Posted By Gbaf News
Posted on September 14, 2018
Integration streamlines security incident remediation by bringing together investigation and response in combined workflows
Exabeam, the next-gen security management company, today announced the addition of case management functionality into Exabeam Advanced Analytics and Exabeam Entity Analytics, its market-leading user and entity behaviour analytics (UEBA) solutions.
The case management offering helps security teams organise and streamline their response efforts to boost security operation center (SOC) productivity.
Exabeam Case Management is an optional module that provides a customisable user interface designed for the workflows of security teams, and that adds intelligence to help analysts resolve incidents more efficiently. Machine learning helps make the interface context aware, presenting users with relevant fields, values, and data for different incident types. The resulting workflows bring pertinent details to analysts when and where they are needed.
New features of the Exabeam Case Management module are:
- Incident Cards – graphical cards on each analyst’s Exabeam home page show both active incidents being worked and pending in their queue, prioritised by severity. The integration with behavioural analytics allows automatic creation of tickets based on incidents with a high risk score. This is an easy way to increase the daily productivity of security analysts at all tiers.
- Workflow Management – with appropriate permissions, analysts can see incidents being worked by their peers and request a merge or escalation as appropriate. This is in addition to the existing capabilities that include workflow definition, case reassignment, ticket tracking, incident triage and case escalation. The increased visibility improves collaboration and reduces redundant work in the SOC.
- Case Context – analysts will see associated security incidents related to their cases in the Advanced Analytics and Entity Analytics interfaces. Threat indicators and relevant artifacts are automatically added to cases. This gives security analysts broader context and allows for human intuition to add to the analytics within the system.
“Many security analysts are using generic IT service management tools to automate their security operations. Historically, ticketing and workflow capabilities for the SOC have either been ‘borrowed’ from departments outside of security, or poorly implemented over the rudimentary functionalities provided by legacy SIEMs. Not only are these tools not customized for security applications, but they are not integrated into the security detection and investigation tools used by the analyst,” said Sylvain Gil, vice president of products and co-founder at Exabeam. “Exabeam Case Management is the first SOC-native case management solution, designed to save analysts time and make them more efficient by integrating security ticketing and workflows into the product. This enables a seamless workflow from detection to triage to remediation.”
Exabeam Case Management is currently in beta testing and is expected to be released next month. It will be demonstrated at Exabeam’s user conference Spotlight 18. For more information on the new case management module, please visit https://www.exabeam.com/product/exabeam-advanced-analytics/.