Cortex XSOAR Tips & Tricks – Dealing with dates

This entry is part 13 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction As an automation platform, Cortex XSOAR fetches data that represents events set at defined moments in time. That metadata is stored within Incidents, will be queried from various systems, and may undergo conversions as it is moves from machines to humans. With its various integrations, Cortex XSOAR ingests datetimes from sources that use different … Continue reading Cortex XSOAR Tips & Tricks – Dealing with dates

The Beauty of Being a Cybersecurity Project Manager for NVISO NITRO MDR

All Project Managers might agree with this: working as a Project Manager is exciting as no two days are ever the same. Just like a conductor of an orchestra leads all musicians to bring harmonic masterpieces to life, so does the cybersecurity Project Manager leading and coordinating the different stakeholders to bring a project to … Continue reading The Beauty of Being a Cybersecurity Project Manager for NVISO NITRO MDR

The Key Role of the Service Delivery Manager at NVISO’s Managed Detect & Respond Service

The Service Delivery Manager (SDM) plays a key role in the delivery of our NVISO cybersecurity NITRO Managed Detect & Respond (MDR) services. As the main point of contact, we represent the client at NVISO and represent NVISO at the client. During the operational lifecycle of a contract, my fellow SDMs and I are responsible … Continue reading The Key Role of the Service Delivery Manager at NVISO’s Managed Detect & Respond Service

Cortex XSOAR Tips & Tricks – Creating indicator relationships in automations

This entry is part 8 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction In Cortex XSOAR, indicators are a key part of the platform as they visualize the Indicators Of Compromise (IOC) of a security alert in the incident to the SOC analyst and can be used in automated analysis workflows to determine the incident outcome. If you have a Cortex XSOAR Threat Intelligence Management (TIM) license, … Continue reading Cortex XSOAR Tips & Tricks – Creating indicator relationships in automations

Cortex XSOAR Tips & Tricks – Execute Commands Using The API

This entry is part 6 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction Every automated task in Cortex XSOAR relies on executing commands from integrations or automations either in a playbook or directly in the incident war room or playground. But what if you wanted to incorporate a command or automation from Cortex XSOAR into your own custom scripts? For that you can use the API. In … Continue reading Cortex XSOAR Tips & Tricks – Execute Commands Using The API

Cortex XSOAR Tips & Tricks – Using The API In Automations

This entry is part 4 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction When developing automations in Cortex XSOAR, you can use the Script Helper in the built-in Cortex XSOAR IDE to view all the scripts and commands available for automating tasks. When there is no script or command available for the specific task you want to automate, you can use the Cortex XSOAR API to automate … Continue reading Cortex XSOAR Tips & Tricks – Using The API In Automations

Cortex XSOAR Tips & Tricks – Tagging War Room Entries

This entry is part 3 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction The war room in Cortex XSOAR incidents allows a SOC analyst to do additional investigations by using any command available as an automation or integration command. It also contains the output of all tasks used in playbooks (if not in Quiet mode). In this blogpost we will show you how to format output of … Continue reading Cortex XSOAR Tips & Tricks – Tagging War Room Entries

Cortex XSOAR Tips & Tricks – Execute Command Function

This entry is part 2 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction When developing the automated SOC workflows for the NVISO Managed SOC and the additional NITRO services on Cortex XSOAR, we have started to make use of automations to do complex tasks instead of playbooks. Automations have much better performances and, if your team has a decent level of Python skills, developing complex tasks in … Continue reading Cortex XSOAR Tips & Tricks – Execute Command Function

Cortex XSOAR Tips & Tricks

This entry is part 1 of 10 in the series Cortex XSOAR Tips & Tricks

Introduction With our Managed Detect and Respond (MDR) service, NVISO provides a managed Security Operations Center (SOC) for a large variety of clients across different industries. Since the beginning of this service, we had an “automate first” principle where we tried to automate as much of the repetitive tasks of the SOC analysts as possible, … Continue reading Cortex XSOAR Tips & Tricks