Blog de Zscaler

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Products & Solutions

Respond and remediate faster with Red Canary’s new Splunk Phantom integration

image

Introducing Red Canary’s native app within the Splunk Phantom Security Orchestration, Automation, and Response (SOAR) platform.

The need for fast and comprehensive incident response is common knowledge in the security industry, reinforced by requirements to lower and report on metrics such as mean time to detect (MTTD) or mean time to respond (MTTR). However— just like how eating well and regular exercise leads to improved mental and physical health—sometimes these truths are easier said than done. For many organizations, working with limited resources and myriad disparate tools proves problematic when implementing processes to meet aggressive detection and response goals.

Red Canary understands these challenges and invests heavily in our security operations platform to maximize efficiency by eliminating false positives, providing high-quality detections, and creating robust automated responses. Today we are excited to announce another investment in our effort to drive security operation efficiency: a native integration with the Splunk Phantom SOAR platform.

Automated response? There’s an app for that

Red Canary customers who use the Phantom platform now have a bird’s eye view of all their threat detections and automated playbooks in one place. The Red Canary integration is delivered through an app within Phantom, enabling customers to automatically synchronize Red Canary detections into their broader security automation and orchestration processes. Data for the integration is provided through Red Canary’s robust REST API, which is available to all customers. The app can be configured in as little as three minutes, initially synchronizing all previous detections then monitoring for any new detections going forward.

Where can I download the app?

The Red Canary app is found and configured in the Apps section of your Splunk Phantom instance:

  • To install the app, select the New Apps box
  • Search for “Red Canary” and click Install.
  • Once the installation is complete, select Configure New Asset within the app and follow the setup and configuration instructions.

 

Red Canary Splunk Phantom SOAR

 

What other automations does Red Canary offer?

Red Canary has built-in investigative and remedial automations for responses that can be completed solely within our Portal. Our Automate framework combines triggers (e.g., a detection is published) with playbooks (e.g., Isolate an endpoint and kill a process) for flexible and robust automations conducted within your Red Canary and endpoint detection and response (EDR) technologies. Red Canary consistently adds new triggers and playbooks to deliver better security outcomes for our customers. As an example, earlier this month we added support to automatically block IPs and domains with Microsoft Defender for Endpoint.

Red Canary Splunk Phantom SOAR

Customers with questions or feedback can reach out to their Red Canary Customer Success Manager (CSM) or Incident Handler (IH) via the Portal.

Stay tuned

The Splunk Phantom platform is in active development with new features—such as detection and remediation acknowledgement—set to be released later this year. With the added context of Red Canary’s detections, defenders will be better informed and quicker on the draw.

 

Schedule a demo

See firsthand how our 24/7, end-to-end approach helps you achieve greater security outcomes—and gets you back to what matters most.

form submtited
Gracias por leer

¿Este post ha sido útil?

Exención de responsabilidad: Este blog post ha sido creado por Zscaler con fines informativos exclusivamente y se ofrece "como es" sin ninguna garantía de precisión, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por errores u omisiones ni por las acciones que se tomen basándose en la información proporcionada. Cualquier sitio web o recurso de terceros enlazado en esta publicación de blog se proporciona únicamente por conveniencia, y Zscaler no se hace responsable de su contenido ni de sus prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, acepta estos términos y reconoce ser el único responsable de verificar y utilizar la información de manera adecuada según sus necesidades.

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Al enviar el formulario, acepta nuestra política de privacidad.