SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Capabilities of the updated Security Vision SOAR and NG SOAR products

Capabilities of the updated Security Vision SOAR and NG SOAR products
18.11.2024

Security Vision SOAR is a comprehensive solution for handling information security incidents at all stages of their lifecycle according to the NIST/SANS methodology, namely:


1. Preparation

2. Detection

3. Containment

4. Investigation

5. Eradication

6. Recovery

7. Post-Incident - Post-incident (working on errors)


The main distinguishing features of Security Vision SOAR:


- Ability to build a consistent attack chain (Kill Chain) by grouping incidents based on common characteristics.


- Object-Oriented Response - an architecture in which all relevant incident entities such as hosts, accounts, processes, hashes, etc., are objects with their own set of attributes, enrichment and response actions, as well as history and relationships.


- Dynamic Playbook - the system itself selects relevant actions to gather additional information and perform actions to contain the spread of the incident based on information about the objects - participants of the incident and their characteristics.


- Expert recommendations, which the system provides to the analyst working on the incident throughout its lifecycle. Recommendations are generated based on the context of the incident and its processing phase, including the use of machine learning models.


Security Vision Next Generation SOAR (NG SOAR) complements the above capabilities with a mechanism for automated interaction with NCSCI and FinCERT, as well as its own SIEM engine.


The main distinguishing features of SIEM from Security Vision:


- Ability to create complex correlation rules with multi-level nesting of conditions, including using repetitions in the rule, event optionality, first event - with a condition like ‘negation’.


- Graphical No-Code editor of correlation rules, which significantly reduces the entry threshold and adaptation time of analysts.


- Optimisation of memory and disc space usage when storing source events.


- When events are received from different sources in a disparate order, time is synchronised despite failures and the chain is reconstructed retrospectively for the correlation rule.


New features added to Security Vision SOAR and Security Vision NG SOAR:


FSTEC DBU Expertise. Incidents and correlation rules can now use not only Mitre Attack tactics and techniques, but also threats and implementation methods from the FSTEC BDU. For boxed correlation rules, the implementation methods corresponding to them are already configured.


Heatmaps for Mitre Attack and FSTEC BDU expertise sets showing the distribution of incidents by tactics and implementation methods, as well as their coverage by correlation rules.

 

рис 1.png 

 

ML model for identifying false positive incidents. The model is trained on the verdicts assigned to incidents by analysts when closing incidents, and when a new incident arrives, it gives a verdict on how similar (in percent) it is in terms of its attributes to previously closed incidents with a False Positive verdict.


Attacker Route. The system automatically visualises the route of incident propagation through the infrastructure, showing the time of compromise of network nodes and the artifacts used by the attacker.


 

рис 2.png 


Reachability Graph. Based on network segment data and network device routing tables, the system allows the analyst to map where an incident could potentially spread based on compromised nodes and their characteristics.

 

рис 3.png 


Recommended

Overview of information security tools: users and data
Overview of information security tools: users and data
Capabilities of the updated Security Vision SOAR and NG SOAR products
Capabilities of the updated Security Vision SOAR and NG SOAR products
Security Vision announces the release of a new version of the Security Vision UEBA product
Security Vision announces the release of a new version of the Security Vision UEBA product
Access control and user identification. IDM systems
Access control and user identification. IDM systems
False or not false?
False or not false?
Security automation with the MITRE matrix variety
Security automation with the MITRE matrix variety
Cyberattacks. Part 2: Advanced Techniques and Manipulations
Cyberattacks. Part 2: Advanced Techniques and Manipulations
What are Network Traffic Analysis (NTA) systems, how do they differ from NDR and IDS?
What are Network Traffic Analysis (NTA) systems, how do they differ from NDR and IDS?
Web Application Security: WAF
Web Application Security: WAF
New generation of reports
New generation of reports
Extension of protection in NGFW and UTM
Extension of protection in NGFW and UTM
SD-WAN - Orchestrator for large scale networks
SD-WAN - Orchestrator for large scale networks

Recommended

Overview of information security tools: users and data
Overview of information security tools: users and data
Capabilities of the updated Security Vision SOAR and NG SOAR products
Capabilities of the updated Security Vision SOAR and NG SOAR products
Security Vision announces the release of a new version of the Security Vision UEBA product
Security Vision announces the release of a new version of the Security Vision UEBA product
Access control and user identification. IDM systems
Access control and user identification. IDM systems
False or not false?
False or not false?
Security automation with the MITRE matrix variety
Security automation with the MITRE matrix variety
Cyberattacks. Part 2: Advanced Techniques and Manipulations
Cyberattacks. Part 2: Advanced Techniques and Manipulations
What are Network Traffic Analysis (NTA) systems, how do they differ from NDR and IDS?
What are Network Traffic Analysis (NTA) systems, how do they differ from NDR and IDS?
Web Application Security: WAF
Web Application Security: WAF
New generation of reports
New generation of reports
Extension of protection in NGFW and UTM
Extension of protection in NGFW and UTM
SD-WAN - Orchestrator for large scale networks
SD-WAN - Orchestrator for large scale networks

Other articles

IPS / IDS systems. Intrusion detection and prevention
IPS / IDS systems. Intrusion detection and prevention
Automating Routine Activities with Security Vision SOAR: A Case Study
Automating Routine Activities with Security Vision SOAR: A Case Study
Overview of information security tools: users and data
Overview of information security tools: users and data
The Hive. Parsing an open source solution
The Hive. Parsing an open source solution
Security Vision announces the release of a new version of the Security Vision UEBA product
Security Vision announces the release of a new version of the Security Vision UEBA product
Information security tools - types and description
Information security tools - types and description
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Features of the new version of the Security Vision UEBA product
Features of the new version of the Security Vision UEBA product

Other articles

IPS / IDS systems. Intrusion detection and prevention
IPS / IDS systems. Intrusion detection and prevention
Automating Routine Activities with Security Vision SOAR: A Case Study
Automating Routine Activities with Security Vision SOAR: A Case Study
Overview of information security tools: users and data
Overview of information security tools: users and data
The Hive. Parsing an open source solution
The Hive. Parsing an open source solution
Security Vision announces the release of a new version of the Security Vision UEBA product
Security Vision announces the release of a new version of the Security Vision UEBA product
Information security tools - types and description
Information security tools - types and description
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Features of the new version of the Security Vision UEBA product
Features of the new version of the Security Vision UEBA product