Important Shuffle apps
The integration of Wazuh and Shuffle SOAR helps a security team to automate multiple recurring activities. It introduces a paradigm shift in approaching incidents, faster response time, phishing analysis, managing Wazuh, and much more. Shuffle SOAR support integration with hundreds of security tools. In this section, we will discuss some important apps and their integration with Wazuh.
Incident enrichment using TheHive
TheHive is a powerful and a scalable security incident response tool designed for SOCs , CSIRTs (Computer Security Incident Response Teams), and CERTs (Computer Emergency Response Teams). We can use TheHive app in a Shuffle workflow to add enrichment to every alert before conducting a manual security investigation. Once you integrate TheHive with a Shuffle workflow, you can execute multiple tasks on TheHive by using API endpoints, as shown here.
Figure 4.19 – TheHive API endpoints
An API endpoint is essentially...