on
01-27-2021
05:33 PM
- edited on
01-27-2021
08:07 PM
by
Hilda Arteaga
This event had place on Wednesday 20th, Janaury at 9:30 hrs PDT
In this session, Cisco Press authors discuss the evolution of Security Orchestration Automation and Response (SOAR). And how cybersecurity professionals have traditionally tried to use different security solutions and tools to streamline security operations in three key areas: threat and vulnerability management, incident response, and security operations automation. Then they discuss how solutions like Cisco Secure X have gone beyond the traditional Security Information Event Management (SIEM) and SOAR solutions in a more modern approach to accelerate time to detect and investigate threats, while maintaining contextual awareness.
Join the security top experts to learn more about how these new capabilities allow organizations to accelerate threat investigations and incident management by aggregating and correlating global intelligence and local context in one view. And how Cybersecurity analysts can now use pre-built workflows aligned to common use cases for building your own workflow to eliminate friction in your processes and automate routine tasks. In addition, they will mention some key content of their book Cisco Next-Generation Security Solutions: All-in-one Cisco ASA Firepower Services, NGIPS, and AMP.
This event provides an opportunity to interact with the authors in real-time and learn more about them, their story, the story behind their publications, and how they became renowned experts.
You can find the slides of the session here, and the video here.
You can download the slides of the presentation in PDF format here.
A: NetFlow is a technology created by Cisco that allows you to collect and analyze network flow metadata. The IPFIX is a vendor neutral implementation of NetFlow. It was based on NetFlow version 9. Most of the Cisco products support both NetFlow and IPFIX.
A: There are no current other books. That’s why Omar suggest to do hands on exercises, but the unfortunate reality is that there are no books for the professional certification yet.
A: [Aron Woland] I used to teach the Certified Ethical Hacker course / certification and I always liked the CeH - as a sort of - broad view of what's avail. Omar may have other thoughts, too. Besides the basic OS, and scripting skills and then going into Capture the flags are great verbal points from Omar.
A: There is no on-prem version today.
A: Yes it does. Many out of the box, and more get added regularly. For Orchestration, as long as it supports a standard API you can work with it (basically).
A: There is “no version of python” in workflows. Workflows are built with Atomic Actions and they are the constructs to create workflows.
This documentation provides more detail https://ciscosecurity-sx-00-integration-workflows.readthedocs-hosted.com/en/latest/orchestration/getting_started.html
If you execute a Python script in workflow, it will be on the target system. So whatever the python version that is installed on the target system:
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: