Video

SOC Workbench Demo: SOC Threat Investigation Walk Through

 

The eSentire Insight Portal allows our customers to see what our Security Operation Centers (SOCs) see. It is where customers can review our investigations, known as Threat Cases, and understand how we are protecting their business. Threat Cases include up to date details on investigations completed, response actions taken, and remediation support after cyber threats have been contained on their behalf.

In this video, Glen Schut, SOC Innovation Manager at eSentire, provides a walk-through of a SOC Investigation in our Insight Portal including detailing:

  • How our SOC Analysts use the SOC Workbench and enrichments from our LLM to perform investigations and determine if suspicious activity observed in a customer environment is malicious and then move to respond to cyber threats on our customers’ behalf
  • How the SOC Workbench assists SOC Analysts with identifying malicious activity as well as how telemetry is correlated, and process trees pull in data from endpoint and other signals to confirm findings
  • A timeline of a sample Threat Case showing an analyst's commentary summary, when the customer was notified and evidence of the threat
  • A sample customer investigation notification and recommended actions to mitigate the threat for complete remediation support

Watch The Video