we have slightly improved the user experience here by grouping them into different logical sections as you see here you can also search them by direct names over here all right moving on to the other records section here we have all the collaboration records like if you have any incidents problems or change request rates you will be able to access them from here similarly you have access to all the emails received sent uh from this section one again advantage that we have as compared to the classic UI is the ability to access draft emails this is not possible in the classic UI you will just be able to type the email and send it across so here while composing an email you'll also be able to you know access quick messages that can be inserted while uh you know composing the email similarly you have response templates that can be applied while composing the email now let us go back and understand the next set of steps in the investigation Journey as the investigation progresses and comes to the review of the closure State Post incident review becomes an important piece of uh process you can take these assessments associated with post incident review or also request assessments as required we also have access to the post incident review reports that can be configured at runtime previewed and downloaded as required now this brings me pretty much to the end of the demo except covering some of the trivia we also have ability to link propose promote um security incident to major security incident as required in addition we can also associate and view miter information so you have the miter card presented with different tactical techniques shown so this way all the information required for an analyst perform investigation is presented to the user in a in a more uh simpler and easier fashion we also have access to the security tags and that brings me to the overall functional demo of this section before one last piece that is the dashboards so you can have all the dashboards that are available out of the box for the analyst from the dashboard Navigation icon over here so you have option to change these different dashboards and access them thank you so much for watching and I hope you would enjoy the new user experience along with us

View original source

https://www.youtube.com/watch?v=sVHTuyEJmxI