Cortex
Cortex is a security product that helps to facilitate security orchestration automation and response (SOAR) activities. Many consider Cortex the most crucial component of incident response because it serves as a sort of IR operating system. This is because it integrates with – marries, if you will – other IR tools with automation to create a streamlined process of working IR. In doing so, Cortex is able to more directly address some of the more common challenges that are faced by today’s SOCs and CSIRTs, as well as professional security researchers, during the threat intelligence and digital forensics portions of the IR process.
Before installing it, let’s take a look at a few things that make Cortex special:
- Analyzer and responder integration: Cortex provides a very robust framework to be used for integrating and executing analyzers and responders. Analyzers are software utilities that are used to perform security analysis tasks, such...