Challenge 03 - Automated Response

< Previous Challenge - Home

Pre-requisites

Verify your environment

Introduction

Now we have our alert rule running, the SOC team is finding that it’s just way too ‘noisy’ because every time an admin logs on, it’s generating Alerts and Incidents. It’s your job to ensure that the Alert must trigger whenever an administrator logs in and create an Incident, AND, the Incident should be automatically closed if the IP address exists in the Watchlist.

Description

We want to automatically update your Security Teams channel when the Incident is not automatically closed.

Close the Incident automatically

Hint: When you log on, if your IP is in the Watchlist, automatically close the alert/incident

Update The Workbook
Send a message to your security operations channel in Microsoft Teams or Slack to make sure your security analysts are aware of the incident.

Success Criteria

Learning Resources

Tips

Check the GitHub repository for existing Logic Apps/ Playbooks.

When adding the Playbook, you need to Manage playbook permissions (in blue, just under the Actions heading).

Read the learning resource above on automated response to find out how to link into Teams (and you can search the web for additional info).

Advanced Challenges

Too comfortable? Eager to do more? Try these additional challenges!