See how Insoft Services is responding to COVID-19

FortiSOAR Design and Development

X

Contact Us

We would love to hear from you. Please complete this form to pre-book or request further information about our delivery options.

Subscribe

I'd like to receive emails with the latest updates and promotions from Insoft.

Data Protection & Privacy

I hereby allow Insoft Ltd. to contact me on this topic. Further, I authorise Insoft Ltd. processing, using collecting and storing my personal data for the purpose of these activities. All your data will be protected and secured as outlined in our privacy policy.


Upcoming Dates

Oct 20 - Oct 22, 2021
09:00 - 17:00
online

Nov 24 - Nov 26, 2021
09:00 - 17:00
online

Dec 20 - Dec 22, 2021
09:00 - 17:00
online

Jan 25 - Jan 27, 2022
09:00 - 17:00
online

  Feb 21 - Feb 23, 2022
09:00 - 17:00
online

  • FortiSOAR Design and Development
    3 days  (Instructor Led Online)  |  Network Security

    Course Details

    In this course, you will learn how to use FortiSOAR to design simple to complex playbooks. You will learn to create your own dashboards using various built-in widgets, and install widgets from the widget library. You will review the dashboards that are built-in to FortiSOAR and learn to edit them according to your requirements.

    In practical labs, you will explore the role of FortiSOAR in mitigating malicious indicators and creating interactive dashboards to display relevant information about alerts and incidents. You will design a playbook to extract indicators from a phishing email alert. You will also design a playbook to enrich those indicators using connectors to query threat intelligence platforms, such as FortiGuard. You will also design a playbook to mitigate malicious indicators by blocking them on FortiGate. You will configure a FortiSIEM connector to ingest incidents into FortiSOAR.

    Product Versions:

    • FortiSOAR 6.4.3
    • FortiSIEM 6.1.1
    • FortiGate 6.4.4
    • FortiMail 6.4.3

    Objectives

    After completing this course, you should be able to:

    • Identify the role of FortiSOAR in a SOC environment
    • Plan a FortiSOAR deployment
    • Manage incidents and alerts in a SOC environment
    • Explore, create, and customize dashboards
    • Explore the structure of a template
    • Create, customize, and analyze various dashboard widgets
    • Create, customize, and publish modules
    • Search for records and filter search records
    • Analyze field-type options in the field editor
    • Categorize playbook trigger types
    • Build a user prompt from a manual trigger step
    • Understand the basics of Jinja syntax
    • Define variables and dictionaries in Jinja
    • Configure step utilities within a playbook step
    • Configure various core steps of a playbook
    • Use the advanced editor within a playbook step
    • Analyze the details of an approval record
    • Review the connector store
    • Understand connector configuration
    • Configure different modes of data ingestion
    • Configure data ingestion from FortiSIEM
    • Install and configure connectors and apply them to a playbook
    • Configure various utility steps
    • Configure referenced playbooks
    • Configure and use dynamic variables and values
    • Use expressions to customize playbook input and outputs
    • Use common Jinja filters and functions
    • Use the json_query filter to extract data from complex data structures
    • Configure for loop functions and if statements

    Outline

    1. Introduction to FortiSOAR
    2. Dashboard Templates and Widgets
    3. Module Templates and Widgets
    4. Application Editor
    5. Dynamic Variables and Values
    6. Jinja Filters, Functions, and Conditions
    7. Introduction to Playbooks
    8. Playbook Core Steps
    9. Playbook Evaluate Steps
    10. Playbook Connectors, Data Ingestion, and Execution Steps

    Target Audience

    This course is intended for cybersecurity professionals responsible for planning, designing, and customizing FortiSOAR deployments, integrating FortiSOAR with FortiGate, FortiSIEM, and FortiMail, and FortiSOAR playbook design and development.

    Prerequisites

    Familiarity with Python programming, and the Jinja2 templating language for Python is required to benefit from this course.

    Familiarity with the following Fortinet products is beneficial:

    • FortiGate
    • FortiSIEM
    • FortiMail