Dynamic intelligent cyber playbooks
A method, involving; detecting an event; identifying one or more security tools that are currently part of an inventory of security tools; generating a playbook based on the inventory, the playbook being generated responsive to the event, the playbook being a script that includes one or more commands, each of the commands corresponding to a respective security tool in the inventory of security tools; and executing the playbook.
1 . A method, comprising;
detecting an event;
identifying one or more security tools that are currently part of an inventory of security tools;
generating a playbook based on the inventory, the playbook being generated responsive to the event, the playbook being a script that includes one or more commands, each of the commands corresponding to a respective security tool in the inventory of security tools, wherein generating the playbook includes:
generating a signature that identifies a plurality of security tools that are part of the inventory and includes information that is associated with the event;
submitting the signature to a machine learning (ML) engine; and
receiving from the ML engine the playbook that is generated by the ML engine in response to the signature; and
executing the playbook.
2 . The method of claim 1 , wherein the playbook is generated by retrieving an existing playbook and deleting, from the existing playbook, any commands that correspond to security tools that are currently not part of the inventory.
3 . The method of claim 1 , wherein generating the playbook includes:
retrieving a template corresponding to the event, the template identifying one or more actions;
generating a respective command that performs at least one of the actions, the respective command corresponding to one of the security tools that are currently part of the inventory; and
including the respective command in the playbook.
4 . The method of claim 1 , wherein generating the playbook includes:
receiving a user input specifying an action;
generating a respective command that performs the action, the respective command corresponding to one of the security tools that are currently part of the inventory; and
including the respective command in the playbook.
5 . The method of claim 1 , wherein generating the playbook includes:
identifying a first action, the first action being one of an action that is specified in a playbook template associated with the event or an action that is specified by a user input;
detecting whether any of the security tools that are currently in the inventory is capable of performing the first action;
when any of the security tools in the inventory is capable of performing the first action, generating a command for performing the first action, and including the command in the playbook; and
when none of the security tools in the inventory is capable of performing the first action, identifying a second action that is designated as a substitute for the first action and can be performed by one of the security tools in the inventory, generating a command for performing the second action, and including the command in the playbook.
6 . The method of claim 1 , wherein the event includes a cyber alert event.
7 . A system, comprising:
a memory; and
at least one processor that is operatively coupled to the memory, the at least one processor being configured to perform operations of:
detecting an event;
identifying one or more security tools that are currently part of an inventory of security tools;
generating a playbook based on the inventory, the playbook being generated responsive to the event, the playbook being a script that includes one or more commands, each of the commands corresponding to a respective security tool in the inventory of security tools, wherein generating the playbook includes:
generating a signature that identifies a plurality of security tools that are part of the inventory and includes information that is associated with the event;
submitting the signature to a machine learning (ML) engine; and
receiving from the ML engine the playbook that is generated by the ML engine in response to the signature; and
executing the playbook.
8 . The system of claim 7 , wherein the playbook is generated by retrieving an existing playbook and deleting, from the existing playbook, any commands that correspond to security tools that are currently not part of the inventory.
9 . The system of claim 7 , wherein generating the playbook includes:
retrieving a template corresponding to the event, the template identifying one or more actions;
generating a respective command that performs at least one of the actions, the respective command corresponding to one of the security tools that are currently part of the inventory; and
including the respective command in the playbook.
10 . The system of claim 7 , wherein generating the playbook includes:
receiving a user input specifying an action;
generating a respective command that performs the action, the respective command corresponding to one of the security tools that are currently part of the inventory; and
including the respective command in the playbook.
11 . The system of claim 7 , wherein generating the playbook includes:
identifying a first action, the first action being one of an action that is specified in a playbook template associated with the event or an action that is specified by a user input;
detecting whether any of the security tools that are currently in the inventory is capable of performing the first action;
when any of the security tools in the inventory is capable of performing the first action, generating a command for performing the first action, and including the command in the playbook; and
when none of the security tools in the inventory is capable of performing the first action, identifying a second action that is designated as a substitute for the first action and can be performed by one of the security tools in the inventory, generating a command for performing the second action, and including the command in the playbook.
12 . The system of claim 7 , wherein the event includes a cyber alert event.
13 . A non-transitory computer-readable medium storing one or more processor-executable instructions, which, when executed by at least one processor cause the at least one processor to perform operations of:
detecting an event;
identifying one or more security tools that are currently part of an inventory of security tools;
generating a playbook based on the inventory, the playbook being generated responsive to the event, the playbook being a script that includes one or more commands, each of the commands corresponding to a respective security tool in the inventory of security tools, wherein generating the playbook includes:
generating a signature that identifies a plurality of security tools that are part of the inventory and includes information that is associated with the event;
submitting the signature to a machine learning (ML) engine; and
receiving from the ML engine the playbook that is generated by the ML engine in response to the signature; and
executing the playbook.
14 . The non-transitory computer-readable medium of claim 13 , wherein the playbook is generated by retrieving an existing playbook and deleting, from the existing playbook, any commands that correspond to security tools that are currently not part of the inventory.
15 . The non-transitory computer-readable medium of claim 13 , wherein generating the playbook includes:
retrieving a template corresponding to the event, the template identifying one or more actions;
generating a respective command that performs at least one of the actions, the respective command corresponding to one of the security tools that are currently part of the inventory; and
including the respective command in the playbook.
16 . The non-transitory computer-readable medium of claim 13 , wherein generating the playbook includes:
receiving a user input specifying an action;
generating a respective command that performs the action, the respective command corresponding to one of the security tools that are currently part of the inventory; and
including the respective command in the playbook.
17 . The non-transitory computer-readable medium of claim 13 , wherein generating the playbook includes:
identifying a first action, the first action being one of an action that is specified in a playbook template associated with the event or an action that is specified by a user input;
detecting whether any of the security tools that are currently in the inventory is capable of performing the first action;
when any of the security tools in the inventory is capable of performing the first action, generating a command for performing the first action, and including the command in the playbook; and
when none of the security tools in the inventory is capable of performing the first action, identifying a second action that is designated as a substitute for the first action and can be performed by one of the security tools in the inventory, generating a command for performing the second action, and including the command in the playbook.