Can one use Splunk phantom for auto-remediation?
What real-life use cases are applicable to the use of Phantom?
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Phantom is mainly used to automate repetitive tasks.
for example: if you have correlation search in Splunk that alerts when phishing email is found.
in general scenarios, analyst will follow incident playbook to perform actions in response to phishing alert.
The list of actions purely based on how incident can be properly handled, below are the just examples:
and also, find more use case here
https://www.splunk.com/en_us/blog/security/playbooks-going-beyond-incident-response-use-cases.html
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Phantom is mainly used to automate repetitive tasks.
for example: if you have correlation search in Splunk that alerts when phishing email is found.
in general scenarios, analyst will follow incident playbook to perform actions in response to phishing alert.
The list of actions purely based on how incident can be properly handled, below are the just examples:
and also, find more use case here
https://www.splunk.com/en_us/blog/security/playbooks-going-beyond-incident-response-use-cases.html
