Automating ATT&CK Testing with SOAR and Atomic Red Team

Automating ATT&CK Testing with SOAR and Atomic Red Team

| | Use Cases
MITRE ATT&CK is the defacto framework for organizations to measure their defense posture. ATT&CK provides categorical verticals in the form of tactics, which align to the common methodologies attackers use. Within these verticals are a set (and subsets) of common ways in which attackers accomplish a tactic (vertical). These are ... Read More
Making MITRE ATT&CK Actionable

Making MITRE ATT&CK Actionable

The Swimlane Deep Dive team is excited to announce the release of pyattck 2.0 and an equivalent PowerShell version called PSAttck. These open-source tools provide security operations centers (SOCs), defenders and offensive security teams with external data points that enrich MITRE ATT&CK by providing potential commands, queries and even detections ... Read More
Responding to Insider Threats with SOAR

Responding to Insider Threats with SOAR

Insider threats occur when an individual with ties to an organization misuses their access for malicious intent, such as stealing intellectual property or other data. Detecting insider threats can be difficult. But by using a security information and event management (SIEM) system or data loss prevention (DLP) products, you can ... Read More
Identify Malicious Domains using SOAR

Identify Malicious Domains using SOAR

Domain Squatting, typosquatting and IDN homograph attacks are commonplace when it comes to phishing and other forms of social engineering. Attackers use domain squatting and typosquatting of domains to trick users into providing their credentials, distribute malware, harm an organization’s reputation, or otherwise maliciously impersonate a legitimate domain. We've discussed ... Read More
You don’t have Windows 7 in your environment, do you?

You don’t have Windows 7 in your environment, do you?

| | News and Events
Today is the day. Microsoft Windows 7 is officially end-of-life (EOL). The Windows 7 operating system was released on October 22, 2009. For 10 years now, IT and system administrators around the globe have relied on their trusty old Windows 7 OS. I mean, it was a step beyond Windows ... Read More
How to investigate alerts in Microsoft Azure with SOAR

How to investigate alerts in Microsoft Azure with SOAR

| | integrations
Alerts or detections come in many forms—some are good and some are not—and security operations center (SOC) analysts are responsible for the initial investigation into these anomalies. What’s more, when it comes to cloud-based resources, we may not have the luxury of logging everything that happens on a host operating ... Read More
Investigate alerts in Microsoft Azure

Investigate alerts in Microsoft Azure

| | integrations
Alerts or detections come in many forms—some are good and some are not—and security operations center (SOC) analysts are responsible for the initial investigation into these anomalies. What’s more, when it comes to cloud-based resources, we may not have the luxury of logging everything that happens on a host operating ... Read More
Understanding APIs: SOAP

Understanding APIs: SOAP

| | security operations
In my previous post, I talked about the basics of REST (representable state transfer) APIs (application programming interfaces). If you haven't read it yet, I highly recommend you read that post before continuing. In this post, we will be talking about the basics of simple object access protocol (SOAP) APIs, ... Read More
Proactive Endpoint Threat Response with Swimlane & Cylance PROTECT

Proactive Endpoint Threat Response with Swimlane & Cylance PROTECT

Swimlane and Blackberry Cylance have partnered to offer a new use case that combines the power of security orchestration, automation and response (SOAR) with Cylance PROTECT’s integrated threat prevention solution. The Proactive Endpoint Threat Response use case utilizes our integration to take a proactive response to detections identified by Cylance ... Read More
Swimlane & Cylance PROTECT: Endpoint Threat Response

Swimlane & Cylance PROTECT: Endpoint Threat Response

Swimlane and Blackberry Cylance have partnered to offer a new use case that combines the power of security orchestration, automation and response (SOAR) with Cylance PROTECT’s integrated threat prevention solution. The Proactive Endpoint Threat Response use case utilizes our integration to take a proactive response to detections identified by Cylance ... Read More
Loading...