SANS (v1.1.10)

This SANS Content Pack helps you streamline incident response according to SANS guidelines as outlined in the SANS Incident Handler’s Handbook.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Case Management

Incident fields (8)

Layouts (1)

Playbooks (4)

README

The SANS Incident Response process for handling a cyber security incident contains the following steps:

This SANS content pack contains several playbooks to help streamline your incident response according to SANS guidelines as outlined in the SANS Incident Handler’s Handbook.

What does this pack do?

The playbooks in this pack contain the phases for handling an incident as they are described in the SANS Institute ‘Incident Handler’s Handbook’ by Patrick Kral.
https://www.sans.org/reading-room/whitepapers/incident/incident-handlers-handbook-33901
Disclaimer: This playbooks don’t ensure compliance to SANS regulations.
The “SANS - Incident Handler’s Handbook Template” playbook provides a template that helps analysts follow these stages.
The “SANS - Incident Handlers Checklist” playbook follows the “Incident Handler’s Checklist” described in the SANS Institute ‘Incident Handler’s Handbook’ by Patrick Kral, and provides the analyst an easy solution for following the correct stages and tasks while handling an incident.
The “SANS - Lessons Learned” helps SOC teams process an incident after it occurs and facilitates the lessons learned, organized by SANS stages.
The “Brute Force Investigation - Generic - SANS” playbook handles a Brute Force incident based on the stages described above.
The playbooks included in this pack helps you save time and automate repetitive tasks associated with Access incidents:

For more information, visit our Cortex XSOAR Developer Docs

![SANS_-Incident_Handler’s_Handbook_Template](https://github.com/demisto/content/raw/167ff7ede241667161f6ce526cbb4665c7eac986/Packs/SANS/doc_files/SANS-_Incident_Handler’s_Handbook_Template.png)