Can one use Splunk phantom for auto-remediation?
What real-life use cases are applicable to the use of Phantom?
Phantom is mainly used to automate repetitive tasks.
for example: if you have correlation search in Splunk that alerts when phishing email is found.
in general scenarios, analyst will follow incident playbook to perform actions in response to phishing alert.
The list of actions purely based on how incident can be properly handled, below are the just examples:
and also, find more use case here
https://www.splunk.com/en_us/blog/security/playbooks-going-beyond-incident-response-use-cases.html
Phantom is mainly used to automate repetitive tasks.
for example: if you have correlation search in Splunk that alerts when phishing email is found.
in general scenarios, analyst will follow incident playbook to perform actions in response to phishing alert.
The list of actions purely based on how incident can be properly handled, below are the just examples:
and also, find more use case here
https://www.splunk.com/en_us/blog/security/playbooks-going-beyond-incident-response-use-cases.html