Lift Your Spirits With Splunk SOAR

Security Splunk
Halloween is just around the corner and we’re looking forward to trick-or-treating, donning our best costumes, and watching [scary] movies. A few of my favorite movies that I watch around Halloween time remind me of our most recent Splunk SOAR updates. Is that a stretch? Possibly. But hey it’s Halloween, let’s have some fun and I’ll try to make it as humerus as possible 💀

“SOAR With The Cloud In The Dead Of Night”

In A Nightmare Before Christmas (1993), Jack Skellington is bored of doing the same things every year for Halloween when he discovers and obsesses over a magical holiday he’s never heard of before: Christmas. Jack eventually realizes he doesn’t need to choose Christmas over Halloween and they can harmoniously coexist together.

Don’t have a Jack Skellington moment, where you feel stuck doing things one way because there are no other options. Similarly, Splunk SOAR was previously an on-premises only offering for customers, but is now available in the cloud. Now you have the flexibility and freedom to choose how you deploy SOAR and streamline your operations: from the cloud, on-premises or hybrid.

“We Did Some Coding For You, And Now You’re Fine”

In Hocus Pocus (1993), 17th century Salem witches — the Sanderson sisters — are inadvertently resurrected by a teenager named Max on Halloween night. Shenanigans ensue as the sisters try to retrieve their spellbook from Max and his crew whilst trying to navigate the 20th century.

If only the Sanderson sisters had a way to codify their spellbook so they wouldn’t have to worry about a bunch of teenagers ruining their plans to live forever. Thankfully, there’s a way to at least codify your security operations workflows using playbooks from Splunk SOAR.

With the new Visual Playbook Editor, you can create playbooks and scale automation using a simplified interface that makes automating security tasks easier and faster than ever, featuring:

“Edit Edit, Little App, SOAR UI Is Where It’s At”

In Death Becomes Her (1992), rivals Madeline and Helen fight for the affections of Ernest (a plastic surgeon turned mortician) and desperately drink a magic potion that promises eternal life and everlasting youth, just as long as they take care of themselves (i.e. not die a gruesome death). Not following that one simple rule, the women realize that they need Ernest’s skills in order to keep up with appearances — literally.

Madeline and Helen could’ve had an easier time with the upkeep and maintenance of their appearances if everything they needed to look youthful was located in one place. While it may not keep you youthful, the improvements to our SOAR app community and development will keep you in one place when searching for and building apps in Splunk SOAR.

First, Splunk SOAR apps are now available on Splunkbase. Search for SOAR apps amongst our extensive ecosystem of partner and community-built technical integrations across the Splunk portfolio, providing you with a one-stop shop to extend the power of SOAR.

Second, the new App Editor makes it easy to view, test, extend, and edit existing apps — and create entirely new apps — all from the SOAR user interface, featuring:

Register for our webinar, Automation for the Modern SOC: Splunk SOAR’s New App Editor, to see this in action.

Get Started And Reach Your SOAR Ghouls (Goals) 👻

Need a little more information before you get SOAR-ing?

Fangs for sticking with me 🧛

Happy Halloween and Happy Splunking! Alexa

----------------------------------------------------
Thanks!
Alexa Araneta

Related Articles

Using Splunk Attack Range to Test and Detect Data Destruction (ATT&CK 1485)
Security
2 Minute Read

Using Splunk Attack Range to Test and Detect Data Destruction (ATT&CK 1485)

Using Splunk Attack Range to test and detect Data Destruction techniques
Solving User Monitoring Use Cases With Splunk Enterprise Security
Security
4 Minute Read

Solving User Monitoring Use Cases With Splunk Enterprise Security

We all know Splunk’s data platform is capable of delivering incredible analytics and insights at scale, but how do we tie that power with all of the security content and premium solutions for security that Splunk provides? I thought it would be a good idea to jot some thoughts down about some common high level security use cases becauseI get asked this question so much.
SUPERNOVA Redux, with a Generous Portion of Masquerading
Security
10 Minute Read

SUPERNOVA Redux, with a Generous Portion of Masquerading

A review of the Pulse Secure attack where the threat actor connected to the network via a the Pulse Secure virtual private network (VPN), moved laterally to its SolarWinds Orion server, installed the SUPERNOVA malware, and collected credentials, all while masquerading the procdump.exe file and renamed it as splunklogger.exe.