Index
As this ebook edition doesn't have fixed pagination, the page numbers below are hyperlinked for reference only, based on the printed edition of this book.
A
Advanced Threat Protection (ATP) 279
Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) 27
alerts 46
Amazon Web Services (AWS) 60
anomalies 46
Application Programming Interfaces (APIs) 46
Artificial Intelligence (AI) 6, 34
auto-closing incidents, with automation rules 250
automation rule, creating 250-252
automation rule, testing 252, 253
automated false-positive incident closure, with watchlist 211
AllowedIP watchlist, querying 218-224
Entities - Get IPs action, adding to playbook 218
False stream, configuring 229
IP from incident, versus IP from watchlist 225-227
permissions, assigning to managed entity 230
playbook, creating 212
playbook, initializing 213-218
playbook, testing 231-234
trigger, adding to playbook 213-218...