chrivand / sxo_secops_workflow

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

License: CISCO published

Automated SecOps workflow with Policy Enforcement Verification

This workflow will serve as an example of a SecOps workflow that includes automated remediation via Cisco Umbrella (block C2 domain), Cisco ThousandEyes (policy enforcement verification) Cisco Duo (disable user), Cisco SecureX (create casebook) and Cisco Webex (send notification). One could easily add/replace other solutions as well.

Check this Youtube demo for more info.

Note: Please test this properly before implementing in a production environment. This is a sample workflow!

Required Targets and API Keys

Setup instructions

  1. Browse to your SecureX orchestration instance. This wille be a different URL depending on the region your account is in:

Import atomic actions

  1. In the left pane menu, select Workflows. Click on IMPORT to import the workflow:

  1. Click on Browse and copy paste the content of the sxo_secops_workflow.json file inside of the text window. Select IMPORT AS A NEW WORKFLOW (CLONE) and click on IMPORT.

Import main workflow

  1. In the left pane menu, select Workflows. Click on IMPORT to import the workflow.

  2. Click on Browse and copy paste the content of the sxo_secops_workflow.json file inside of the text window. Select IMPORT AS A NEW WORKFLOW (CLONE) and click on IMPORT.

  3. Next you will need to update targets / account keys and setting a trigger to run the workflow.

Notes

  • Please test this properly before implementing in a production environment. This is a sample workflow!

Author(s)

  • Christopher van der Made (Cisco)

About

License:Other