Outbound Network Detection and Response
- 02 Apr 2025
- 1 Minute to read
- DarkLight
- PDF
Outbound Network Detection and Response
- Updated on 02 Apr 2025
- 1 Minute to read
- DarkLight
- PDF
Article summary
Did you find this summary helpful?
Thank you for your feedback!
Outbound Network Detection and Response
Description
This workflow covers outbound suspicious network pattern detections. there are four phases of the playbook: * Evidence collection - detection details, network related artifacts as IPs and services - based on Sentinel logs from Palo Alto URL filtering logs, Versa web proxy logs and Cybereason EDR telemetry.
Enrichment - enrich the context for the source or destination.
Investigation - check the source process for the communication, checked other alerts towards the same resource (URL, domain or IP), and if it was blocked by the security products.
Response - block IP, block URL.
Trigger Request
There is no input for this workflow.
Supported CDC Versions
- 2.8
Was this article helpful?