SIEM
ITSM
SOAR
Support
SIEM
ITSM
SOAR
Support
Explore how Tata Communications' award-winning Managed Detection and Response (MDR), streamlined the threat management lifecycle in response to a potential ransomware incident at a leading auto manufacturing firm.
2/6
The incident is created in ITSM automatically.
3/6
Incident created notification sent to Customer.
4/6
SOAR auto-triages and auto-enriches the incident ticket.
5/6
Incident update email notification is sent to customer.
6/6
Based on reputation score and investigation output, SOAR initiates auto-response action against indicator of compromise. The associated playbook is triggered and SOAR blocks the C&C communication at customer’s perimeter control and a potential cyber incident has been averted.
1/6
SIEM detects alert "Successful Communication To External Malicious IP Address” for the mentioned Malicious IP “***.**.***.140 by correlation of Customer network traffic with known Ransomware IOC feeds.
Preventing a
ransomware attack in
2
2:143
2:574
3:075
3:256
3:401