1
1

00:00:00,600  -->  00:00:02,070
<v Instructor>SOAR!</v>
2

2

00:00:02,070  -->  00:00:03,570
Now, when I talk about SOAR,
3

3

00:00:03,570  -->  00:00:05,970
I'm not talking about soaring like a bird.
4

4

00:00:05,970  -->  00:00:08,640
No, SOAR is an acronym, and it stands
5

5

00:00:08,640  -->  00:00:11,940
for the Security Orchestration Automation and Response,
6

6

00:00:11,940  -->  00:00:13,860
also known as SOAR.
7

7

00:00:13,860  -->  00:00:15,450
This is a class of security tools
8

8

00:00:15,450  -->  00:00:17,430
that helps facilitate incident response,
9

9

00:00:17,430  -->  00:00:19,650
threat hunting and security configurations
10

10

00:00:19,650  -->  00:00:22,050
by orchestrating and automating runbooks
11

11

00:00:22,050  -->  00:00:24,120
and delivering data enrichment.
12

12

00:00:24,120  -->  00:00:28,050
Basically, think about this as a SIEM version 2.0.
13

13

00:00:28,050  -->  00:00:29,310
Now, when you're dealing with SOAR,
14

14

00:00:29,310  -->  00:00:31,680
SOAR is primarily used for incident response,
15

15

00:00:31,680  -->  00:00:33,030
but there is a large part of it
16

16

00:00:33,030  -->  00:00:35,070
that's used for threat hunting as well.
17

17

00:00:35,070  -->  00:00:37,440
But really the number one place you're going to see SOAR used
18

18

00:00:37,440  -->  00:00:39,630
is incident response because it can automate
19

19

00:00:39,630  -->  00:00:41,100
so many of your actions.
20

20

00:00:41,100  -->  00:00:44,790
Now, as I said, I like to think about this as SIEM 2.0.
21

21

00:00:44,790  -->  00:00:47,190
Essentially, it's a next-generation SIEM.
22

22

00:00:47,190  -->  00:00:48,840
This takes a security information
23

23

00:00:48,840  -->  00:00:51,630
and event monitoring system and integrates it in with SOAR.
24

24

00:00:51,630  -->  00:00:53,070
And when you put those two together,
25

25

00:00:53,070  -->  00:00:55,800
this really does become your next-generation SIEM.
26

26

00:00:55,800  -->  00:00:57,960
Just like when you deal with next-generation firewalls,
27

27

00:00:57,960  -->  00:01:00,810
they took you from dealing with layer three and layer four
28

28

00:01:00,810  -->  00:01:02,640
and brought you all the way up to layer seven.
29

29

00:01:02,640  -->  00:01:05,340
It made it just so much better and so much more capable.
30

30

00:01:05,340  -->  00:01:08,160
Same thing here, when you integrate a SOAR in with a SIEM,
31

31

00:01:08,160  -->  00:01:10,260
you get this really awesome product.
32

32

00:01:10,260  -->  00:01:12,570
It's going to give you the ability to scan security
33

33

00:01:12,570  -->  00:01:15,390
and threat data to be able to identify different things.
34

34

00:01:15,390  -->  00:01:17,640
You can then analyze it using machine learning,
35

35

00:01:17,640  -->  00:01:19,710
and then you can also automate the process
36

36

00:01:19,710  -->  00:01:21,870
of doing data enrichment to make that data
37

37

00:01:21,870  -->  00:01:23,790
inside that SIEM even more powerful
38

38

00:01:23,790  -->  00:01:25,530
for you as an analyst to use.
39

39

00:01:25,530  -->  00:01:27,600
And, finally, you can do incident response.
40

40

00:01:27,600  -->  00:01:29,520
So you can provision new resources.
41

41

00:01:29,520  -->  00:01:31,020
That means you can create new accounts.
42

42

00:01:31,020  -->  00:01:32,580
You can create new VMs.
43

43

00:01:32,580  -->  00:01:34,440
If you're using VDI, you can actually delete
44

44

00:01:34,440  -->  00:01:36,930
somebody's infected box and then create
45

45

00:01:36,930  -->  00:01:38,790
a new virtual machine for them to use.
46

46

00:01:38,790  -->  00:01:41,460
And all this can be done using automated playbooks
47

47

00:01:41,460  -->  00:01:43,920
if you use the SOAR capability.
48

48

00:01:43,920  -->  00:01:45,150
Now, when we talk about this,
49

49

00:01:45,150  -->  00:01:46,410
I just mentioned the word playbook.
50

50

00:01:46,410  -->  00:01:47,940
What exactly is that?
51

51

00:01:47,940  -->  00:01:49,920
Well, a playbook is essentially a checklist
52

52

00:01:49,920  -->  00:01:51,600
of actions that you're going to perform
53

53

00:01:51,600  -->  00:01:54,390
to detect and respond to a specific type of incident.
54

54

00:01:54,390  -->  00:01:57,000
So if you said, "Hey, if I have an alert that says
55

55

00:01:57,000  -->  00:01:58,140
there is a phishing campaign
56

56

00:01:58,140  -->  00:02:00,000
and somebody clicked a link on this machine,"
57

57

00:02:00,000  -->  00:02:01,920
we're going to do steps one through 10.
58

58

00:02:01,920  -->  00:02:03,600
And then we're going to re-image their machine,
59

59

00:02:03,600  -->  00:02:05,010
and we're going to give them a new computer.
60

60

00:02:05,010  -->  00:02:06,450
That might be your steps.
61

61

00:02:06,450  -->  00:02:08,250
So, for example, if you have somebody who clicked
62

62

00:02:08,250  -->  00:02:10,050
on a link in this phishing campaign,
63

63

00:02:10,050  -->  00:02:12,157
you might have steps one through five which says,
64

64

00:02:12,157  -->  00:02:14,700
"Go to the machine. Isolate it from the network.
65

65

00:02:14,700  -->  00:02:17,490
Do a virus scan to make sure they haven't infected themself.
66

66

00:02:17,490  -->  00:02:19,350
Check the registry to make sure there's nothing in there
67

67

00:02:19,350  -->  00:02:22,650
for persistency, and then back up all the user data,
68

68

00:02:22,650  -->  00:02:25,500
reformat the computer, and then reinstall the computer
69

69

00:02:25,500  -->  00:02:27,270
and put their data back on."
70

70

00:02:27,270  -->  00:02:29,160
These might be the actions you're going to do.
71

71

00:02:29,160  -->  00:02:31,110
Now, these could be manual or automated,
72

72

00:02:31,110  -->  00:02:32,430
but in the case of a playbook,
73

73

00:02:32,430  -->  00:02:35,070
usually you're talking about just the steps involved.
74

74

00:02:35,070  -->  00:02:36,900
Now, if I can automate a lot of that,
75

75

00:02:36,900  -->  00:02:38,460
that becomes a runbook.
76

76

00:02:38,460  -->  00:02:41,040
Now a runbook is an automated version of a playbook,
77

77

00:02:41,040  -->  00:02:43,080
and it leaves clearly defined interaction points
78

78

00:02:43,080  -->  00:02:44,460
for human analysis.
79

79

00:02:44,460  -->  00:02:46,447
For example, my SOAR might say,
80

80

00:02:46,447  -->  00:02:48,540
"If somebody clicks a link in a phishing email,
81

81

00:02:48,540  -->  00:02:50,520
do these steps, one through five.
82

82

00:02:50,520  -->  00:02:53,460
When you get to step two, pause, send it to an analyst,
83

83

00:02:53,460  -->  00:02:55,140
who will then say, re-image the machine
84

84

00:02:55,140  -->  00:02:57,000
or don't re-image the machine."
85

85

00:02:57,000  -->  00:02:58,500
These are the ways that we can use these things,
86

86

00:02:58,500  -->  00:03:01,020
and they all work together to create a better environment
87

87

00:03:01,020  -->  00:03:03,330
and to help reduce the workload of our analysts,
88

88

00:03:03,330  -->  00:03:04,860
because again, we only have
89

89

00:03:04,860  -->  00:03:06,450
so many cybersecurity professionals,
90

90

00:03:06,450  -->  00:03:08,070
and if we're having them waste their time
91

91

00:03:08,070  -->  00:03:10,500
on very minor things that we can automate,
92

92

00:03:10,500  -->  00:03:11,790
that's not very helpful to us.
93

93

00:03:11,790  -->  00:03:14,070
So, instead, we want to automate what we can
94

94

00:03:14,070  -->  00:03:16,570
and SOAR allows us to do a lot of that automation.
