Skip to content

Repository for Cisco SecureX Orchestration Workflows and Atomic Actions

License

Notifications You must be signed in to change notification settings

iberlinson/SX-AO

Repository files navigation

SX-AO

Repository for Cisco SecureX Orchestration Workflows and Atomic Actions

  • NOTE:
    • If you don't have a SecureX Account, please follow the Quick Start Guide.
    • Detailed instructions to add iberlinson/SX-AO repositories to you Securex Instance can be found HERE
    • How to import a workflow : HERE
    • SecureX Orchestration Documentation : HERE

Available Atomics Actions

  • List and Readme Here*

Available Use Cases (Workflows)

  • 🛎 Cisco Umbrella : Notification on Security Events (Umbrella-Notification-Security-Events)

    • Receive a near real time notification in Webex Teams or via Email on a new domain blobked by Umbrella

      • Use SecureX Orchestration to periodically :
        • Get new security event from last check
        • Notify in Webex Teams on new domains blocked seen for the first time in the organization
        • Maintain a statistic table with number of hits for each domain and current notification status
    • This workflow can be trigger by a schedule to execute every X minutes

    • Use Case and Installations : Detailed informations about the workflow can be found HERE

  • 🔦 Hunt - Search User

    • Search for a given user via :

      • Orbital (Account (Monitoring and Logged_In)
      • Secure Endpoint - User Activity (telemetry)
    • Notify in Cisco Webex or/and via Email about result

    • Create Casebook if user found

    • Use Case and Installation : Detailed informations about the workflow can be found HERE

  • 🧽 Cisco Secure EP - Remove Inactive Endpoints

    • Cisco Seucre Endpoint : Identify and Remove from computers list endpoints with a last seen over a given number of days (default : 45 days)

    • Use Case and Installation : Detailed informations about the workflow can be found HERE

  • TG-Feeds-to-Umbrella-BlockList-2-Tiers-approval

  • 🛎 RT-Monitoring-SecureEP-Umbrella-Notification-Incident

    • Continuous monitoring of Umbrella and/or Secure EP Security events (loop)

    • Near real time Incident creation and update (grouped by endpoint hostname, no duplicate event)

    • Near real time notification on new or updated incident (no duplicate notification for same event occurring multiple times)

    • Statistic tables

    • Use Case and Installations : Detailed informations about the workflow can be found HERE

About

Repository for Cisco SecureX Orchestration Workflows and Atomic Actions

Topics

Resources

License

Stars

Watchers

Forks