Skip to content

Latest commit

 

History

History
40 lines (31 loc) · 2.16 KB

File metadata and controls

40 lines (31 loc) · 2.16 KB
sidebar sidebar
permalink reference-soar.html
keywords ransomware protection, soar, security orchestration, microsoft sentinel, splunk, automation, threat response, playbook
summary Integrate and use SOAR playbooks to automate NetApp Ransomware Resilience threat response tasks.

Integrate a SOAR playbook for NetApp Ransomware Resilience

Ransomware Resilience offers security orchestration, automation, and response (SOAR) playbooks that enable you to automate tasks such as threat response.

Ransomware Resilience playbooks offer the following capabilities:

  • Block/unblock a user*

  • Create a snapshot of a volume

  • Enrich an IP address with threat intelligence

  • Enrich storage information for a given agent and system

  • Take a volume offline for incident response or take a volume online after an incident

  • Test connectivity

  • Review the status of an enrichment job

* Blocking/unblocking a user is only supported for Splunk and Google SecOps SOAR playbooks. You must have configured user behavior detection on a supported system to block a user.

Playbooks

Ransomware Resilience offers playbooks for Google SecOps, Microsoft Sentinel, and Splunk. Review the pertinent page for setup details.

Note
For Azure NetApp Files systems, review the limitations for Azure NetApp Files with SOAR.