Automated investigation and response capabilities
When it comes to investigating and responding to alerts, it can be exhausting. Having some level of automated investigation and response capabilities can save your SOC from burnout and give them time to focus on deeper investigations. Automated investigation and response, or AIR, can help your team operate more effectively. Let's cover an example of this feature.
In this example, the alert is from a user submitting a suspicious email as a phishing attack, as shown in the following screenshot. On top of the message being sent to Microsoft for further analysis, it also gets sent to your administrators and is visible in Threat Explorer, under Submissions:
Once this submission comes in, it kicks off an investigation workflow automation, which includes the following phases:
- Determining what type of threat it might be and who sent it
- Where the email...