SafeBreach Insights - Breach and Attack Simulation platform extends the SafeBreach - Breach and Attack Simulation platform pack to include remediation and validation of behavioral-based indicators of compromise (BIOCs) as well as non-behavioral indicators of compromise (IOCs).
BIOCs that are proven via simulation results to be capable of breaching your enterprise are fetched from SafeBreach into Cortex XSOAR playbooks. This allows XSOAR to orchestrate and automate updates to your endpoint and network security controls. At the same time, IOCs are fetched and fully automated to update your endpoint and network security controls.
The integration with Cortex XSOAR enables the workflow for a closed-loop process to ensure your security defenses will prevent the latest non-behavioral indicators and behavioral indicators from breaching your enterprise.
Enable the premium pack for the SafeBreach Insights integration with Cortex XSOAR and benefit from closed-loop automated security control remediation of behavioral and non-behavioral IOCs via an enriched SafeBreach Dashboard in your Cortex XSOAR platform:
- Discover security gaps with continuous breach & attack simulation
- Remediate and validate missed indicators automatically
- Orchestrate remediation of behavioral indicators
- Maximize the effectiveness and value of your existing security controls
What does this pack do?
- Processes behavioral indicators, creating SafeBreach Insight incidents
- Handles the SafeBreach Insight incidents with a dedicated playbook, orchestrating the remediation process for closing discovered security gaps
- Summarizes the current status of actionable insights and related indicators in a dedicated SafeBreach Insights prioritization dashboard
How to enable it?
- Install SafeBreach - Breach and Attack Simulation platform pack
- Enable and configure SafeBreach v2 integration
- Install SafeBreach Insights - Breach and Attack Simulation platform premium pack
- Create a feed-triggered job that will be triggered for SafeBreach behavioral indicators
- Assign the playbook for the job - "SafeBreach - Process Behavioral Insights Feed"
- Assign "SafeBreach - Handle Insight Incident" playbook as a default playbook for "SafeBreach Insight" incident type
Watch a product demo at https://safebreach.com/Cortex-XSOAR-Integration