To help you find the most relevant information, we have defined three personas: IT administrator, Security analyst, and Incident responder. While these may not perfectly align with your organization's structure or your specific role, they optimize content based on typical roles.
Security analyst
A security analyst defends and protects an organization against malicious threats. This involves triaging alerts to prioritize them, investigating suspicious behaviour and potential threats to determine a false positive or malicious threat, and responding to malicious threats with containment measures.
Perform search queries based on alert evidence
Analyze triage data and file acquisitions
Analyze network traffic for unusual or suspicious behavior
Analyze behavior from a notification, event, alert, or incident
Conduct third-party security reviews
Determine a false positive or malicious threat
Contain the threat
Create and own the investigation case
Coordinate remediation stakeholder efforts
Threat hunting for anomalies in general
Set up recurring searches
Evaluate organizational risks and threats
Incident responder
An incident responder is responsible for proactive security hardening and reactive incident management. This involves responding to escalated events and indicators from the Security Analyst and conducting in-depth investigations to determine the root cause of a breach. To continuously adapt to the threat landscape, they test and implement changes to system policies, rules, endpoint hosts, and file collection.
Test and implement new features and modifications
Collaborate with the IT administrator on performance and modifications to global policies
Collaborate with the security analyst to constantly improve controls
Create and tune custom IOC detection rules
Create APIs
Manage exclusions
Review investigation cases
Contain threats
Execute custom rules and policies
Remediate affected hosts
Modify file acquisitions
Apply security policies
Update third party threat data
Perform advanced configuration options
IT administrator
An IT administrator is responsible for the initial software setup, network configuration, and ongoing management of the security system. They ensure compatibility with existing IT platforms, define default settings, and manage the infrastructure for optimal performance.
Install and deploy software
Perform network configuration
Perform performance and scalability enhancements
Ensure compatibility with existing systems
Manage users
Set up policy configuration
Define data classification